chiprook
← Security
SecuritySeptember 18, 2026, 00:11

Brevo supply-chain attack injected ClickFix scripts on customer sites

Attackers stole a long-lived Cloudflare API key hardcoded in Brevo's source code and, via a malicious Cloudflare Worker, replaced content on brevo.com, sendinblue.com, and sibforms.com for about 5.5 hours, as well as in form scripts and widgets embedded on customer sites. Sansec estimates up to 100,000 sites may be affected; visitors saw a fake Cloudflare check and ClickFix instructions.

Brevo supply-chain attack injected ClickFix scripts on customer sites
#Brevo#Cloudflare#WordPress#Sansec
Read next
Security

Sekoia uncovers Exvicy, a new ClickFix MaaS built on ErrTraffic code

Security

Cyberattack hits University of Munich, student data at risk

Security

TASK#STOMP Windows backdoor steals documents, Wi-Fi passwords and screenshots

Security

CVE-2026-81657 in IBM Guardium: deserialization flaw rated 9.8