Brevo, the marketing vendor behind Sendinblue, has confirmed that attackers stole a long-lived Cloudflare API key with full account permissions that had been hardcoded in application source code, then used it to create a malicious Cloudflare Worker that rewrote content at the CDN edge for roughly five and a half hours on 14 September. The Worker modified pages on brevo.com, sendinblue.com and account domains, plus the Brevo forms, Conversations widget and SDK loader scripts that customers embed on their own sites; security firm Sansec assesses the reach at up to 100,000 websites. Because the rewrite happened edge-side and removed security headers such as Content-Security-Policy, origin servers and files remained unmodified and standard integrity checks did not flag the change. Visitors were shown a fake Cloudflare verification page with ClickFix instructions to run a command on Windows; on WordPress sites embedding an affected widget, the script checked whether the visitor was logged in as an administrator and attempted to install a plugin called "Web Media Optimizer" that acts as a persistent backdoor, hides from the plugin list, stores a backup command URL, and hardcodes an authentication key that can mint a WordPress administrator session without a password. Brevo says its API, email delivery and customer account data were unaffected and revoked the key; the exposure window is 16:07β20:30 UTC.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-09-18 |
| Source | BleepingComputer |
| Reliability | Tier 2 |