Yes, all stratum servers are back online and shares are now being processed and will be paid as usual.
It seems, at this stage, the coins lost were relatively small in number so the pool will be able to cover all losses. Payments are still on hold until I can re-credit accounts that were affected - writing a script to do that now. Once that is done website will go back on line.
Please note all password and payment addresses needed to be reset as the attacker was able to 'sniff' passwords and changed users payout addresses once he logged into their accounts. As we have no way of knowing what passwords and or payout addresses have been compromised decided it would be safest to reset both so attacker cannot login to accounts that were compromised and threshold payments don't go to the attackers addresses. I know its a major pain in the ass but better than losing more coins.
Ahh! Fantastic news! It seems Miningpool.co is well on it's way to settling back to normal again.
I agree with changing passwords. A vulnerability like that could have cost users hundreds of coins, or even worse if the imaginable had happened and if you hadn't have caught it in time. Once the site goes live again, a change of password will be done, and likewise.. I hope.. A change of payout address.
I presume other users of the site who are unaware of the vulnerability will be notified on the main page that a change of password will be advisable?
It's a major pain in the arse that is worth it when it comes to currency.