• Sources: primary
  • Summary: Brevo states the attackers held a long-lived Cloudflare API key with full account permissions that was hardcoded in application source code, and used it to create a Cloudflare Worker that rewrote responses at the CDN edge on 2026-09-14 between 16:07 and 20:30 UTC. The Worker stripped Content-Security-Policy headers while origin servers and files stayed unmodified, so integrity checks against the origin did not detect the change. It altered the Brevo forms script, the Conversations widget, and the SDK loader that customers embed on their own sites, which Sansec reports may have reached up to 100,000 websites. On WordPress sites the injected script checked whether the visitor was a logged-in administrator and attempted to install a backdoor plugin named Web Media Optimizer, which hides itself from the plugin list, copies itself into the must-use plugins directory, and carries a hardcoded key granting an administrator session without the password.
  • Why it matters: The edge sat above every artifact the customer could verify, so a stolen CDN credential produced a script substitution that file and origin integrity checks could not see, and any WordPress administrator who browsed an affected site while logged in on 2026-09-14 has plugins installed that day and administrator passwords to audit.
  • Follow-up: Whether Brevo or Sansec publishes a confirmed count of affected sites, which currently stands only as an upper estimate.

send feedback on this story