Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts.

Read the full article at SecurityWeek →