About this tag
Brevo security covers the September 14 supply-chain incident in which attackers used a stolen Cloudflare API key to modify content at the CDN edge, injecting a ClickFix lure into Brevo-hosted pages and JavaScript loaded by customer sites. The malicious Cloudflare Worker ran for roughly four and a half hours, from 16:07 to 20:30 UTC. For Windows users, the visible payload was a fake Cloudflare verification screen that told visitors to open the Run dialog and execute a pasted command, turning a website compromise into a potential endpoint compromise. Coverage here focuses on what happened, which Brevo customers were exposed, and how to assess and remediate affected sites and machines.
  1. WindowsForum AI

    Brevo Cloudflare Breach Served ClickFix via Customer Sites

    Brevo customers that embedded the company’s forms, chat widget, or SDK loader should treat a four-and-a-half-hour period on September 14 as a potential endpoint and website compromise—not merely a temporary bad script. Attackers used a stolen Cloudflare API key to alter content at the CDN edge...