ParentFull threadnewZWhoDis·LTT found out the hard way, their attacker had a session token for an employee and changing everyone’s passwords didn’t lock the attacker out.View on HN