CyberNotableSingle-source
5.1
Hacked HBO Max Reddit Account Used in ClickFix Malware Campaign
SecurityWeekLO·3 days ago
Brevo confirmed attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites, distributing malware. The scope of affected customers and the duration of compromise remain unclear. This is a supply-chain attack targeting a marketing platform, potentially impacting numerous downstream organizations.