{
  "meta": {
    "version": "v1",
    "pricing": {
      "public": {
        "label": "Public",
        "description": "Read-only API access for lightweight status checks and public integrations."
      },
      "premium": {
        "label": "Premium",
        "description": "API keys with higher hourly quotas, plus Slack, Teams, Discord, webhook, and email outage alerts across your vendor stack."
      }
    },
    "generatedAt": "2026-10-02T22:41:21.604Z"
  },
  "data": {
    "id": "incident_statuspage_pantheon_n671b672fsdc",
    "slug": "pantheon-security-advisory-malicious-activity-affecting-platform-hosts-2026-10-01",
    "title": "Security Advisory: Malicious Activity Affecting Platform Hosts",
    "summary": "Security Advisory: Malicious Activity Affecting Platform Hosts",
    "status": "monitoring",
    "stale": false,
    "severity": "minor",
    "startedAt": "2026-10-01T19:38:12.377+00:00",
    "updatedAt": "2026-10-02T15:05:07.165+00:00",
    "resolvedAt": null,
    "provider": {
      "slug": "pantheon",
      "name": "Pantheon"
    },
    "affectedServices": [
      {
        "slug": "pantheon-sites",
        "name": "Customer Sites"
      }
    ],
    "links": {
      "html": "/incidents/pantheon-security-advisory-malicious-activity-affecting-platform-hosts-2026-10-01",
      "api": "/api/v1/incidents/pantheon-security-advisory-malicious-activity-affecting-platform-hosts-2026-10-01",
      "providerHtml": "/providers/pantheon",
      "alerts": "https://outagedeck.com/account?stack=pantheon&utm_source=api&utm_medium=response&utm_campaign=api_alerts&utm_content=incident"
    },
    "impactSummary": "Pantheon reported this event with no impact level.",
    "source": {
      "id": "source_pantheon_status",
      "kind": "official_api",
      "name": "Pantheon Operations Status",
      "checkedAt": "2026-10-02T22:35:06.019+00:00",
      "stale": false,
      "officialUrl": "https://status.pantheon.io",
      "statusPageUrl": "https://status.pantheon.io"
    },
    "updates": [
      {
        "id": "update_statuspage_pantheon_n671b672fsdc_lh7ftgbr86vd",
        "status": "monitoring",
        "body": "Beginning September 29, Pantheon identified malicious activity in which an attacker gained control of a customer website and used it to target platform resources.\n\nActivity from the compromised site attempted to exploit a Linux kernel vulnerability (CVE-2026-53362) on platform application hosts, and some sites may have briefly experienced interruptions as a result.\n\nWe have taken the following actions:\n- Disabled and deleted the affected site.\n- Accelerated the operating-system and kernel updates already in progress, bringing application hosts to a version that addresses this vulnerability.\n- Deployed additional platform protections and monitoring.\n\nWe have notified the affected customer directly. The compromise was limited to that single site; based on the information available to us, we have found no evidence of platform-wide data exfiltration or that this activity exposed data belonging to other customers. \nWe are continuing to review platform activity and will update this advisory if that changes.\n\nHow to protect your site: \nAttackers most often gain control of a site through outdated or unmaintained code. Keeping your site current is the most effective protection. We strongly encourage all customers to keep CMS core, plugins, and themes fully updated, remove and delete sites and code you no longer use, and review user and credential access. If you notice unexpected code, deployments, or changes on your site, contact Pantheon Support.\n\nWe will post updates here as more information becomes available. If you have questions, please contact Pantheon Support.",
        "createdAt": "2026-10-01T19:38:12.467+00:00"
      },
      {
        "id": "update_statuspage_pantheon_n671b672fsdc_2w0g19f1528p",
        "status": "monitoring",
        "body": "As our investigation has continued, we have determined that a small number of customer sites — not one — were affected. \n\nIn each case, the site was first compromised through a weakness in its own application, then used to interact with platform services. We are working directly with the affected customers on cleanup and credential rotation, and we have added platform controls to restrict this activity and detection to identify it going forward.\n\nThe activity remains limited to the individual affected sites and their own data. We have found no evidence that any other customer's site or data was accessed.\n\nWhat you can do: Keeping your site current is the most effective protection. \nPlease update your CMS core, plugins, themes, and modules to the latest versions; remove plugins, themes, and modules you don't use; and delete sites you no longer need. If you notice unexpected code, deployments, or changes on your site, contact Pantheon Support.\n\nWe will continue to post updates here.",
        "createdAt": "2026-10-02T15:05:07.162+00:00"
      }
    ],
    "access": {
      "plan": "public",
      "keyed": false
    }
  }
}