This was announced here earlier: #1542491
Attackers have already drained Lightning nodes operated by Foundation and Citadel21, and BTCPay Server quietly restricted remote Lightning access before most operators even knew there was a threat.
BTCPay's response was to restrict remote Lightning access across the board, essentially pulling the emergency brake. That decision protects future users but does nothing for anyone already hit. The attacker or attackers accessed connected Lightning nodes through a vector in remote management, siphoning funds before operators could react.
It's curious to see how media sees things in delay. The issue has already been fixed, and here is what you should do #1543355