Brevo confirmed that attackers stole a Cloudflare API key and used a malicious Cloudflare Worker to inject ClickFix scripts into Brevo pages and customer-embedded JavaScript for several hours on September 14. The compromise also pushed a fake WordPress plugin called “Web Media Optimizer” to some sites, while Brevo says its core app, API, email delivery systems, and customer account data were not affected. #Brevo #Cloudflare #ClickFix #WebMediaOptimizer #WordPress
Keypoints
- Attackers used a stolen Cloudflare API key with full permissions.
- A malicious Cloudflare Worker altered Brevo content at the CDN edge for about five and a half hours.
- The injected scripts showed a fake Cloudflare verification page and ClickFix instructions.
- Some WordPress sites received a malicious plugin posing as “Web Media Optimizer” for persistence and backdoor access.
- Brevo revoked the key, removed attacker infrastructure, and says core systems and customer data were not impacted.