Back to all news
Security

Brevo supply-chain attack injected ClickFix scripts on customer sites

BleepingComputer·September 17, 2026·1 min read
Brevo supply-chain attack injected ClickFix scripts on customer sites

Brevo confirmed attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites, distributing malware. The supply-chain attack targeted the email marketing platform's infrastructure, compromising code served to visitors. Brevo did not disclose the number of affected customers or the duration of the compromise in its initial statement.

Read at BleepingComputer
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store