[Mitigated] This website's software installation was compromised
Due to our usage of an old version of CMS software Ghost, this site (www.menhera.org) was compromised around 4th August 00:00-01:00 JST using a known attack vector allowing one to obtain API credentials illegally. The attacker used it to post spams on some posts of this website. We have reverted all of them by now.
Response
We upgraded all the stacks including Node.JS, Ghost, and the host OS, and invalidated all credentials. All passwords have been reset. No traces of further compromise have been found.
Conclusion
Never install a CMS and leave it. That's it. We apologize for our inaction and its damages. We will keep all the important software up-to-date from now on.
Contacts
itops <AT> menhera dot ad dot jp (IT Operations Center, Human-life Information Platforms Institute).