Skip to main content
CyberSingle-sourceHighDevelopingFeatured
7.2

Brevo supply-chain attack: stolen Cloudflare API key injects ClickFix malware

Brevo confirmed attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites, distributing malware. The scope of affected customers and the duration of compromise remain unclear. This is a supply-chain attack targeting a marketing platform, potentially impacting numerous downstream organizations.

BleepingComputer3 days agoUSengCredibility 30%View source

Score Breakdown

Mosaic Score7.2
Confidence0.7
Significance0.8
Source credibility0.3

Intelligence Tags

Entities

countryconcept
Source

Part of a situation

Related signals

8 found