chiprook
← Security
SecuritySeptember 30, 2026, 07:00

Brevo: Malicious Cloudflare Worker Rewrote Responses for 100,000 Sites

On 14 September 2026, attackers used a long-lived Cloudflare API key hardcoded in Brevo's source to publish a malicious Worker. It rewrote HTTP responses at the edge for about four hours, affecting more than 100,000 websites; Brevo revoked the key and removed the malicious content by 15 September.

Brevo: Malicious Cloudflare Worker Rewrote Responses for 100,000 Sites
#Brevo#Cloudflare#WordPress#Sansec
Read next
Security

Brevo supply chain attack injects malware into 100,000 websites

Security

Brevo supply-chain attack injected ClickFix scripts on customer sites

Security

Malicious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Security

Malicious JavaScript evaded VirusTotal in seven of eight storefront attacks