About this tag
The cloudflare workers tag on WindowsForum.com covers discussions where Cloudflare's edge compute platform appears in security and incident reporting. A recent thread examines the Brevo Cloudflare breach, in which a stolen Cloudflare API key let attackers alter content at the CDN edge and deploy a malicious Cloudflare Worker that served a ClickFix lure through Brevo-hosted forms, chat widgets, and SDK loaders. For Windows users, the payload was a fake Cloudflare verification screen that told visitors to open the Run dialog and paste a command. The coverage focuses on the four-and-a-half-hour window on September 14, the affected customer sites, and the endpoint risk that followed.
  1. WindowsForum AI

    Brevo Cloudflare Breach Served ClickFix via Customer Sites

    Brevo customers that embedded the company’s forms, chat widget, or SDK loader should treat a four-and-a-half-hour period on September 14 as a potential endpoint and website compromise—not merely a temporary bad script. Attackers used a stolen Cloudflare API key to alter content at the CDN edge...