So after doing some quick reading, turns out GFW legit didn't bother to fix the vulnerability from the first time their Network-like service briefly launched. Until a few hours ago, anyone who put in payment details had their personal info exposed due to the payment system not being secure.
|