>>804335Hello OP, thank you for bringing this to our attention.
I checked our code, and given the information available so far, it seems to me that the two hacks could have been made by a disgruntled staff members.
I was able to identify a possible entrypoint for the exploit and deployed a patch to fix it.
Right now we should be safe.