[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fbTEfZhJdhssBLCE9gK_E7WVfahUoGazWYc4zV3wuQ60":3},{"article":4,"iocs":56},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"7cf5c463-9629-40b3-8634-99685a08c13b","Brevo Supply Chain Attack Injects Malware Into 100,000 Websites","brevo-supply-chain-attack-injects-malware-into-100-000-websites-110c0e","Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts. The post Brevo Supply Chain Attack Injects Malware Into 100,000 Websites appeared first on SecurityWeek.","Customer engagement platform Brevo suffered a supply chain attack where hackers exploited a SAML SSO vulnerability to gain access to accounts. They later used a compromised Cloudflare API key to deploy a worker that injected malicious scripts into Brevo's websites and customer-embedded JavaScript files. This attack impacted over 100,000 websites, serving a fake Cloudflare verification page to trick users into running malicious commands and attempting to install plugins on WordPress sites.","Brevo supply chain attack injected malware into over 100,000 websites via compromised API key.","Customer engagement platform Brevo fell victim to a supply chain attack that resulted in malicious code being injected into over 100,000 websites. Brevo was initially hacked on September 10, when a threat actor exploited a vulnerability in Brevo’s handling of SAML SSO to access 138 accounts, including one belonging to cryptocurrency storage provider Trezor. The attackers sent phishing emails from six of the accounts and exported the contacts of 43 accounts, Brevo said in an incident notice. The company closed the unauthorized access, but the attackers returned on September 14, when they used a compromised long-lived Cloudflare API key to deploy a worker. That worker injected malicious scripts into brevo.com and sibforms.com, and into three JavaScript files that Brevo’s customers embed into their websites, the company said in a post-mortem. “The script showed selected visitors a fake ‘Cloudflare, verify you are human’ page that instructed them to paste and run a command on their computer, a social-engineering technique known as ClickFix,” Brevo explains.Advertisement. Scroll to continue reading. On the WordPress websites embedding a Brevo widget, the script attempted to deploy and run a plugin if the visitor was logged in as an administrator. The malicious worker was active for roughly five and a half hours before Brevo removed it and revoked the compromised API key and credentials. “Our investigation indicates the key was first misused in late August 2026. We have found no injection of malicious content into customer-facing pages before 14 September,” Brevo said. According to cybersecurity firm Sansec, the malware was served for roughly four hours, and more than 100,000 websites were likely impacted. The company recommends that all sites using Brevo be reviewed for potential compromise. Administrators should check for unauthorized plugin installations, and site visitors should check their machines for malware if they were served the fake verification pages. “Brevo is no longer serving malicious code. However, your WordPress site may have been backdoored, and your customers may have fallen for the ClickFix scam,” Sansec notes. Related: Critical Orkes Conductor Vulnerability Exploited in Attacks Related: OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training Related: Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom Related: Rust Supply Chain Attack Linked to North Korean Hackers Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire ISC Patches 14 Vulnerabilities in BIND 9 Security UpdateCisco Fixes Dozens of Flaws Across FMC, ISE and Nexus DashboardCISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure DefensesActive Exploitation Triggers Emergency Patch for Cisco ISE Zero-DayAIUC Raises $40 Million to Certify Enterprise AI AgentsUnauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover280,000 Impacted by Premier Medical Group Data BreachChrome, Firefox Updates Patch 115 Vulnerabilities Latest News Critical Orkes Conductor Vulnerability Exploited in AttacksMIND Secures $72 Million for AI-Powered DLPCheck Point, Kaspersky, Tanium Patch Product VulnerabilitiesCyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board VesselsOpenAI Says Its Models Searched GitHub for Leaked API Keys During TrainingCISA Retires Weekly Vulnerability Bulletin in Risk-Based PivotRevolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M RansomComp AI Raises $34 Million for AI-Native Compliance and Security Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the Moveincident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.Ruben D. Chacon has joined ADM as Vice President and Global CISO.GDIT has appointed retired Maj. Gen. Ryan Heritage as Vice President, Full-Spectrum Cyber.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fbrevo-supply-chain-attack-injects-malware-into-100000-websites\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F06\u002Fsupply-chain-threat.webp","2026-09-18T09:46:57+00:00","2026-09-18T10:00:25.560665+00:00",8,[18,21,24,27,29,31],{"name":19,"type":20},"Brevo","vendor",{"name":22,"type":23},"Cloudflare worker","product",{"name":25,"type":26},"SAML SSO","technology",{"name":28,"type":23},"Cloudflare API key",{"name":30,"type":23},"WordPress",{"name":32,"type":20},"Sansec","26b0b636-0e31-4db1-bffb-61bdf9f20a58",{"id":33,"icon":35,"name":36,"slug":37},null,"Supply Chain","supply-chain",[39,41,46,51],{"category":40},{"id":33,"icon":35,"name":36,"slug":37},{"category":42},{"id":43,"icon":35,"name":44,"slug":45},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":47},{"id":48,"icon":35,"name":49,"slug":50},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":52},{"id":53,"icon":35,"name":54,"slug":55},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[57],{"type":50,"value":58,"context":59},"ClickFix","Name of the social-engineering technique used to trick users into running malicious commands."]