Brevo Supply Chain Attack Used Cloudflare API Key to Inject Malware for 5+ Hours
A threat actor obtained a highly privileged Cloudflare API key belonging to email marketing firm Brevo and used it to rewrite web responses at the CDN edge, without touching Brevo's origin servers. The attack, which lasted approximately five hours and 29 minutes, injected ClickFix scripts that tricked visitors into running malicious commands via the Windows Run dialog. A separate attack path targeted logged-in WordPress administrators whose sites embedded Brevo's Conversations widget, attempting to silently install an unauthorized plugin called Web Media Optimizer. The rogue plugin was designed to inject additional JavaScript and create illegitimate admin sessions, though confirmed successful installations across affected sites have not been established. Security firm Sansec estimated the injection may have reached over 100,000 sites based on widget embedding data, but this figure does not represent confirmed compromises.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in