Tech News
← Home  ·  All topics

Cloudflare Api Key

1 GoKawiil brief on this topic

Brevo breach used stolen Cloudflare API key to push ClickFix malware to sites

Brevo disclosed that hackers obtained a hardcoded, full-permission Cloudflare API key and used it to deploy a rogue Cloudflare Worker that rewrote content at the CDN edge for roughly 5.5 hours on September 14. The tampered scripts, including Brevo's forms widget, Conversations tool and SDK loader embedded on customer sites, were altered to serve ClickFix malware while stripping security headers to evade detection.