Cloud · InfosecFeed Brief

Brevo supply-chain attack injected ClickFix scripts on customer sites

Cloud

What you need to know

Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. [...]

Source transparency

This is an InfosecFeed curated brief based on reporting from BleepingComputer. InfosecFeed does not claim ownership of the original reporting.

Read the original report at BleepingComputer ↗