Brevo platform used in supply-chain attack affecting over 100,000 sites
Between 16:05 and 20:13 UTC on September 14, 2026, files served by the marketing platform Brevo were altered to load malicious code. This code attempted to install a backdoor plugin on WordPress sites with a logged-in administrator, while other visitors were shown a fake verification prompt. Security firm Sansec estimates the incident exposed over 100,000 websites using Brevo's tracking, chat, or form services. The attack followed a separate September 10 breach where an attacker accessed 138 Brevo customer accounts. Sites infected during the four-hour window remain compromised even though Brevo has stopped serving the altered files.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in