www.spreaker.com
Brevo Supply Chain Attack: Malware Injected Into 100,000+ Websites
https://www.osintinvestigate.com
A major cybersecurity incident involving Brevo exposed more than 100,000 websites to malicious code. In this episode, we examine how attackers compromised Brevo, abused a long-lived Cloudflare API key, and used a malicious Cloudflare Worker to inject scripts into Brevo services and JavaScript assets embedded by customers. The attack also involved ClickFix social engineering and attempts to install malicious WordPress plugins when administrators visited affected websites. We explain the September 2026 timeline, how the attack worked, why supply chain compromises can have such a wide impact, and what website administrators should check after the incident.