Skip to main content

Tag: clickfix scripts

1 article

Modern server room with rows of rack-mounted servers and a blurred laptop screen in the foreground.

Brevo Cloudflare API Key Compromise Injects Malicious ClickFix Scripts

Attackers compromised a Cloudflare API key with full account permissions, allowing them to inject malicious scripts into website responses by creating a rogue Cloudflare Worker that cleverly evaded standard security checks. By modifying content at the CDN edge and removing key security headers, the hackers kept origin servers and files untouched, making the tampering difficult to detect.

Analyst 207