security1 publisher
Attackers rewrote Brevo's embedded scripts at Cloudflare's edge with a hardcoded full-permission key
Brevo says a long-lived Cloudflare key with full account permissions sat in its application source code, and the Worker built with it stripped Content-Security-Policy headers from scripts that Sansec estimates reach 100,000 sites.
Publishers:bleepingcomputer.com
Reality
- Evidence62
- Adoption45
- Hype gap−10
- Incentives62
- Confidence58