ZeroHour
Product

Brevo Conversations

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Hackers Turn Brevo Widgets Into Malware Delivery Channel Across 100,000+ Websites

Attackers compromised Brevo-hosted JavaScript to deliver a WordPress backdoor and ClickFix payloads across 100,000+ websites, exposing visitors and admins.

Sansec found injected script tags loading f.js from attacker-controlled subdomains of sendibt1.com appended to legitimate Brevo resources, with PublicWWW listing 114,371 pages referencing Brevo assets. During a September 14 window (16:05:18–20:12:53 UTC), the conditional payload installed a plugin from cdn10.sendibt1.com/p/wm.zip into WordPress admin sessions and showed other visitors a fake human-verification ClickFix overlay instructing them to run pasted commands. Evidence, including an August 25 SSL certificate for cdn.sendibt1.com and Cloudflare DNS usage, suggests a possible compromise of Brevo's Cloudflare environment, unconfirmed by Brevo. Brevo separately disclosed a September 10 SAML SSO incident in which an attacker accessed 138 accounts, sent phishing from six, and exported contacts from 43.

GBHackersupdated · 6h agofirst · 10h agoMalware in the wild 5 sources

Brevo supply-chain attack injected ClickFix scripts on customer sites

Attackers used a stolen Cloudflare API key to inject ClickFix malware-delivery scripts into Brevo sites and customer-embedded scripts for five hours.

Brevo confirmed attackers stole a long-lived Cloudflare API key with full account permissions that had been hardcoded in source code, and used it to create a malicious Cloudflare Worker that rewrote content at the CDN edge for roughly 5.5 hours on September 14 (16:07-20:30 UTC), affecting brevo.com, sendinblue.com, sibforms.com, and customer-embedded Brevo scripts; Sansec estimated up to 100,000 websites may have been exposed. Visitors saw fake Cloudflare verification pages with ClickFix instructions to run a Windows command, and the injected code uploaded a persistent WordPress backdoor plugin named 'Web Media Optimizer' to sites where logged-in admins browsed. The backdoor hides from the plugin list, persists in the must-use plugins directory, contacts attacker servers, and contains a hardcoded key to forge WordPress administrator sessions. Brevo said app.brevo.com, its API, email delivery, and customer data were unaffected; a separate September 10 SSO incident led to Trezor phishing hitting 347,000 addresses with at least 2,500 accounts compromised.

BleepingComputerupdated · 6h agofirst · 22h agoData breach in the wild 5 sources