I've noticed in last few days some of the users registered few years back are starting to post crypto spam messages so clearly their accounts have been compromised. Its happening on 2 different forums (different country, hosting, but they are both 2.2.7 patch 1 and only have Media gallery as common addon). My question is if anybody noticed same thing on other versions or maybe its know exploit? I know the first thing I will hear is to upgrade but one of the forum is really complex with lots of custom stuff and bridged with Joomla so upgrade is not really easy option. Thank you.
