chiprook
← Security
SecuritySeptember 18, 2026, 16:46

Brevo supply chain attack injects malware into 100,000 websites

Hackers breached Brevo twice: on September 10 via a SAML SSO vulnerability, accessing 138 accounts, and on September 14 using a stolen Cloudflare API key to inject malicious scripts into brevo.com, sibforms.com, and three client JS files. Sansec estimates over 100,000 sites were affected, with attackers showing a fake Cloudflare check and infecting WordPress admin panels.

Brevo supply chain attack injects malware into 100,000 websites
#Brevo#Cloudflare#WordPress#Sansec
Read next
Security

Kaspersky finds MovieReaper trojan in pirated films, C2 hidden on Solana blockchain

Security

npm Trusted Publishing Abused to Ship GHAPPIER Loader

Security

Orchid Security Delivers AI Readiness Controls With Application-Level Kill Switches

Security

Mandiant: hijacked AI coding session spread Shai-Hulud worm across ~100 repos