Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Brevo Security Breach Impacts Over 100,000 Websites

Brevo Security Breach Impacts Over 100,000 Websites

Posted on September 18, 2026 By CWS

Brevo, a platform focused on customer engagement, recently experienced a significant security breach that compromised over 100,000 websites through a supply chain attack. This incident involved the injection of malicious code, raising concerns across the digital landscape.

Initial Breach and Exploitation

The breach began on September 10 when attackers uncovered a vulnerability in Brevo’s SAML SSO handling process. This allowed them unauthorized access to 138 accounts, notably including one from the cryptocurrency storage firm Trezor. The attackers exploited this access to send phishing emails from six accounts and exfiltrate contact information from 43 accounts.

Although Brevo quickly shut down this unauthorized access, the threat actors returned on September 14. Utilizing a compromised, long-term Cloudflare API key, they managed to deploy a worker that injected malicious scripts into Brevo’s domains and JavaScript files embedded in client websites.

Impact and Malicious Activity

These scripts tricked selected visitors with a counterfeit ‘Cloudflare, verify you are human’ page. This page employed a social engineering tactic known as ClickFix, prompting users to execute commands on their devices. On WordPress sites featuring a Brevo widget, the script attempted to install and execute a plugin if the user was logged in as an administrator.

The malicious activity persisted for about five and a half hours before Brevo successfully removed the compromised worker and invalidated the API key and credentials. Brevo’s investigation suggests that the API key was initially misused in late August, although no customer-facing pages were affected before September 14.

Response and Recommendations

According to cybersecurity firm Sansec, the malware was active for roughly four hours and potentially affected more than 100,000 websites. In response, Brevo advises all users to inspect their websites for signs of compromise, such as unauthorized plugin installations. Visitors exposed to the fake verification pages are encouraged to check their devices for malware.

Although Brevo has ceased serving malicious code, the risk of a backdoor on WordPress sites remains, potentially exposing customers to the ClickFix scam. Vigilance and thorough security checks are recommended to mitigate further risks.

This incident underscores the importance of robust security measures and timely response to vulnerabilities, highlighting the ongoing challenges in protecting digital assets from sophisticated cyber threats.

Security Week News Tags:API key, Brevo, ClickFix, Cloudflare, Cybersecurity, malicious code, Malware, Phishing, Sansec, security breach, supply chain attack, Trezor, website security, WordPress

Post navigation

Previous Post: Transparent Tribe Unveils New Rust Backdoor Strategy
Next Post: Microsoft Patches Severe Azure AI Foundry Vulnerability

Related Posts

Arizona Attorney General Sues Chinese Online Retailer Temu Over Data Theft Claims Arizona Attorney General Sues Chinese Online Retailer Temu Over Data Theft Claims Security Week News
Venezuelan Nationals Admit to ATM Jackpotting in US Venezuelan Nationals Admit to ATM Jackpotting in US Security Week News
Chris Thompson’s Journey: From Game Hacker to Cybersecurity Pioneer Chris Thompson’s Journey: From Game Hacker to Cybersecurity Pioneer Security Week News
In Other News: Docker AI Attack, Google Sues Chinese Cybercriminals, Coupang Hacked by Employee In Other News: Docker AI Attack, Google Sues Chinese Cybercriminals, Coupang Hacked by Employee Security Week News
High-Severity Vulnerabilities Patched by Ivanti and Zoom High-Severity Vulnerabilities Patched by Ivanti and Zoom Security Week News
New Insights on Optimizing KEV Catalog Usage for Security New Insights on Optimizing KEV Catalog Usage for Security Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Feral Wolf Ransomware Exploits Exposed Business Systems
  • Abandoned CDN Domain Re-Registered, Impacting Thousands
  • Microsoft Patches Severe Azure AI Foundry Vulnerability
  • Brevo Security Breach Impacts Over 100,000 Websites
  • Transparent Tribe Unveils New Rust Backdoor Strategy

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Feral Wolf Ransomware Exploits Exposed Business Systems
  • Abandoned CDN Domain Re-Registered, Impacting Thousands
  • Microsoft Patches Severe Azure AI Foundry Vulnerability
  • Brevo Security Breach Impacts Over 100,000 Websites
  • Transparent Tribe Unveils New Rust Backdoor Strategy

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark