The hacker claims it to be a CF 0-day vulnerability:
> 05:05 < ryan_> manager.linode.com was breached with a coldfusion exploit
...
> 05:33 < Ruchira> ryan||: give us the link to cold fusion vulnerability that you are talking about
> 05:34 < ryan||> Ruchira: 0day
> 05:34 < ryan||> linode staff apparently failed to deduce it themselves and relied on chmodding CFIDE to 000