Brevo ClickFix attack used a stolen Cloudflare key to alter pages and embedded scripts for 5.5 hours; Brevo says application data was not affected.