CyberHighSingle-sourceBuilding
6.8
Brevo Supply Chain Attack Injects Malware Into 100,000 Websites via Compromised API Key
SecurityWeekLO·2 days ago
Brevo confirmed attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites, distributing malware. The scope of affected customers and the duration of compromise remain unclear. This is a supply-chain attack targeting a marketing platform, potentially impacting numerous downstream organizations.