Brevo: Malicious Cloudflare Worker Rewrote Responses for 100,000 Sites
On 14 September 2026, attackers used a long-lived Cloudflare API key hardcoded in Brevo's source to publish a malicious Worker. It rewrote HTTP responses at the edge for about four hours, affecting more than 100,000 websites; Brevo revoked the key and removed the malicious content by 15 September.
- Worker altered Brevo and customer scripts for about four hours
- Sansec: altered scripts loaded on over 100,000 websites
- Visitors saw a fake Cloudflare challenge with a ClickFix payload
- WordPress admins got a hidden Web Media Optimizer plugin
Read next
Security