> Brevo supply-chain attack injected ClickFix scripts on customer sites
[AUTHOR: Bill Toulas]
[DATE: 17/09/2026 17:11]
[LANGUAGE: EN]
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. [...]