SShortSingh.
Back to feed

Brevo platform used in supply-chain attack affecting over 100,000 sites

0
·2 views

Between 16:05 and 20:13 UTC on September 14, 2026, files served by the marketing platform Brevo were altered to load malicious code. This code attempted to install a backdoor plugin on WordPress sites with a logged-in administrator, while other visitors were shown a fake verification prompt. Security firm Sansec estimates the incident exposed over 100,000 websites using Brevo's tracking, chat, or form services. The attack followed a separate September 10 breach where an attacker accessed 138 Brevo customer accounts. Sites infected during the four-hour window remain compromised even though Brevo has stopped serving the altered files.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

Developer creates client-side data formatter to prevent accidental credential exposure

A developer built PasteKit, a web-based formatting tool that processes data entirely within the user's browser. This addresses security concerns highlighted in November 2025 when over 80,000 pasted items, including credentials and private keys, were found exposed from other formatter sites. The tool ensures no data is sent to a server by using client-side Web Workers and strict Content Security Policies. It supports 58 formats and 48 converters, works offline, and is free to use without registration.

0
ProgrammingDEV Community ·

Study assesses costs and trade-offs of Shopware for small online shops

A 2026 case study estimated initial setup and running costs for a small Shopware e-commerce store. The author cautions that the minimal two-figure monthly cost is a baseline that excludes marketing, support, and maintenance. The analysis notes that while platforms like WooCommerce may have lower entry fees, most merchants require paid plugins, increasing costs. The study concludes that choosing an e-commerce platform involves long-term factors like flexibility, security, and potential vendor lock-in, not just initial price.

0
ProgrammingDEV Community ·

Developer details iterative process to get actionable Go performance tips from LLMs

A software developer attempted to get specific performance optimization advice for a legacy Go microservice from a Large Language Model. Initial generic prompts yielded only high-level, non-actionable suggestions. The developer then experimented by feeding the model specific code snippets and raw profiling data over several hours. The key breakthrough involved structuring prompts with detailed context, specific data, and a clear goal, treating the LLM as a junior engineer requiring precise guidance.