@RBBL_ROUZR Not mainly. It was a CSRF-style platform flaw: a crafted link could auto-submit attacker instructions and progress through build, publish and scheduling without clear confirmation. The click triggered it; the missing authorization boundary was the bug. It was patched June 8.