<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[I have a few questions...]]></title><description><![CDATA[<p>I have a few questions... "Security exercise" sounds planned but this is "Unplanned maintenance" on a Friday night.</p><p>Is PostHog rotating keys due to a security incident?</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://www.posthogstatus.com/incidents/01KSV6HJYKG5QJAP8HVTSQVSM1" title="PostHog Status">
<img src="https://www.posthogstatus.com/posthog-icon.svg" class="card-img-top not-responsive" style="max-height: 15rem;" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://www.posthogstatus.com/incidents/01KSV6HJYKG5QJAP8HVTSQVSM1">
PostHog Status
</a>
</h5>
<p class="card-text line-clamp-3">Current status of PostHog services</p>
</div>
<a href="https://www.posthogstatus.com/incidents/01KSV6HJYKG5QJAP8HVTSQVSM1" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://www.posthogstatus.com/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />



<p class="d-inline-block text-truncate mb-0"> <span class="text-secondary">(www.posthogstatus.com)</span></p>
</a>
</div></p>]]></description><link>https://board.circlewithadot.net/topic/3e4ce065-ed51-4692-82c3-8ba6e0b6d35b/i-have-a-few-questions...</link><generator>RSS for Node</generator><lastBuildDate>Fri, 05 Jun 2026 08:04:19 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/3e4ce065-ed51-4692-82c3-8ba6e0b6d35b.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 30 May 2026 01:26:35 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to I have a few questions... on Tue, 02 Jun 2026 17:46:35 GMT]]></title><description><![CDATA[<p><span><a href="/user/zkat%40fedi.zkat.tech">@<span>zkat</span></a></span> Apparently. I didn't even know the slang meaning until people started pointing it out to me recently. <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f605.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--sweat_smile" style="height:23px;width:auto;vertical-align:middle" title="😅" alt="😅" /> I have yet to find a good explanation for the name.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/AlesandroOrtiz/statuses/116681762102820354</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/AlesandroOrtiz/statuses/116681762102820354</guid><dc:creator><![CDATA[alesandroortiz@infosec.exchange]]></dc:creator><pubDate>Tue, 02 Jun 2026 17:46:35 GMT</pubDate></item><item><title><![CDATA[Reply to I have a few questions... on Tue, 02 Jun 2026 17:31:18 GMT]]></title><description><![CDATA[<p><span><a href="/user/alesandroortiz%40infosec.exchange" rel="nofollow noreferrer noopener">@<span>AlesandroOrtiz</span></a></span> how is "PostHog" a real, actual name of a real, actual company? They can't be serious.</p>]]></description><link>https://board.circlewithadot.net/post/https://fedi.zkat.tech/users/zkat/statuses/01KT4P7JGA0G0464T43Q6G501H</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fedi.zkat.tech/users/zkat/statuses/01KT4P7JGA0G0464T43Q6G501H</guid><dc:creator><![CDATA[zkat@fedi.zkat.tech]]></dc:creator><pubDate>Tue, 02 Jun 2026 17:31:18 GMT</pubDate></item><item><title><![CDATA[Reply to I have a few questions... on Tue, 02 Jun 2026 17:19:03 GMT]]></title><description><![CDATA[<p>Still waiting on promised postmortem. Latest update from Saturday:<br />"A security researcher privately disclosed a vulnerability that allowed access to production credentials. We've fixed the underlying issue and are actively working on additional hardening.</p><p>As a precaution, we immediately rotated our most sensitive production credentials."</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://www.posthogstatus.com/incidents/01KSV6HJYKG5QJAP8HVTSQVSM1" title="PostHog Status">
<img src="https://www.posthogstatus.com/posthog-icon.svg" class="card-img-top not-responsive" style="max-height: 15rem;" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://www.posthogstatus.com/incidents/01KSV6HJYKG5QJAP8HVTSQVSM1">
PostHog Status
</a>
</h5>
<p class="card-text line-clamp-3">Current status of PostHog services</p>
</div>
<a href="https://www.posthogstatus.com/incidents/01KSV6HJYKG5QJAP8HVTSQVSM1" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://www.posthogstatus.com/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />



<p class="d-inline-block text-truncate mb-0"> <span class="text-secondary">(www.posthogstatus.com)</span></p>
</a>
</div></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/AlesandroOrtiz/statuses/116681653867950081</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/AlesandroOrtiz/statuses/116681653867950081</guid><dc:creator><![CDATA[alesandroortiz@infosec.exchange]]></dc:creator><pubDate>Tue, 02 Jun 2026 17:19:03 GMT</pubDate></item><item><title><![CDATA[Reply to I have a few questions... on Sat, 30 May 2026 04:06:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/olearysec%40infosec.exchange">@<span>olearysec</span></a></span> Yeah, I posted about it here: <a href="https://infosec.exchange/@AlesandroOrtiz/116661218239511606" rel="nofollow noopener"><span>https://</span><span>infosec.exchange/@AlesandroOrt</span><span>iz/116661218239511606</span></a></p><p>Was still really hoping you were right.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/AlesandroOrtiz/statuses/116661549760402009</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/AlesandroOrtiz/statuses/116661549760402009</guid><dc:creator><![CDATA[alesandroortiz@infosec.exchange]]></dc:creator><pubDate>Sat, 30 May 2026 04:06:19 GMT</pubDate></item><item><title><![CDATA[Reply to I have a few questions... on Sat, 30 May 2026 04:04:27 GMT]]></title><description><![CDATA[<p><span><a href="/user/alesandroortiz%40infosec.exchange">@<span>AlesandroOrtiz</span></a></span> </p><p>Update: the 01:18 entry got edited. "Security exercise" is gone, now it says they're rotating keys after a research team confirmed an exploit in one of their AWS environments. So you called it. Incident-driven, not hygiene. Good catch.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/116590719847167786/statuses/116661542390148852</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/116590719847167786/statuses/116661542390148852</guid><dc:creator><![CDATA[olearysec@infosec.exchange]]></dc:creator><pubDate>Sat, 30 May 2026 04:04:27 GMT</pubDate></item><item><title><![CDATA[Reply to I have a few questions... on Sat, 30 May 2026 02:58:08 GMT]]></title><description><![CDATA[<p>Kudos to PostHog for the real-time disclosure at least. They could have disclosed this in a quiet blog post a week from now. Only customers subscribed to app status page incidents would be notified via email, so also need to see how they notify customers directly who aren't subscribed to status page.</p><p>Also <a href="https://infosec.exchange/tags/hugops" rel="tag">#<span>hugops</span></a> since security incidents are never fun.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/AlesandroOrtiz/statuses/116661281647427752</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/AlesandroOrtiz/statuses/116661281647427752</guid><dc:creator><![CDATA[alesandroortiz@infosec.exchange]]></dc:creator><pubDate>Sat, 30 May 2026 02:58:08 GMT</pubDate></item><item><title><![CDATA[Reply to I have a few questions... on Sat, 30 May 2026 02:42:00 GMT]]></title><description><![CDATA[<p><span><a href="/user/olearysec%40infosec.exchange">@<span>olearysec</span></a></span> Update: It's a security incident of sorts.</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://infosec.exchange/@AlesandroOrtiz/116661217123074045" title="Alesandro Ortiz 🇵🇷🏳️‍🌈 (@AlesandroOrtiz@infosec.exchange)">
<img src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/661/211/309/554/309/original/aad8257f63100489.png" class="card-img-top not-responsive" style="max-height: 15rem;" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://infosec.exchange/@AlesandroOrtiz/116661217123074045">
Alesandro Ortiz 🇵🇷🏳️‍🌈 (@AlesandroOrtiz@infosec.exchange)
</a>
</h5>
<p class="card-text line-clamp-3">Attached: 1 image

Sounds like an external security researcher was able to access one of PostHog's AWS environments.

Also note the quiet update of the existing status (same timestamp as earlier update; no email sent out to incident subscribers).

"We are rotating keys after a security research team was able to confirm an exploit in one of our AWS environments. We're working with the security research team on the issue. No keys were publicly available, and no data has been compromised. You may see impacts on exports, reverse proxies, and other services. We'll have more updates as we continue to work on this incident."

https://www.posthogstatus.com/incidents/01KSV6HJYKG5QJAP8HVTSQVSM1</p>
</div>
<a href="https://infosec.exchange/@AlesandroOrtiz/116661217123074045" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://infosec.exchange/packs/assets/favicon-16x16-DEOT6-He.png" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />





























<p class="d-inline-block text-truncate mb-0">Infosec Exchange <span class="text-secondary">(infosec.exchange)</span></p>
</a>
</div></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/AlesandroOrtiz/statuses/116661218239511606</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/AlesandroOrtiz/statuses/116661218239511606</guid><dc:creator><![CDATA[alesandroortiz@infosec.exchange]]></dc:creator><pubDate>Sat, 30 May 2026 02:42:00 GMT</pubDate></item><item><title><![CDATA[Reply to I have a few questions... on Sat, 30 May 2026 02:41:43 GMT]]></title><description><![CDATA[<p>Sounds like an external security researcher was able to access one of PostHog's AWS environments.</p><p>Also note the quiet update of the existing status (same timestamp as earlier update; no email sent out to incident subscribers).</p><p>"We are rotating keys after a security research team was able to confirm an exploit in one of our AWS environments. We're working with the security research team on the issue. No keys were publicly available, and no data has been compromised. You may see impacts on exports, reverse proxies, and other services. We'll have more updates as we continue to work on this incident."</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://www.posthogstatus.com/incidents/01KSV6HJYKG5QJAP8HVTSQVSM1" title="PostHog Status">
<img src="https://www.posthogstatus.com/posthog-icon.svg" class="card-img-top not-responsive" style="max-height: 15rem;" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://www.posthogstatus.com/incidents/01KSV6HJYKG5QJAP8HVTSQVSM1">
PostHog Status
</a>
</h5>
<p class="card-text line-clamp-3">Current status of PostHog services</p>
</div>
<a href="https://www.posthogstatus.com/incidents/01KSV6HJYKG5QJAP8HVTSQVSM1" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://www.posthogstatus.com/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />



<p class="d-inline-block text-truncate mb-0"> <span class="text-secondary">(www.posthogstatus.com)</span></p>
</a>
</div></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/AlesandroOrtiz/statuses/116661217123074045</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/AlesandroOrtiz/statuses/116661217123074045</guid><dc:creator><![CDATA[alesandroortiz@infosec.exchange]]></dc:creator><pubDate>Sat, 30 May 2026 02:41:43 GMT</pubDate></item><item><title><![CDATA[Reply to I have a few questions... on Sat, 30 May 2026 02:10:02 GMT]]></title><description><![CDATA[<p><span><a href="/user/olearysec%40infosec.exchange">@<span>olearysec</span></a></span> AFAIK this is the first time they've done any planned maintenance that impacted web app availability, going back several years.</p><p>There's been many unplanned issues that impacted web app availability, but none cited anything similar to this (like key rotation or security exercise).</p><p>I hope you're right and they forgot to announce it, but also seems unusual given they haven't done this before in a way that impacted web app availability, either as planned maintenance or unplanned maintenance. All the unplanned maintenance affecting web app uptime I've seen has never cited security exercise or key rotation.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/AlesandroOrtiz/statuses/116661092499835631</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/AlesandroOrtiz/statuses/116661092499835631</guid><dc:creator><![CDATA[alesandroortiz@infosec.exchange]]></dc:creator><pubDate>Sat, 30 May 2026 02:10:02 GMT</pubDate></item><item><title><![CDATA[Reply to I have a few questions... on Sat, 30 May 2026 01:52:18 GMT]]></title><description><![CDATA[<p><span><a href="/user/alesandroortiz%40infosec.exchange">@<span>AlesandroOrtiz</span></a></span> </p><p>"Unplanned" just means it wasn't on the maintenance calendar, not that it's an accident. A planned key rotation they didn't pre-announce lands there by default.</p><p>And it went from "doing maintenance" to "it's a security exercise" — that's the opposite of how a breach reads. Those escalate into an advisory and a "rotate your keys" email. None of that here. Fair to side-eye given the month we're having, but this looks like hygiene.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/116590719847167786/statuses/116661022802459368</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/116590719847167786/statuses/116661022802459368</guid><dc:creator><![CDATA[olearysec@infosec.exchange]]></dc:creator><pubDate>Sat, 30 May 2026 01:52:18 GMT</pubDate></item></channel></rss>