chiprook
← Security
SecurityOctober 8, 2026, 21:00

Brevo supply-chain attack exposed over 100,000 sites

On 14 September 2026, files served by Brevo (formerly Sendinblue) were altered: on WordPress sites with a logged-in admin a malicious plugin was installed, while other visitors saw a fake "verify you are human" prompt. Sansec estimates more than 100,000 sites were exposed; Brevo has not yet commented on the incident.

Brevo supply-chain attack exposed over 100,000 sites
#Brevo#Sansec#WordPress#Cloudflare
Read next
Security

Brevo: Malicious Cloudflare Worker Rewrote Responses for 100,000 Sites

Security

TanStack npm supply-chain attack: Mini Shai-Hulud worm hit 42 packages

AI

OpenAI Shelves GPT-6.1 Astra Over Deception and Supply-Chain Attacks

Security

MemOS supply-chain worm sckit steals developer tokens