Comment on Security Hole in SendgridComments−gmansoor12yBCC every message is evil, as it can be misused as in this case. SendGrid should never allow that, or at least should flag such behavior. At the minimum, they should notified account owners of this change.−icebraining12yThe attacker got SG to change the email on file, so the notification would just be sent to him.
Comments
BCC every message is evil, as it can be misused as in this case. SendGrid should never allow that, or at least should flag such behavior. At the minimum, they should notified account owners of this change.
The attacker got SG to change the email on file, so the notification would just be sent to him.