conv.

All stories
SecurityQuiet 6d · day 8

Brevo supply-chain attack injects ClickFix malware via Cloudflare API theft

Attackers stole a Cloudflare API key to inject malicious scripts across thousands of customer websites.

What to know

  • Attackers stole a Cloudflare API key tied to Brevo and used it to inject ClickFix malware scripts across thousands of websites on Monday.
  • The attack compromised Brevo's own domains (brevo.com, sendinblue.com) and three JavaScript files embedded on customer sites, including WordPress plugins.
  • This is a supply-chain attack: customers' own websites were compromised through Brevo's infrastructure, creating widespread exposure.

Brevo Compromised email and marketing providerCloudflare Infrastructure provider

Brevo supply-chain attack injects ClickFix malware via Cloudflare API theft
pcmag.com

How it unfolded 1 development · click the chart to see its coverage posts

Peak 2 pieces in two hours at Sep 17, 11 AM; 7 pieces over 8 days (1 article · 6 posts) Sep 16, 3 PM — 1 piece · 1 post — Mastodon 1Sep 16, 5 PM — quietSep 16, 7 PM — quietSep 16, 9 PM — quietSep 16, 11 PM — quietSep 17, 1 AM — quietSep 17, 3 AM — quietSep 17, 5 AM — quietSep 17, 7 AM — quietSep 17, 9 AM — quietSep 17, 11 AM — 2 pieces · 1 article · 1 post — Mastodon 2Sep 17, 1 PM — quietSep 17, 3 PM — 1 piece · 1 post — Hacker News 1Sep 17, 5 PM — 2 pieces · 2 posts — Mastodon 2Sep 17, 7 PM — quietSep 17, 9 PM — quietSep 17, 11 PM — quietSep 18, 1 AM — quietSep 18, 3 AM — 1 piece · 1 post — Mastodon 1Sep 18, 5 AM — quietSep 18, 7 AM — quietSep 18, 9 AM — quietSep 18, 11 AM — quietSep 18, 1 PM — quietSep 18, 3 PM — quietSep 18, 5 PM — quietSep 18, 7 PM — quietSep 18, 9 PM — quietSep 18, 11 PM — quietSep 19, 1 AM — quietSep 19, 3 AM — quietSep 19, 5 AM — quietSep 19, 7 AM — quietSep 19, 9 AM — quietSep 19, 11 AM — quietSep 19, 1 PM — quietSep 19, 3 PM — quietSep 19, 5 PM — quietSep 19, 7 PM — quietSep 19, 9 PM — quietSep 19, 11 PM — quietSep 20, 1 AM — quietSep 20, 3 AM — quietSep 20, 5 AM — quietSep 20, 7 AM — quietSep 20, 9 AM — quietSep 20, 11 AM — quietSep 20, 1 PM — quietSep 20, 3 PM — quietSep 20, 5 PM — quietSep 20, 7 PM — quietSep 20, 9 PM — quietSep 20, 11 PM — quietSep 21, 1 AM — quietSep 21, 3 AM — quietSep 21, 5 AM — quietSep 21, 7 AM — quietSep 21, 9 AM — quietSep 21, 11 AM — quietSep 21, 1 PM — quietSep 21, 3 PM — quietSep 21, 5 PM — quietSep 21, 7 PM — quietSep 21, 9 PM — quietSep 21, 11 PM — quietSep 22, 1 AM — quietSep 22, 3 AM — quietSep 22, 5 AM — quietSep 22, 7 AM — quietSep 22, 9 AM — quietSep 22, 11 AM — quietSep 22, 1 PM — quietSep 22, 3 PM — quietSep 22, 5 PM — quietSep 22, 7 PM — quietSep 22, 9 PM — quietSep 22, 11 PM — quietYesterday, 1 AM — quietYesterday, 3 AM — quietYesterday, 5 AM — quietYesterday, 7 AM — quietYesterday, 9 AM — quietYesterday, 11 AM — quietYesterday, 1 PM — quietYesterday, 3 PM — quietYesterday, 5 PM — quietYesterday, 7 PM — quietYesterday, 9 PM — quietYesterday, 11 PM — quietToday, 1 AM — quietToday, 3 AM — quietToday, 5 AM — quietToday, 7 AM — quietToday, 9 AM — quietToday, 11 AM — quiet 1
Sep 17Sep 18Sep 19Sep 20Sep 21Sep 22yesterdaynow · 12:57 PM ET
  1. 1

    Brevo confirms supply-chain attack to media outlets

    Brevo publicly acknowledged the breach and detailed how attackers exploited the compromised Cloudflare API key to distribute ClickFix malware across thousands of websites via the company's embedded JavaScript files.

    “Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware.”
    — Brevo
    1. 1 outlet first by Mastodon, 6d ago · read ↗

    • kim_harding@mastodon.scot

      Hack at Marketing Vendor Exploited To Widely Spread ClickFix Malware Attack https:// uk.pcmag.com/security/167382/h ack-at-marketing-vendor-exploited-to-widely-spread-clickfix-malware-attack A hack at Brevo, an online marketing vendor, created a pathway to place a ClickFix-style attack across numerous websites on Monday to try and trick users into…

      kim_harding@mastodon.scotMastodon6d agoview on Mastodon ↗
    2 more of the top 3 · 4 posts in this stretch
    • BleepingComputer@infosec.exchange

      Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. https://www. bleepingcomputer.com/news/secu rity/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/

      BleepingComputer@infosec.exchangeMastodon6d agoview on Mastodon ↗
    • PCMag@mastodon.social

      A hack at Brevo, an online marketing vendor, created a pathway to place a ClickFix-style attack across possibly thousands of websites on Monday to try and trick users into installing malware. https://www. pcmag.com/news/hack-at-marketi ng-vendor-exploited-to-widely-spread-clickfix-malware-attack

      PCMag@mastodon.socialMastodon6d agoview on Mastodon ↗
    all of them →
  2. background

    Malicious code injected into Brevo domains and customer JavaScript files — The injected code appeared on brevo.com, sendinblue.com, and three JavaScript files that Brevo customers embed on their own websites, including the company's WordPress widget. The fake verification screens were designed to trick users into installing malware.

  3. background

    Attackers compromise Brevo via stolen Cloudflare API key — Attackers stole a long-lived Cloudflare API key associated with Brevo and used it to inject malicious ClickFix scripts across the company's infrastructure and customer sites.

What people are saying 2 voices from 1 site · best of 5 · verbatim