Brevo just dropped the post-mortem on a supply-chain hit. 🔓 Attackers stole a long-lived Cloudflare API key that was hardcoded in Brevo’s source. They spun up a malicious Worker and rewrote CDN edge responses for ~5.5 hours on Sep 14 (16:07–20:30 UTC). Sansec says up to ~100k sites embedding Brevo forms, widgets, or SDK loaders were in the blast radius. Visitors got fake Cloudflare checks → ClickFix malware. Logged-in WordPress admins risked a persistent backdoor plugin. Origin files stayed clean. App, API, email delivery, and customer account data were not hit. ✅ Hardcoded CDN keys still eating companies alive. How many of your SaaS vendors still ship secrets in app code? #Cybersecurity #InfoSec #Technology
Harsha Nandhan ReddyShare
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.