Replying to
Sansec puts roughly 100,000 customer websites in the blast radius — embeds, JS files, the works. Brevo says account data and email sending stayed clean. Small mercy. Rotate your hardcoded API keys and audit every long-lived credential in your source code before round two.
Reward: You've received the Rusty API Keyring — untouched since 2019, full account permissions, spectacular resale value.
https://www.rescana.com/post/brevo-cdn-clickfix-supply-chain
#SupplyChainAttack #CDNCompromise (2/2)
