discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Brevo supply-chain attack injected ClickFix scripts on customer sites

Brevo confirms attackers used a stolen Cloudflare API key to inject malicious ClickFix scripts into its and its customers' sites, affecting up to 100,000 websites.

By Bill Toulas·Sep 17·bleepingcomputer.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

Brevo supply-chain attack injected ClickFix scripts on customer sites
Image: bleepingcomputer.com

Brevo reports a supply chain attack where attackers used a stolen API key to inject malicious ClickFix scripts into Brevo and its customers' sites, affecting up to 100,000 websites.

Why it matters

This attack highlights the importance of securing API keys and the potential risks of compromised credentials in a supply chain attack.

Bad guys stole a special code from Brevo and used it to put sneaky stuff on Brevo's and other websites. This made other websites show fake messages and let the bad guys do bad things.

Analysis

{"heading_1":"The Attack","paragraph_1":"Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware.","paragraph_2":"The attack affected pages on brevo.com, sendinblue.com, login/account/my/onboarding.brevo.com, and sibforms.com. The Cloudflare worker also modified the Brevo forms script, Brevo Conversations widget, and the Brevo SDK loader scripts that customers embed on their websites.","paragraph_3":"Brevo says the attackers used the API key to create a malicious Cloudflare Worker that modified content at the CDN edge for approximately five and a half hours on September 14. The attack was detected and mitigated by Brevo within a few hours of the compromise.","paragraph_4":"Brevo says the key may have been compromised as early as late August, but there's no evidence of prior malicious activity. Upon detecting the compromise, Brevo removed the Worker and its routes, revoked the compromised key and credentials created with it, removed the hardcoded credential from its source code, deleted attacker-controlled hostnames, and purged its edge caches."}

Key points

  • Brevo confirmed the attack and says it affected up to 100,000 websites.
  • The attack was detected and mitigated within a few hours of the compromise.
  • Brevo says the key may have been compromised as early as late August, but there's no evidence of prior malicious activity.
The Upside

The attack was quickly detected and mitigated, and Brevo took steps to prevent it from happening again. This shows that security teams can respond to such attacks effectively.

The Downside

The attack could have affected more sites if Brevo had not acted quickly. The incident also highlights the importance of securing API keys and monitoring for suspicious activity.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritysupply-chainmalwarebrevoclickfix

Author

Bill Toulas

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 17, 2026

Source

bleepingcomputer.com

Share

Topics

securitysupply-chainmalwarebrevoclickfix

Related

More from this desk

Oct 7·bleepingcomputer.com

Ransomware recovery CEO charged over secret ransom payments

MonsterCloud CEO charged with fraud for secretly paying ransomware attackers, charging victims up to $19 million for recovery services.

Oct 7·wired.com

Shaq Got Hacked. Now He’s Pitching for a VPN

Shaq talks about his experience with cyber security and the importance of personal privacy. NordVPN is helping him raise awareness.

Oct 7·bleepingcomputer.com

FBI Warns of Ongoing FortiBleed Attacks Locking Out FortiGate VPN Admins

FBI warns of ongoing FortiBleed attacks targeting Fortinet FortiGate firewalls and SSL VPN gateways, locking out legitimate administrators.

Oct 7·bleepingcomputer.com

Hackers Hijack Google Domains After Breaching ccTLD Registries

Hackers obtained unauthorized HTTPS certificates for Google domains and hijacked ccTLD domains for Ghana, American Samoa, and Sierra Leone. Google blocked unauthorized certificates and notified affected organizations.