ZeroHour
Product

Web Media Optimizer

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Brevo supply-chain attack injected ClickFix scripts on customer sites

Attackers used a stolen Cloudflare API key to inject ClickFix malware-delivery scripts into Brevo sites and customer-embedded scripts for five hours.

Brevo confirmed attackers stole a long-lived Cloudflare API key with full account permissions that had been hardcoded in source code, and used it to create a malicious Cloudflare Worker that rewrote content at the CDN edge for roughly 5.5 hours on September 14 (16:07-20:30 UTC), affecting brevo.com, sendinblue.com, sibforms.com, and customer-embedded Brevo scripts; Sansec estimated up to 100,000 websites may have been exposed. Visitors saw fake Cloudflare verification pages with ClickFix instructions to run a Windows command, and the injected code uploaded a persistent WordPress backdoor plugin named 'Web Media Optimizer' to sites where logged-in admins browsed. The backdoor hides from the plugin list, persists in the must-use plugins directory, contacts attacker servers, and contains a hardcoded key to forge WordPress administrator sessions. Brevo said app.brevo.com, its API, email delivery, and customer data were unaffected; a separate September 10 SSO incident led to Trezor phishing hitting 347,000 addresses with at least 2,500 accounts compromised.

BleepingComputerupdated · 7h agofirst · 23h agoData breach in the wild 5 sources

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.