Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

    September 18, 2026

    Microsoft Director Privately Admitted AI Was the “Largest Theft of Labor in Human History,” Unsealed Court Documents Show

    September 18, 2026

    How to use the new AI photo editing tools in iOS 27

    September 18, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
    Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
    Cybersecurity

    Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

    The Tech GuyBy The Tech GuySeptember 18, 2026No Comments2 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Customer engagement platform Brevo fell victim to a supply chain attack that resulted in malicious code being injected into over 100,000 websites.

    Advertisement

    Brevo was initially hacked on September 10, when a threat actor exploited a vulnerability in Brevo’s handling of SAML SSO to access 138 accounts, including one belonging to cryptocurrency storage provider Trezor.

    The attackers sent phishing emails from six of the accounts and exported the contacts of 43 accounts, Brevo said in an incident notice.

    The company closed the unauthorized access, but the attackers returned on September 14, when they used a compromised long-lived Cloudflare API key to deploy a worker.

    That worker injected malicious scripts into brevo.com and sibforms.com, and into three JavaScript files that Brevo’s customers embed into their websites, the company said in a post-mortem.

    “The script showed selected visitors a fake ‘Cloudflare, verify you are human’ page that instructed them to paste and run a command on their computer, a social-engineering technique known as ClickFix,” Brevo explains.

    Advertisement. Scroll to continue reading.

    On the WordPress websites embedding a Brevo widget, the script attempted to deploy and run a plugin if the visitor was logged in as an administrator.

    The malicious worker was active for roughly five and a half hours before Brevo removed it and revoked the compromised API key and credentials.

    “Our investigation indicates the key was first misused in late August 2026. We have found no injection of malicious content into customer-facing pages before 14 September,” Brevo said.

    According to cybersecurity firm Sansec, the malware was served for roughly four hours, and more than 100,000 websites were likely impacted.

    The company recommends that all sites using Brevo be reviewed for potential compromise. Administrators should check for unauthorized plugin installations, and site visitors should check their machines for malware if they were served the fake verification pages.

    “Brevo is no longer serving malicious code. However, your WordPress site may have been backdoored, and your customers may have fallen for the ClickFix scam,” Sansec notes.

    Related: Critical Orkes Conductor Vulnerability Exploited in Attacks

    Related: OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training

    Related: Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom

    Related: Rust Supply Chain Attack Linked to North Korean Hackers

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training

    September 18, 2026

    Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels

    September 17, 2026

    CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

    September 17, 2026

    CISA Releases Guidance on Deploying Cyber Decoys

    September 17, 2026

    EU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media

    September 17, 2026

    First Agentic AI Data Breach Reported to Spanish Regulator

    September 16, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

    September 18, 2026

    Microsoft Director Privately Admitted AI Was the “Largest Theft of Labor in Human History,” Unsealed Court Documents Show

    September 18, 2026

    How to use the new AI photo editing tools in iOS 27

    September 18, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.