Skip to main content
CyberSingle-sourceHighDevelopingFeatured
7.2

Brevo supply-chain attack: stolen Cloudflare API key injects ClickFix malware

Brevo confirmed attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites, distributing malware. The scope of affected customers and the duration of compromise remain unclear. This is a supply-chain attack targeting a marketing platform, potentially impacting numerous downstream organizations.

BleepingComputerabout 19 hours agoUSengCredibility 30%View source

Score Breakdown

Mosaic Score7.2
Confidence0.7
Significance0.8
Source credibility0.3

Intelligence Tags

Entities

countryconcept
Source

Related signals

8 found