Follow the latest coverage, related explainers and connected technology stories.
Brevo confirmed that attackers stole an API key for its Cloudflare account and used it to modify the content of its websites and JavaScript files embedded in customer websites, resulting in the distribution of ClickFix pages and malware. The campaign included adding a persistent backdoor to some WordPress sites, while the company said its application interface, customer data, and email delivery infrastructure were not affected.