CyberHighSingle-sourceAccelerating
7.2
Brevo supply-chain attack: stolen Cloudflare API key injects ClickFix malware
BleepingComputerLO·US·3 days ago
Attackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts into websites using Brevo's services, affecting up to 100,000 sites. The full scope and payload details remain unclear, but this represents a significant supply-chain compromise with broad reach.