Adform quietly put out an updated statement and regulatory filing saying the attack only worked over sites served with http, rather than https.
Does anybody understand _why_ they think this? The script itself was served over https via their endpoint, I can't see any browser controls that stop it when embedded on https:// urls
https://site.adform.com/resources/newsroom/security-incident-company-update/


