As noted in my other reply, their entire attacking network is suspect from where I'm sitting. I don't work for Cloudflare, so I can't really say if they're passing through traffic for some customer that has been compromised by a botnet (or whatever), or if they've been compromised themselves as part of a supply chain attack. I'm sure you understand this is *especially* concerning when they're sitting in the middle of the process of issuing security certificates! 97689740cd073cd8205f52f59ba85a7572280cb63dd5774da6d9420232e83783