Sapphire 2019 Data Breach
What Happened?
When we converted our Apache configuration to NGINX, we used an automated tool
and it did not convert the "no PHP execution access" on our avatar and cover
uploads. This allowed a 3rd party to upload and execute a PHP shell in which
they could possibly downloaded a