Tag: clickfix scripts
1 article

Brevo Cloudflare API Key Compromise Injects Malicious ClickFix Scripts
Attackers compromised a Cloudflare API key with full account permissions, allowing them to inject malicious scripts into website responses by creating a rogue Cloudflare Worker that cleverly evaded standard security checks. By modifying content at the CDN edge and removing key security headers, the hackers kept origin servers and files untouched, making the tampering difficult to detect.