
Security question: Hacked via Zapier integration
Hi there. I have a self-hosted Ghost instance. This week, my site had its posts and pages all deleted via the Zapier integration API key by some malicious actor. I had not used the integration in my Zapier account, but I was able to see in the History logs that all the malicious activity happened via Zapier. My question is, where are the security vulnerabilities I should add guards for? I have 2FA on and use randomly generated passwords for all my accounts, so I’ve rotated my passwords and the ...





