Tag: Brevo


  • Brevo Supply-Chain Attack Injects ClickFix Malware

    Attackers used a stolen Cloudflare API key to inject malicious scripts into Brevo websites and customer-facing components. The Brevo supply-chain attack exposed visitors to ClickFix lures and targeted WordPress administrators with a persistent backdoor. Attackers Compromise Cloudflare API Key Brevo confirmed that attackers obtained a long-lived Cloudflare API key with full account permissions. The customer…