Home / Sep 18, 2026 / Story
0
#3 BleepingComputer general September 17, 2026 at 17:11 UTC

Brevo supply-chain attack injected ClickFix scripts on customer sites

By Bill Toulas

AI Summary

A supply-chain attack against email platform Brevo saw attackers steal a Cloudflare API key to inject malicious ClickFix scripts into Brevo's own websites and JavaScript files embedded on customer sites, enabling downstream malware distribution. The incident illustrates how a single stolen cloud service credential can propagate malicious payloads across thousands of third-party sites relying on shared JS assets.

Relevance score: 88.0/100

# More from September 18