Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Brevo Security Breach Impacts Over 100,000 Websites

Brevo Security Breach Impacts Over 100,000 Websites

Posted on September 18, 2026 By CWS

Brevo, a platform focused on customer engagement, recently experienced a significant security breach that compromised over 100,000 websites through a supply chain attack. This incident involved the injection of malicious code, raising concerns across the digital landscape.

Initial Breach and Exploitation

The breach began on September 10 when attackers uncovered a vulnerability in Brevo’s SAML SSO handling process. This allowed them unauthorized access to 138 accounts, notably including one from the cryptocurrency storage firm Trezor. The attackers exploited this access to send phishing emails from six accounts and exfiltrate contact information from 43 accounts.

Although Brevo quickly shut down this unauthorized access, the threat actors returned on September 14. Utilizing a compromised, long-term Cloudflare API key, they managed to deploy a worker that injected malicious scripts into Brevo’s domains and JavaScript files embedded in client websites.

Impact and Malicious Activity

These scripts tricked selected visitors with a counterfeit ‘Cloudflare, verify you are human’ page. This page employed a social engineering tactic known as ClickFix, prompting users to execute commands on their devices. On WordPress sites featuring a Brevo widget, the script attempted to install and execute a plugin if the user was logged in as an administrator.

The malicious activity persisted for about five and a half hours before Brevo successfully removed the compromised worker and invalidated the API key and credentials. Brevo’s investigation suggests that the API key was initially misused in late August, although no customer-facing pages were affected before September 14.

Response and Recommendations

According to cybersecurity firm Sansec, the malware was active for roughly four hours and potentially affected more than 100,000 websites. In response, Brevo advises all users to inspect their websites for signs of compromise, such as unauthorized plugin installations. Visitors exposed to the fake verification pages are encouraged to check their devices for malware.

Although Brevo has ceased serving malicious code, the risk of a backdoor on WordPress sites remains, potentially exposing customers to the ClickFix scam. Vigilance and thorough security checks are recommended to mitigate further risks.

This incident underscores the importance of robust security measures and timely response to vulnerabilities, highlighting the ongoing challenges in protecting digital assets from sophisticated cyber threats.

Security Week News Tags:API key, Brevo, ClickFix, Cloudflare, Cybersecurity, malicious code, Malware, Phishing, Sansec, security breach, supply chain attack, Trezor, website security, WordPress

Post navigation

Previous Post: Transparent Tribe Unveils New Rust Backdoor Strategy
Next Post: Microsoft Patches Severe Azure AI Foundry Vulnerability

Related Posts

Promptfoo Raises .4 Million for AI Security Platform Promptfoo Raises $18.4 Million for AI Security Platform Security Week News
AI Fuels Surge in Google’s Chrome Vulnerability Discoveries AI Fuels Surge in Google’s Chrome Vulnerability Discoveries Security Week News
Mate Security Secures M to Enhance AI-Powered SOC Mate Security Secures $35M to Enhance AI-Powered SOC Security Week News
Enhancing Application Security in the AI Age Enhancing Application Security in the AI Age Security Week News
CrowdStrike to Acquire Browser Security Firm Seraphic for 0 Million CrowdStrike to Acquire Browser Security Firm Seraphic for $420 Million Security Week News
Alleged Chinese State Hacker Wanted by US Arrested in Italy Alleged Chinese State Hacker Wanted by US Arrested in Italy Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Patches Severe Azure AI Foundry Vulnerability
  • Brevo Security Breach Impacts Over 100,000 Websites
  • Transparent Tribe Unveils New Rust Backdoor Strategy
  • Top Container Registry Security Tools in 2026
  • Ransomware Developer Sentenced Amid Cybersecurity Alerts

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Patches Severe Azure AI Foundry Vulnerability
  • Brevo Security Breach Impacts Over 100,000 Websites
  • Transparent Tribe Unveils New Rust Backdoor Strategy
  • Top Container Registry Security Tools in 2026
  • Ransomware Developer Sentenced Amid Cybersecurity Alerts

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark