Security News Brevo supply-chain attack injected ClickFix scripts on customer sites BleepingComputer Daniel Bender 17 Sep 2026 Share Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware.