Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Brevo suffered a supply chain attack after a compromised Cloudflare API key was used to inject malicious scripts into Brevo assets and customer-embedded JavaScript, impacting more than 100,000 websites. The attack followed an earlier SAML SSO abuse that exposed 138 accounts, including Trezor, and used fake Cloudflare verification pages to trick visitors with the ClickFix scam. #Brevo #Cloudflare #Trezor #ClickFix

Keypoints

  • Brevo was first breached through a flaw in its SAML SSO handling.
  • The initial intrusion exposed 138 accounts and enabled phishing from six of them.
  • Attackers later used a compromised long-lived Cloudflare API key to deploy a worker.
  • The malicious worker injected scripts into Brevo domains and customer-facing JavaScript files.
  • More than 100,000 websites may have been affected, and WordPress sites may have been backdoored.

Read More: https://www.securityweek.com/brevo-supply-chain-attack-injects-malware-into-100000-websites/