Surfshark Exposes Internal Servers to the Internet
Surfshark said hackers reached one of its internal test servers after a configuration error left it exposed to the internet, and the company said it is still checking whether internal systems or customer-facing services were affected.
The mistake turned infrastructure meant to stay private into something reachable like a public service, so attackers did not need to break through a login wall first. That matters because the exposed path may have covered more than one box: Surfshark is also investigating proxy infrastructure, which raises the question of whether adjacent internal tooling shared the same weak isolation.
For organizations that run separate test, proxy, and production environments, the durable issue is trust boundaries, not a single server. If those layers share routing or access assumptions, one configuration slip can widen the blast radius beyond the system that first showed up in logs.