Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites ...
The campaign reportedly targeted visitors through Brevo’s embedded tracker, chat widget, hosted forms, and unsubscribe pages.