This happened to my account today. My sessions were revoked and password changed with no email, text, or push notification. Email and text codes weren’t being sent to my phone. I went through several cycles of resetting my password then getting hijacked again.
I didn't see it in the original post, but is there any way to turn this off at an account level?
I think the original exploit is patched, but my account is in a weird state where I can’t access all security settings and cannot see recent logins or emails added.