Home / Sep 19, 2026 / Story
0
#2 SecurityWeek general September 18, 2026 at 09:46 UTC

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

By Ionut Arghire

AI Summary

A supply chain attack against email marketing platform Brevo used a compromised API key to deploy a malicious Cloudflare Worker that injected malicious scripts into approximately 100,000 websites. The attack demonstrates how a single compromised vendor credential can cascade into mass website compromise, affecting downstream visitors of all affected sites.

Relevance score: 85.0/100

# More from September 19