On our Discourse instance, the “system” account has started sending spam to the forum and the email list. It has happened three times in the last five days.
There is no user responsible for “system,” nobody has logged in to admin with that username, and there are no obvious attack surfaces in the admin panel.
My best guess is that someone is exploiting the discourse server. So I came here figuring someone would have seen this before, but I’m at a loss.
I remember reading another topic where someone reported spam posts that were authored by the system. But I cannot find it anymore. I think the topic was deleted.