CuraSec

Act active

Brevo supply-chain attack injected ClickFix scripts on customer sites

2026-09-18 14:58 UTC · BleepingComputer · read the source ↗ #supply-chain#clickfix#saas-breach
  • Engineer — Act: If your web properties embed Brevo JavaScript, audit those pages now for ClickFix script injection and remove or replace the embed; also audit your own Cloudflare API key scopes and rotation practices to prevent analogous key theft.
  • SOC/IR — Act: Hunt for ClickFix execution artifacts—browser-spawned PowerShell, clipboard-injected command execution—on endpoints whose users visited Brevo-embedded pages during the compromise window; check EDR for downstream post-exploitation activity from any hits.
  • Leader — Act: Confirm whether your organization uses Brevo’s embedded JS on customer-facing sites; if so, determine the exposure window and assess whether visitors received malicious scripts triggering breach-notification or disclosure obligations under applicable regulations.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.