Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: surfshark (1 article)Clear

Surfshark VPN says a misconfigured test server let attackers reach build credentials

VPN provider Surfshark disclosed that attackers accessed an internal engineering test server that a configuration error had left reachable from the internet, along with a proxy server used for content optimization. Surfshark says the exposure was limited to a non-production environment and included service configurations, build-related credentials, system binaries, and portions of code history, but did not reach customer data, VPN traffic, encryption keys, or production systems. The company detected the activity on August 31, contained it by September 2, rotated credentials, revoked tokens, and completed remediation within days. It is a reminder that misconfigured internet-exposed test environments remain a common and avoidable breach path, even at security-focused companies.

Check
Inventory internet-facing assets for exposed test, staging, and engineering servers, remove public access to non-production systems, and rotate any build credentials or tokens that a test environment could expose.
Affected
Organizations with internal test or engineering servers unintentionally reachable from the internet; attackers can obtain build credentials, configurations, and source history, which can seed further compromise even when production data is untouched.
Fix
Keep non-production environments off the public internet, apply production-level access controls to test systems, store credentials in dedicated vaults rather than build environments, continuously scan your external attack surface, and rotate secrets.