Piki wrote:
I'm certainly not asking for any sympathy. I just came on to post in case there was some sort of security exploitation. Getting all those emails at once was completely unexpected, and with them coming through over a period of roughly 20 minutes, it was rather annoying. With all the security hackings that have been happing with my friends, and the ones that happened to me several months before I discovered Linode, I'm a bit paranoid about my digital security.
Completely understood. You can't be too paranoid about security
But I'm still suspecting that it was just another bug with the already bug-riddled member database code, rather than the result of malicious activity. Bugs like this can stay hidden for years, suddenly show up when there's a rare coincidence of user IDs, thread IDs, and the current phase of the moon, and then disappear again until the next time. Even as we speak, somebody somewhere might be wondering why he's not getting notification e-mails for threads he subscribed to. But that's a lot less noticeable than getting spammed, hence it doesn't get reported.
Since you posted the full headers including Message IDs, Linode staff may be able to track them down -- or at least change their settings so that any future incidence of this bug goes on the record. While they're doing so, just change your passwords and relax. If you get any more e-mails, please post those Message IDs, too.
Take it easy, life's too short to get all stressed up.