Brevo supply chain attack injects malware into 100,000 websites
Hackers breached Brevo twice: on September 10 via a SAML SSO vulnerability, accessing 138 accounts, and on September 14 using a stolen Cloudflare API key to inject malicious scripts into brevo.com, sibforms.com, and three client JS files. Sansec estimates over 100,000 sites were affected, with attackers showing a fake Cloudflare check and infecting WordPress admin panels.
- Sept 10: 138 Brevo accounts compromised via SAML SSO
- Sept 14: malicious worker active for about 5.5 hours
- Sansec: over 100,000 sites infected, script active ~4 hours
- Attack used ClickFix technique with fake Cloudflare check
Read next
Security