@arstechnica The phrase "...the threat actor updated ... an IDP ... used to authenticate to a production environment.." in the article is tantalizingly vague. I'm guessing that there was no more detail about the nature of the "production environment" @dangoodin?