Malicious Cloudflare Worker Hit Brevo for 4 Hours, Affecting 100,000+ Sites
On September 14, 2026, attackers used a hardcoded Cloudflare API key found in Brevo's source code to deploy a malicious Cloudflare Worker that silently altered HTTP responses at the network edge for approximately four hours. Because the attack modified responses in transit rather than touching origin files, standard integrity checks and file hash monitoring failed to detect it, and security firm Sansec estimated over 100,000 websites loaded the tampered scripts. The Worker stripped security headers and injected a fake browser-verification overlay mimicking a Cloudflare challenge, tricking visitors into running a PowerShell command via a ClickFix technique that moved code execution onto their own machines. The incident came just four days after Brevo disclosed a separate SAML single sign-on vulnerability that had exposed 138 customer accounts and led to phishing emails and data exports, though Brevo has not confirmed any link between the two events. Brevo revoked the compromised key, removed the hardcoded credential, deleted attacker-created DNS records, and purged the edge cache; both Brevo and Cloudflare confirmed the malicious content was fully removed by September 15, 2026.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in