We've had four customers affected by this incident due to a staff error in our Debian 11 system image for a user named "a" with a weak password. Debian 10 and Centos 7 images appear to be unaffected, but users are advised to check for themselves. Current Debian 11 mirrors have removed this user.
1. Delete the user with the username ...