Act
active
Brevo supply-chain attack injected ClickFix scripts on customer sites
- Engineer — Act: If your web properties embed Brevo JavaScript, audit those pages now for ClickFix script injection and remove or replace the embed; also audit your own Cloudflare API key scopes and rotation practices to prevent analogous key theft.
- SOC/IR — Act: Hunt for ClickFix execution artifacts—browser-spawned PowerShell, clipboard-injected command execution—on endpoints whose users visited Brevo-embedded pages during the compromise window; check EDR for downstream post-exploitation activity from any hits.
- Leader — Act: Confirm whether your organization uses Brevo’s embedded JS on customer-facing sites; if so, determine the exposure window and assess whether visitors received malicious scripts triggering breach-notification or disclosure obligations under applicable regulations.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.