Brevo Supply Chain Attack: One API Key, 100,000 Sites
Attackers used a single hardcoded Cloudflare API key to hijack Brevo's CDN edge for five and a half hours on September 14, serving fake Cloudflare verification pages and silently installing a backdoor…