We identified unauthorized access to one of our InDesign generation servers, where a cryptocurrency mining application was installed.
The incident resulted from exploitation of a recently disclosed macOS vulnerability, CVE-2026-65400.
The affected server has been isolated and secured, the unauthorized software and access have been removed, and the vulnerability has been patched. As an additional precaution, we will fully wipe and rebuild the server during our upcoming maintenance window.
T...