Brevo Supply-Chain Attack Injected ClickFix Scripts on Customer Sites

On September 14, 2026, threat actors executed a supply-chain attack against Brevo by leveraging a compromised, long-lived Cloudflare API key that had been hardcoded into the company's application source code. Between 16:07 and 20:30 UTC, the attackers used this key to deploy a malicious Cloudflare Worker that modified content at the CDN edge, stripping Content-Security-Policy headers and injecting ClickFix scripts into Brevo's domains and embedded customer assets, potentially impacting up to 100,000 websites. The injected scripts presented visitors with fake Cloudflare verification prompts to execute malicious Windows commands, while also targeting logged-in WordPress administrators to silently install a persistent backdoor plugin disguised as "Web Media Optimizer." This malicious plugin, retrieved from cdn10.sendibt1.com, hides from the active plugin list, establishes persistence in the must-use directory, periodically fetches secondary JavaScript payloads from glegchner.com and corralos.beer, and contains a hardcoded authentication key allowing attackers to bypass administrator passwords. Brevo has since revoked the compromised API key, removed the malicious Worker, purged its edge caches, and advised affected WordPress administrators to inspect their installations for unauthorized plugins and rotate credentials.

Severity: Critical

Threat Details and IOCs

Malware: AcridRain, AcridRain Stealer, ACR Stealer, ACRStealer, Amatera, Amatera Stealer, AMOS, AnimateClipper, Atomic macOS Stealer, Atomic Stealer, ClearFake, ClearFix, ClickFix, Cthulu, Cuckoo, CurlBackRAT, Lorem Ipsum, Lorem Ipsum Loader, Lumma, LummaC2, Lumma Stealer, mac.c, Mac.c Stealer, Mac.C Stealer, MacSync, MacSync Stealer, ModeloRAT, pastejacking, Poseidon, Posilod, RenEngine Loader, RenPy Loader, RenPy Trojan, SHAMOS, SHub Stealer, TerminalFix, Web Media Optimizer, XMRig, ZigClipper, ZigCryptoStealer
Technologies: Anthropic Claude, Apple macOS, Brevo, Cloudflare, Google Chrome, HBO Max, JFrog, Kestra, Kludex Starlette, Linux, LiteLLM, Microsoft Entra ID, Microsoft PowerShell, Microsoft Windows, Microsoft Windows Active Directory, Microsoft Windows Server, Microsoft Windows Terminal, N-able N-central, PHP, PrestaShop, Python, Reddit, Sangoma Switchvox, SonicWall SMA 1000 Series, WordPress
Threat Actors: Amatera, APT28, APT29, BlueDelta, BronzeSilhouette, ClickFix, Coldriver, CozyBear, DEV-0391, DEV0832, EVALUSION, InsidiousTaurus, Interlock, Kimsuky, KongTuke, LenAI, MacC, MuddyWater, PasteSwitch, PurpleBravo, RapidBrigantine, Redfly, Sandworm, Scamquerteo, Shamos, SheldIO, SlavicNationEmpire, Storm-0249, Storm-0391, Storm-0558, Storm-1607, Storm-2372, TA571, Ta584, TAG-87, TheProtocolOne, UAT-10820, UNC3236, UNC5142, UNC5342, VanguardPanda, VanillaTempest, ViceSociety, VoltTyphoon, Voltzite
Attacker Countries: China, Iran, North Korea, Pakistan, Russia
Attacker IPs: 104[.]21[.]77[.]104, 138[.]124[.]93[.]32, 164[.]90[.]161[.]147, 165[.]22[.]199[.]85, 168[.]100[.]9[.]122, 172[.]236[.]51[.]169, 176[.]53[.]159[.]66, 188[.]114[.]97[.]3, 199[.]217[.]98[.]33, 37[.]27[.]52[.]152, 38[.]244[.]158[.]103, 38[.]244[.]158[.]56, 45[.]94[.]47[.]204, 62[.]60[.]226[.]0, 62[.]60[.]226[.]69, 77[.]91[.]65[.]13, 92[.]246[.]136[.]14
Attacker Domains: 3262d48df5d75e34[.]shop, 45a3158594d6ba76[.]fun, 67b3ac3e45812153[.]fun, 67sixcebeh[.]surf, 82d35f9b891c987a[.]fun, 9082b2a18f2e00fe[.]fun, additionalver[.]com, aforvm[.]com, aidevmaster[.]com, alfredaps[.]com, apple[.]clean-disk-guide[.]com, applediag[.]com, arkypc[.]com, basequill9[.]com, beaocnagent[.]com, bestsocialmedianewspapper[.]com, boiseno[.]club, br[.]hugo-lapp[.]co, bright-links[.]com, broadwalkindia[.]com, camaligsalvatrefoils[.]com, canvas-35[.]com, carlessclapped[.]com, cdn10[.]sendibt1[.]com, cdn11[.]sendibt1[.]com, cdn2[.]sendibt1[.]com, cdn3[.]sendibt1[.]com, cdn4[.]sendibt1[.]com, cdn9[.]sendibt1[.]com, cdn[.]sendibt1[.]com, cehamilton[.]com, cf[.]hugo-mapp[.]co, chatgpt-safepage[.]com, cim-kolea[.]com, cladesktop[.]gitlab[.]io, claud-code[.]pages[.]dev, claude-tools[.]com, claud-tips[.]com, clean-disk-guide[.]com, clean-disk-tools[.]com, cleearpeyak[.]online, cli-desktop[.]com, cli-guides[.]com, cli-stack[.]com, clveeragent[.]com, cmux-lab[.]com, code-desktop[.]com, codex-craft[.]com, codex-notes[.]com, codex-paths[.]com, congiagent[.]com, corralos[.]beer, cosimcagent[.]com, crisp-paths[.]com, cw[.]hugo-lapp[.]lat, dau[.]hugo-mapp[.]co, ddcd62e16a428c8e[.]shop, denverplumbingandwaterheater[.]com, desktop-version[.]com, digitalpoint[.]com, dmt[.]unguidedfreewill[.]co, docs[.]google[.]com, dogtrainersgeorgia[.]com, doh[.]hugo-mapp[.]co, ed[.]hugo-lapp[.]lat, ember-bridge[.]com, en[.]hugo-mapp[.]co, esp[.]hugo-mapp[.]co, euquiz[.]space, facebook[.]com, fcp[.]unguidedfreewill[.]co, fd-api-irc[.]velqo7[.]co, fd-api-irf[.]velqo7[.]co, fd-api-iris[.]velqo7[.]co, fd-api-irs[.]velqo7[.]co, fd-api-rop[.]velqo7[.]co, fd-api-zog[.]velqo7[.]co, fd[.]gstats-api-contact[.]cc, fd[.]gstats-api-contd[.]cc, fd[.]hugo-lapp[.]lat, fern-plume[.]com, filequanticore[.]com, filesiriuscore[.]com, flame-guard[.]cc, flutelikelurkerunsinewy[.]com, folfdighdd[.]xyz, fr[.]hugo-mapp[.]co, gatemaden[.]space, getnova[.]top, gigappyworld[.]com, gitnow([.])dev, gitnow[.]dev, glegchner[.]com, glowmedaesthetics[.]com, glrack[.]com, gogolfonline[.]com, grove-12[.]com, habar55[.]namebright[.]bike, harbor-29[.]com, hbomax-macos[.]com, hbomaxx[.]app, hbomaxx[.]us, hbubagent[.]com, heroestales[.]com, hindustanagency[.]com, hivinest[.]online, homebrwmac-hub[.]com, houstongaragedoorinstallers[.]com, infiniti-stealer[.]com, insinght[.]site, io[.]hugo-lapp[.]lat, jup[.]unguidedfreewill[.]co, kffd3[.]vexlatech[.]cc, kffd3[.]vogueatelier[.]cc, kr[.]hugo-lapp[.]co, lakhov[.]com, lalandscapelighting[.]com, lb[.]propertyfind[.]cc, leaf68[.]com, letsdiskuss[.]com, linked-log[.]com, loop-lumen[.]com, macdeveloperhub[.]com, macfixguide[.]com, macstoragetips[.]com, marbellaresales[.]com, mgo[.]gstats-api-contact[.]cc, microsoftupdater[.]info, mpasvw[.]com, muse-code-ide[.]com, node-slate[.]com, nova-desk[.]top, nova-fix[.]top, nova-hub[.]top, nova-labs[.]top, novastacktips[.]com, nova-tools[.]top, oakenfjrod[.]ru, offlineupdater[.]com, onemm[.]net, opendisplay[.]us, ouilov[.]com, paf[.]hugo-mapp[.]co, papartybus[.]com, pastebin[.]com, paste[.]sh, perchframe15[.]com, pf[.]hugo-mapp[.]co, pine63[.]com, pinescope11[.]com, pkg[.]vogueatelier[.]cc, polygon-bor-rpc[.]publicnode[.]com, press29[.]com, pressureulcerlawyer[.]com, promo-chatgpt[.]com, pt[.]hugo-lapp[.]co, rectangleap[.]com, remotion-skills[.]com, restoremental[.]com, rudder-moss[.]com, sdx[.]unguidedfreewill[.]co, sgaaagent[.]com, sic180[.]com, smart[.]hugo-mapp[.]co, sp13[.]gstats-api-coni[.]co, sp13[.]gstats-api-cont[.]co, sp1[.]gstats-api-coni[.]co, sprieagent[.]com, static[.]quorashift[.]cc, st[.]hugo-lapp[.]lat, storageprofiler[.]com, td[.]hugo-lapp[.]lat, thepullmanfolkestone[.]com, tnt[.]unguidedfreewill[.]co, trekmesh15[.]com, truieparth[.]online, umapla[.]com, update-check[.]com, verificationscodes[.]beer, verse-18[.]com, veruisuealx[.]xyz, wantsellonline[.]com, wdm[.]unguidedfreewill[.]co, wdm[.]velqo7[.]co, wdx[.]unguidedfreewill[.]co, wdx[.]velqo7[.]co, weaveridge7[.]com, wix[.]velqo7[.]co, wuess[.]com, xn--b1ahgbfifq[.]gstats-api-cont[.]co, xn--b1aluem3j[.]gstats-api-contd[.]cc, xn--i-ctbr1afp[.]gstats-api-contd[.]cc, yelahaye[.]surf
Attacker URLs: 3262d48df5d75e34[.]shop/UpdateCheck/, ddcd62e16a428c8e[.]shop/UpdateCheck/, hivinest[.]online/UpdateCheck/, hxxp[://]62[.]60[.]226[.]0/upload.php, hxxps[://]boiseno[.]club, hxxps[://]cdn10[.]sendibt1[.]com/p/wm.zip, hxxps[://]cdn11[.]sendibt1[.]com/api/v1/0044d4a, hxxps[://]cdn11[.]sendibt1[.]com/api/v1/e08a3c4, hxxps[://]cdn11[.]sendibt1[.]com/f.js, hxxps[://]cdn2[.]sendibt1[.]com/api/v1/0044d4a, hxxps[://]cdn2[.]sendibt1[.]com/api/v1/e08a3c4, hxxps[://]cdn2[.]sendibt1[.]com/f.js, hxxps[://]cdn3[.]sendibt1[.]com/api/v1/8e4c615, hxxps[://]cdn3[.]sendibt1[.]com/api/v1/f659473, hxxps[://]cdn4[.]sendibt1[.]com/f.js, hxxps[://]cdn9[.]sendibt1[.]com/f.js, hxxps[://]cdn[.]brevo[.]com/js/brevo-conversations.js, hxxps[://]cdn[.]brevo[.]com/js/sdk-loader.js, hxxps[://]cdn[.]sendibt1[.]com/api/v1/0044d4a, hxxps[://]cdn[.]sendibt1[.]com/api/v1/e08a3c4, hxxps[://]cdn[.]sendibt1[.]com/f.js, hxxps[://]conversations-widget[.]brevo[.]com/brevo-conversations.js, hxxps[://]corralos[.]beer/a412dkoq.js, hxxps[://]docs[.]google[.]com/spreadsheets/d/documentidentifier/gviz/tq?querylanguageinputformattedforHTTP, hxxps[://]glegchner[.]com/ads.php, hxxps[://]paste[.]sh/dQfdExjo#AqjB4BBtlwLt2NKrlC0x8J9O, hxxps[://]update-check[.]com/m/7d8df27d95d9, hxxps[://]yelahaye[.]surf, hxxps[:]//arkypc.com/curl/c46084d53f2256206cd2695ec998a98418969f278381b1f0cc848f21815ec543, hxxps[:]//desktop-version.com/app, hxxps[:]//ember-bridge.com/curl/a44a37519au/setup.sh, hxxps[:]//ember-bridge.com/curl/quohwuhu5o2/setup.sh, hxxps[:]//ember-bridge.com/curl/sxbljspqq9f7/init.sh, hxxps[:]//ember-bridge.com/zyeMb6slon_3VWVlkSkdiJurcyhY5cFNmchnavRnMgU/soundfix/update, hxxps[:]//habar55.namebright.bike/01964960-d755-75d1-826b-99f2652ceced, hxxp[:]//sic180.com/fail, hxxps[:]//linked-log.com/, hxxps[:]//.oakenfjrod.ru/polymarket-91267b64-989f-49b4-89b4-984e0154d4d4, hxxps[:]//weaveridge7.com/api/metrics/run?event=pasted, insinght[.]site/UpdateCheck/, loop-lumen[.]com/zxc/
Attacker Hashes: 008e04a7807f9ed59d77942b1d268e4a93bb82316346f48e5f5b663233db3fff, 013e587247324cfa3005443d2b8036f9a434cafafa1d8a56a6f5637b3dd9d3c1, 026478003fe354134c03acf6890e7d3b153ba08a836eca42350db48f213872ab, 02ac1914fcb4efae0699571751acd700ef0a1933312cd37e72bb7f37bacf4776, 032b529fac61e550f5dc9489686f519b82d64625fa05a8d9ecf8ba8be9b2ad22, 06a3d3bdeb33411fba53eed53cf528f3b33fdf5c2a74921d5d98002cb5e2ba1b, 06c74829d8eee3c47e17d01c41361d314f12277d899cc9dfa789fe767c03693e, 0d58616c750fc8530a7e90eee18398ddedd08cc0f4908c863ab650673b9819dd, 12f6fde9d8058292ad1fb869352eebd615aa59c526a481a39fb52aa59e368d0d, 131a071301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f157aab4, 18c2090e8a0ae0568af9b87e59eaf8270f23d2909600ed9db91a9444fd8b278f, 18c8b79ce68060782e52445a9f38c57e4b6e3f09f625b0465e0a9576e51a7505, 1ba14ee44de95a3e6dcb9866cd00015dbf37f078a74362a827b21c8b2ec48a1a, 1e63be724bf651bb17bcf181d11bacfabef6a6360dcdfda945d6389e80f2b958, 20a0f60d7364766ce7317dd17c0287c72cb2a402872e15fbdeaf9303bcf0ceb7, 23bec473632af324b0a271f6b0575ea3d3174af7042ee5d582cb739714a35af8, 249088420058e50b5e7d1e615a6b9c212e1c341b43fbd8b60cde30d5bd281938, 24ebde9b82e4a2825fcb5951ee735278372538917ed58c68fcd1215b4497405f, 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92, 2f04ba77bb841111036b979fc0dab7fcbae99749718ae1dd6fd348d4495b5f74, 31cf473bb93abef0760d4992d45bafcd936edb7c26193c175f8491f8ffaef0e0, 3276414afb3c7ce7aa19db5401051ce4ad6968a7cc6bf8384cd6470c92541a24, 342df92235c9dec81203b837addaa38bb85b64b4a48fe71b5303ca86d991991e, 407aaecabee599cb29dbb3cf177ed77b67f65d63f456c7abeda5834c0d36ed5f, 427e8b573407f6029923cdb4686b5f77, 439f01ee546eabbdbcc02c0312cf3de28877ed8fcba80e46da88b76b02527a66, 480c65e5bb793da2d5ddfdcf00dd37bd4c7176ea0fb58d4e6bd5c891795dc2f5, 48cc0941b4129bfaeb6948de49dc7c81456e92907b3ea6bdcef5ff186dddf200, 4af488d79aef7daa12b1c18f0cce28b7edadccb8b6b0fb8d50d1d53a9a7c2df7, 52385473e1a64ae5b7a3b79f145304e6b2c5db53e8883e6beede41821c08673f, 57f84dd867e3a3857562f6dc08126608cf13a87f717602afb1a2526bddfc4ee7, 58a5c601c9df7ca2120435588fc39f97712d9b878795f6ee500590099a432308, 5a9a3ce9ff74d7823737b184330134b25a4f36fc1d268789229f8de16832508c, 5ae085cb918abaeb83b4819106534247cfd30f30c77cbcc7806fbf99e12234fb, 5d43abf5c36ea203176d3300ff14af27b4be81810ad2679b3a62b255e3d6e1c8, 5e8ad983129f6771d186f60379dca30d208374cac45bac75d5459aaf0fabc8ad, 5ee86cbcd296e0998ca20ee65a7506fb3baecfb7ce98eede29bff1a6a6e0fc95, 6705033c16d499d65b79f0f8f459a8ea214ae85aedffb3d25f68ba26e455f136, 6759c72365d0c690db613ff30635970668f5699b65c3842ecdc4f1b695ed13a7, 6d9ced8d62655d1a0ddc0d6b5359a10e921b4b2b3b1000dcf96b240f2fa79662, 7a4c15c5f056322ceb9a16fd74374ec0e85aacbaeeb6042ff34b9c415e900864, 825f0358da26a5cd85076be4586c4125ea5958235f3d9669ea3bf60c0edfc5b2, 86d0c50cab4f394c58976c44d6d7b67a7dfbbb813fbcf622236e183d94fd944f, 8c469b571875c6ba0009237379ba0a23b716db6d97724a81a7032a2e4b3456b6, 8d88b558dc9edbc4fdb66eb2451fd5f4df49266921346d2db1191cf23f0d13dc, 906035b6092b2ce1290c566f590e88f1b960b25c6d987f46a3d99cca5b05ee9d, 91b192d28380c77bda19a142c8979d03b3409ca819c07e6dabae0c73a2ab2360, 93d986f39599df747e4f65484a41d5e5ae7ece345924ea36e4f4ee623ce2f0ae, 97f9e987cbd9de6e853c1adcc7614a8d77d4216d63473e7a1f0f6356c5f0e771, 9a7b4dcd51d9251c177d323d6aaecdfc86674f69bc1af048dc872926d22aaa24, 9b62c12bc5c7feb9802f58e6cf75a368690df3c754e37cc64483a92acacf87a5, 9eb96fc1fda13b143a90896793754b6a61942dbf87846895bb9ea8c1e849cd96, 9f26da2456f30b1e10c9aaee4fbf4cbab07912177366aca7fa1103be08a026ff, a69fb9b56a10c8616e76b20a6900842737e16077796aa195b86b71407b8e79b9, a90a93e9776852dac869d4097dba2a4741ef5d316a1ae8631329349287e6a411, ac90360ac4d8c2eb2585daa867d085d2fb12b859bed6c3a472a738cd08e55383, b8d107800403b9197e5b7609ceacd8e4cac1b0f9a1d156e6dacd6c3f7794b36a, ba77feed86bcda49308746421bdc684a432dd5d68c363975b2a3c6831bda3f07, bc9165c426258d33799107d41a1e692504d7e69e02762475ab3b8cbcd19d5d40, cf8d03a0de9e29e3f6a81606443cbf9df2167e95435f88ede747415d4b7e84ed, d1690bec25ed5423e86a9ba1ce41ba8d0de91700e0b680291196dd9975a8a29c, d4150c1c97f047c6edb14767bf1efa8f9e37d63b124f38f27da4ef52d570aac2, d4cfab5e052df4c049f258e226d11825cb37b0359be454b83241edd59b295f08, d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1aba3fcb, d5a60dedf71308f5971269b7a63903e4b68992c392a0368f1dd03cb7e4bcefbc, d72df956a51b1ec0af1e1d375a5704538d2e32688259c14aed39cf1e9d0d770a, d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b5a0540, da73e42d1f9746065f061a6e85e28f0c, dbe8f391291a66a509d5a0144ece8e61789657f96bac14f786293bb4d2ca21ac, dbed9e4764c4d5ab9d316625a9301ccc099c3530b751dab097a3866b97f817b1, de9d325af3156232c34916840210efb5706d6e6a5eba1827c8240e4f71c09fa2, df8221a933b38284ebdcb8bffc2df62123c9f5b5f421dd0b070e13e668b3eabf, e6e54a8e8f30cedd8492f515ab95e005478bafb41998c43341fcf3a494573d6c, eb1b4be34d05b394fb74efdeb95faecd1d1963be6ecc1b9db2b4757b491f01f0, ebb2a2f9f58d0908848399ffcb3a254e9171a8c14daeeae7fc042376372802f4, ec9111b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331, ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb, ecfaa20f25e11878686249c7094706bc3dcd2dc0ace0f2932a39d1bfdac85863, ede6ea506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7, ededeacf30e493dd632d477fe770ba419aa2848f685ea049381a0a8d2cc3e84d, eec09815c3664aa6b3cd370a8b8f566be3b804949cfc514f145262136898b009, f122d596ac6f5bb26ec69ab5fa68506da71d0f72bba5533c913dedd0314855e7, f5f1eb6d43dd61d5b069c250e5c666384f7417d0c95014773bf9edf8ff13bebe, f67d572d2d30407b3f470904326411450763108980cdad89550fbb221fb06782, f71d72711fe132f00d1a10d6f8c0f26c1544b41f57ca9262668dd2c771cc31f7, f771f4717ed04f723b30f9e0424cc2f630f1ffe47857502edd27c3c40c609320, f8d09bb7ef38015342fb8ae11c489fc1a3f01e743123e4222e9291cb474fb75e, fbc6e1867de39feb53f62f8fe805b9dee8ca66e751243731d1db3974eba07e97, fdfd0b06cb31d68146dbb5ffb45b82ca1b59a7b4f62f917a990a9c3bd01654ab
Victim Industries: Accounting, Automotive, Banking, Consulting Services, Cryptocurrency, E-commerce, Education, Energy, Financial Services, Gaming, Government, Healthcare, Hospitality, Information Technology, Insurance, IT and DevOps, Legal Services, Logistics, Manufacturing, Media and Entertainment, Mining, Nonprofit, Pharmaceuticals, Professional Services, Public Administration, Retail, Social Media, Software, Technology Hardware, Telecommunications, Transportation, Utilities, Utilities & Energy, Wholesale
Victim Countries: Australia, Bangladesh, Brazil, Canada, China, Czech Republic, Dominican Republic, France, Germany, Hungary, India, Iran, Israel, Japan, Luxembourg, Malaysia, Mexico, Nepal, North Korea, Pakistan, Peru, Philippines, Poland, Portugal, Russia, Serbia, Singapore, Slovakia, South Korea, Spain, Switzerland, Tunisia, Ukraine, United Kingdom, United States

Mitigation Advice

  • Block the following domains at the corporate DNS filter: cdn10.sendibt1[.]com, yelahaye[.]surf, boiseno[.]club, glegchner.com, and corralos[.]beer.
  • Add rules to the network firewall and web proxy to deny outbound connections to the following domains: cdn10.sendibt1[.]com, yelahaye[.]surf, boiseno[.]club, glegchner.com, and corralos[.]beer.
  • Immediately scan all company WordPress sites for a plugin named "Web Media Optimizer" and inspect the 'mu-plugins' (must-use plugins) directory for any suspicious or unexpected files.
  • Force an immediate password rotation for all administrator-level accounts on all company WordPress sites.
  • Conduct an immediate audit of all Cloudflare API keys, identifying and revoking any that are long-lived, have excessive permissions, or are not actively in use.

Compliance Best Practices

  • Implement a centralized secrets management solution, such as HashiCorp Vault or a cloud provider's equivalent, and establish a mandatory policy to remove all hardcoded credentials from application source code.
  • Establish and enforce a formal API key lifecycle management policy that requires all keys to be created with the minimum necessary permissions and be rotated on a regular schedule.
  • Incorporate Subresource Integrity (SRI) hashes for all third-party scripts and resources loaded on company websites to ensure their integrity.
  • Develop and deploy a strict Content Security Policy (CSP) for all public-facing web applications to whitelist trusted sources for scripts and other resources, preventing the execution of unauthorized code.
  • Establish a recurring governance process to inventory, review, and approve all third-party JavaScript components and services embedded in company websites.
  • Enforce mandatory multi-factor authentication (MFA) for all administrator accounts on company-managed WordPress sites and other critical web applications.
Sources

https://arstechnica.com/security/2026/09/clickfix-attacks-infecting-pcs-and-macs-are-going-viral/

https://blog.polyswarm.io/the-evolution-of-clickfix-mapping-the-growing-fix-family

https://buaq.net/go-438682.html

https://buaq.net/go-439194.html

https://buaq.net/go-442555.html

https://cyberinsider.com/100000-wordpress-sites-infected-via-brevo-supply-chain-attack/

https://cyberpress.org/brevo-cdn-javascript-injection/

https://cyberpress.org/clickfix-delivers-blockchain-banking-malware/

https://cyberpress.org/hbo-max-clickfix-hijack/

https://cyberpress.org/microsoft-warns-terminalfix-clickfix-campaign/

https://cyberpress.org/terminalfix-opens-reverse-tunnels/

https://gbhackers.com/brevo-widgets-supply-chain/

https://gbhackers.com/crimekit-uses-polygon-smart-contracts/

https://gbhackers.com/hackers-use-fake-cloudflare-captcha/

https://gbhackers.com/terminalfix-uses-fake-captcha/

https://hackread.com/microsoft-terminalfix-campaign-malware-png-images/

https://hothardware.com/news/clickfix-malware-is-going-viral

https://isc.sans.edu/diary/rss/33318

https://rhisac.org/threat-intelligence/terminalfix-campaign-targets-multiple-critical-sectors-with-clickfix-variant/

https://sansec.io/research/brevo-supply-chain-attack

https://securereading.com/clickfix-blockchain-malware-campaign/

https://securityonline.info/clickfix-browser-attack-crypto-theft/

https://securityonline.info/terminalfix-campaign-reverse-tunnel/

https://techcrunch.com/2026/09/14/clickfix-attacks-are-tricking-mac-and-windows-users-into-hacking-themselves/

https://www.bleepingcomputer.com/news/security/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/

https://www.bleepingcomputer.com/news/security/microsoft-warns-of-terminalfix-attacks-deploying-reverse-tunnels/

https://www.esecurityplanet.com/threats/news-hbo-max-reddit-clickfix-malware-ads/

https://www.hendryadrian.com/hbo-max-ads-on-a-compromised-reddit-account-exposed-a-massive-pasteswitch-clickfix-operation/

https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/

https://www.securityweek.com/brevo-supply-chain-attack-injects-malware-into-100000-websites/

CVE-2026-87886: Acronis Backup Plugin Privilege Escalation Flaw Exploited in Targeted Attacks

Acronis has disclosed a high-severity local privilege-escalation vulnerability, tracked as CVE-2026-87886 (CVSS score 7.8), affecting its Backup integrations for cPanel & WHM and Plesk on Linux. Stemming from insecure default file permissions (CWE-276), the flaw allows an authenticated, low-privileged attacker to elevate their access and potentially execute arbitrary code with root-level privileges. Active exploitation has been observed in the wild targeting the Acronis Backup plugin for cPanel & WHM, prompting the Cybersecurity and Infrastructure Security Agency (CISA) to add the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on September 16, 2026, with a federal remediation deadline of September 19, 2026. The vulnerability affects Acronis Backup plugin for cPanel & WHM versions prior to build 1.9.3.1021 and Acronis Backup extension for Plesk versions prior to build 1.8.11.638. To mitigate the risk, administrators must update cPanel & WHM deployments to version 1.9.3 HF3, build 1021 (or version 1.9.4, build 1022) and Plesk deployments to version 1.8.11, build 638 or later. Defenders should also monitor system telemetry for suspicious indicators, such as low-privileged accounts spawning root-owned processes, unauthorized modifications to Acronis plugin files, or unexpected shells initiated by plugin-related processes.

Severity: Critical

Threat Details and IOCs

Malware: AsyncRAT, PeckBirdy, VenomRAT
CVEs: CVE-2026-87886
Technologies: Acronis, Acronis Backup plugin for cPanel & WHM, cPanel, DirectAdmin, Linux, Plesk
Threat Actors: APT31, JungleBamboo, Ta412, TideCastle, Unc3569, UNK-DoubleCheck, UNK-LateNight, UNK-QuietRacket, VioletTyphoon
Victim Industries: Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services, Government, Healthcare, IT Services, Managed Service Providers, Web Hosting
Victim Countries: France, United States

Mitigation Advice

  • Immediately inventory all Linux servers to identify those running the Acronis Backup plugin for cPanel & WHM and document their specific build versions.
  • Immediately inventory all Linux servers to identify those running the Acronis Backup extension for Plesk and document their specific build versions.
  • On all identified vulnerable servers, update the Acronis Backup plugin for cPanel & WHM to version 1.9.3 HF3 (build 1021) or newer.
  • On all identified vulnerable servers, update the Acronis Backup extension for Plesk to version 1.8.11 (build 638) or newer.
  • On all servers that were running a vulnerable version of the Acronis Backup plugin for cPanel & WHM, conduct a retrospective hunt for signs of compromise, such as low-privileged accounts spawning root-owned processes or unauthorized changes to Acronis plugin files.
  • If the retrospective hunt reveals evidence of compromise, immediately rotate all potentially exposed credentials, including user passwords, database credentials, API keys, and SSH keys on the affected server.

Compliance Best Practices

  • Implement an automated software asset management system to maintain a continuous, up-to-date inventory of all applications and their versions running on company servers.
  • Develop and deploy SIEM detection rules to continuously monitor for and alert on suspicious privilege escalation techniques on Linux servers.
  • Deploy a File Integrity Monitoring (FIM) solution on critical Linux servers to alert on unauthorized modifications to sensitive system files, configurations, and application directories.
  • Initiate a project to review and enforce the principle of least privilege (PoLP) for all user accounts and file system permissions on multi-tenant and critical servers.
  • Enhance security controls for initial access vectors by hardening web applications, enforcing multi-factor authentication, and improving credential security policies.

Plugin4Shell Vulnerability Enables Zero-Click RCE in OpenAI Codex, Microsoft Copilot, and Other AI Agents

A zero-click remote code execution (RCE) vulnerability, dubbed "Plugin4Shell," affects major AI coding agents including Anthropic’s Claude Code, OpenAI’s Codex, Google's Gemini CLI, Microsoft’s Copilot, and GitHub Copilot, potentially granting attackers full access to all agent-accessible assets and data. The security flaw exploits a plugin SHA-pinning bypass within trusted marketplaces; while agents check out the exact commit pinned by the marketplace, they fail to verify its landing, allowing attackers who control the plugin's repository to resolve the checkout to malicious code. Because these agents automatically update installed plugins by default, the exploit executes without user interaction. In response, Anthropic patched the vulnerability in Claude Code version 2.1.179, and OpenAI resolved it in Codex version 0.146.0. Google has deprecated Gemini CLI without a patch, advising users to migrate to its protected Antigravity environment, while Microsoft Copilot remains vulnerable due to its support for external marketplaces like Bitbucket, despite GitHub implementing restrictions on SHA-resembling branch and tag names.

Severity: Critical

Threat Details and IOCs

Technologies: Anthropic Claude, Atlassian Bitbucket, Git, GitHub Copilot, Google Gemini CLI, Microsoft Copilot, Microsoft GitHub Copilot, OpenAI Codex
Attacker Hashes: 41d0bc0a4aeb2fbf797dacea39e876d98c95024b, aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
Victim Industries: Information Technology, Software, Technology Hardware
Victim Countries: Australia, United States

Mitigation Advice

  • Update all instances of Anthropic's Claude Code to version 2.1.179 or newer to patch the Plugin4Shell vulnerability.
  • Ensure all instances of OpenAI's Codex are updated to version 0.146.0 or newer.
  • Immediately begin migrating all users and systems from the vulnerable Google Gemini CLI to the recommended Antigravity agentic development environment.
  • If possible, disable the automatic update feature for all Microsoft Copilot plugins to prevent a zero-click supply chain attack until a patch is released.
  • Conduct an immediate audit of all installed Microsoft Copilot plugins. Remove any plugins that are not business-critical or that originate from untrusted marketplaces or repositories.

Compliance Best Practices

  • Develop and implement a formal policy for vetting, approving, and managing the lifecycle of all plugins used by AI coding agents. This process should include source code repository analysis and author reputation checks.
  • Implement the principle of least privilege for all AI coding agents. Run them in sandboxed environments or with dedicated, restricted service accounts that have access only to the specific code repositories and data they require to function.
  • Expand the corporate vulnerability management program to officially include AI agents, models, and their third-party components like plugins. Ensure these assets are included in regular security assessments and inventory management.
  • Establish a security policy to disable automatic updates for third-party plugins and extensions in developer tools, including AI agents, by default. Mandate a manual review and approval process for all updates to mitigate supply chain risks.

HEIF Heist Image Flaws Let Attackers Gain RCE Across Meta, Slack, and GitHub Enterprise

A broad class of image-processing vulnerabilities known as "HEIF Heist" allows threat actors to exploit memory-unsafe C/C++ parsers, specifically `libheif` and `libde265`, to achieve remote code execution (RCE), heap disclosure, and account compromise across major platforms including Meta, Slack, and GitHub Enterprise. These flaws, commonly reached through image-processing tools like ImageMagick and libvips, affect various web frameworks and ecosystems such as Next.js, Node.js, Ruby on Rails, and Discourse. Notably, a heap buffer overflow in `libheif` was chained with an OpenAI single sign-on vulnerability to compromise employee ChatGPT accounts, while another flaw, tracked as CVE-2026-19118, enables authenticated RCE in GitHub Enterprise Server. Furthermore, the integration of agentic AI workflows has significantly accelerated the exploit development cycle, reducing the time to weaponize these memory-corruption bugs to just one to three days. To mitigate these risks, organizations must inventory their image-processing pipelines, upgrade to patched library versions such as `libheif` 1.23.4, restrict risky formats using ImageMagick policies, and isolate image conversion workloads within hardened, ephemeral sandboxes.

Severity: Critical

Threat Details and IOCs

Malware: Bash0day, Bashlite, Gafgyt, Lizkebab, Lumma Stealer, Lumma Stealer (successor), Mirai, Remus, Tenzor, Torlus
CVEs: CVE-2026-19118, CVE-2026-32882, CVE-2026-84383
Technologies: Amazon Web Services, Debian, Discourse, Docker, GitHub, ImageMagick, libheif, libvips, Linux, OpenAI, sharp, Slack, strukturag libheif, Struktur libde265, Vercel Next.js
Attacker Emails: email protected
Attacker Domains: rce[.]ee
Attacker URLs: rce[.]ee/ctf-forum
Victim Industries: Artificial Intelligence, Internet & Cloud Services, Social Media, Software, Technology Hardware
Victim Countries: Canada, United States

Mitigation Advice

  • Create an inventory of all applications, services, and containers that process HEIF, HEIC, or AVIF image files, including web servers, content management systems, and chat applications.
  • Update the `libheif` library to the latest patched version (e.g., 1.23.4 or newer as specified by your Linux distribution's security advisories) on all identified systems.
  • Update the `libde265` library to the latest security-patched version on all systems that use it for HEIF/HEIC decoding.
  • If you use a self-hosted GitHub Enterprise Server, immediately update your instance to a patched version (3.17.20, 3.18.14, 3.19.11, 3.20.7, 3.21.5, or 3.22.0 and newer) to mitigate CVE-2026-19118.
  • Disable server-side processing of HEIF, HEIC, and AVIF image formats on all public-facing file upload endpoints where these formats are not a business requirement.
  • Configure your ImageMagick `policy.xml` file to explicitly deny the decoding of HEIF, HEIC, and AVIF formats if they are not required for business operations.
  • If you run a self-hosted Discourse instance, follow the official remediation guidance to patch and rebuild your installation to prevent exploitation through its file upload pipeline.

Compliance Best Practices

  • Architect and implement a sandboxing solution to isolate all high-risk file processing, such as image decoding, in a separate, temporary, and low-privilege environment.
  • Develop and enforce a secure development policy that requires security reviews and vulnerability scanning for all third-party libraries, especially those that parse complex file formats or are written in memory-unsafe languages.
  • Conduct a security review of all applications integrated with your Single Sign-On (SSO) provider. Enforce stricter access policies and require multi-factor authentication (MFA) for SSO-connected applications that grant access to sensitive internal systems or data.

CVE-2025-39964 and CVE-2026-53266: Linux Kernel Vulnerabilities Under Active Exploitation

The Cybersecurity and Infrastructure Security Agency (CISA) has confirmed the active, in-the-wild exploitation of two distinct Linux kernel vulnerabilities, CVE-2025-39964 and CVE-2026-53266, which threaten the stability and security of enterprise servers and cloud environments. The first flaw, CVE-2025-39964 (CVSS 7.8), is a race condition within the kernel's cryptographic user API `(AF_ALG` datapath) that allows two concurrent writers on the same socket, leading to unpredictable payload interleaving, corrupted cryptographic results, or denial-of-service conditions. The second vulnerability, CVE-2026-53266 (CVSS 8.8), is a memory corruption issue in the netfilter bridge ebtables SNAT target that enables local attackers to achieve privilege escalation; this occurs because the driver copies data into memory pages during address range rewrites in nonlinear network fragments without verifying write access. To secure affected systems, administrators must deploy the latest distribution updates containing specific kernel patch commits—such as 0f28c4adbc4a97437874c9b669fd7958a8c6d6ce and bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87—or apply temporary mitigations, which include blacklisting the `af_alg` kernel module and disabling ARP hardware address rewriting in ebtables rules.

Severity: Critical

Threat Details and IOCs

CVEs: CVE-2025-39682, CVE-2025-39964, CVE-2026-53266, CVE-2026-68121, CVE-2026-74469, CVE-2026-80844, CVE-2026-81000
Technologies: Linux Kernel
Victim Industries: Financial Services, Government, Information Technology, Technology Hardware, Telecommunications
Victim Countries: United States

Mitigation Advice

  • Identify all Linux systems in our environment and apply the latest kernel security updates provided by the respective distribution vendors to remediate CVE-2025-39964 and CVE-2026-53266.
  • For Linux systems that cannot be patched immediately, mitigate the risk from CVE-2025-39964 by blacklisting the 'af_alg' kernel module to prevent it from being loaded.
  • On Linux systems that cannot be patched immediately, mitigate CVE-2026-53266 by reviewing ebtables rules and disabling ARP hardware address rewriting to prevent exploitation.
  • Initiate a threat hunt using EDR and SIEM tools to search for indicators of compromise on Linux systems, such as unexpected kernel panics, system reboots, or logs showing unauthorized privilege escalation from unprivileged user accounts.

Compliance Best Practices

  • Review and improve our patch management policy for Linux systems to ensure critical kernel security updates are tested and deployed automatically within a defined, short timeframe.
  • Establish and enforce a kernel hardening baseline for all production Linux systems that disables any kernel modules not explicitly required for business operations, following the principle of least functionality.
  • Tune EDR and SIEM detection rules to create high-fidelity alerts for anomalous local privilege escalation activities on Linux endpoints, such as a user process spawning a root shell or making unauthorized modifications to system files.
  • Begin a project to deploy a mandatory access control framework, such as SELinux or AppArmor, with policies designed to confine critical applications and prevent unauthorized system interactions, even in the event of a successful exploit.

Authors & Contributors

Brian Sayer (Author)

Threat Intelligence Analyst, F5