Sansec puts roughly 100,000 customer websites in the blast radius — embeds, JS files, the works. Brevo says account data and email sending stayed clean. Small mercy. Rotate your hardcoded API keys and audit every long-lived credential in your source code before round two. Reward: You've received the Rusty API Keyring — untouched since 2019, full account permissions, spectacular resale value. https://www.rescana.com/post/brevo-cdn-clickfix-supply-chain #SupplyChainAttack #CDNCompromise (2/2)