Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: cloudflare-worker (1 article)Clear

Stolen Cloudflare key let attackers poison Brevo scripts on 100,000 sites

Attackers stole a Cloudflare API key from marketing platform Brevo and used it to inject malicious code into the scripts that Brevo's customers embed on their own websites, affecting more than 100,000 sites. The key was long-lived, had full account permissions, and was hardcoded in application source code, which let the attackers create a Cloudflare Worker that modified Brevo's forms, widget, and loader scripts at the network edge for about five and a half hours. Visitors saw a fake verification page with ClickFix instructions to run a command on Windows, and on WordPress sites where an admin was logged in, the script tried to silently install a backdoor plugin.

Check
Keep API keys out of source code, replace long-lived full-permission keys with scoped short-lived credentials in a secrets manager, and review third-party scripts your sites embed for unexpected changes or injected content.
Affected
Websites embedding Brevo's scripts and their visitors during the incident; a stolen key let attackers modify those trusted scripts at the edge to push ClickFix malware and a WordPress backdoor plugin.
Fix
Scope and rotate API keys, store them outside code, constrain embedded third-party scripts with subresource integrity and content security policy, monitor for edge content changes, and teach users to reject paste-a-command prompts.