ZeroHour
Product

Sibforms

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Hackers Turn Brevo Widgets Into Malware Delivery Channel Across 100,000+ Websites

Attackers compromised Brevo-hosted JavaScript to deliver a WordPress backdoor and ClickFix payloads across 100,000+ websites, exposing visitors and admins.

Sansec found injected script tags loading f.js from attacker-controlled subdomains of sendibt1.com appended to legitimate Brevo resources, with PublicWWW listing 114,371 pages referencing Brevo assets. During a September 14 window (16:05:18–20:12:53 UTC), the conditional payload installed a plugin from cdn10.sendibt1.com/p/wm.zip into WordPress admin sessions and showed other visitors a fake human-verification ClickFix overlay instructing them to run pasted commands. Evidence, including an August 25 SSL certificate for cdn.sendibt1.com and Cloudflare DNS usage, suggests a possible compromise of Brevo's Cloudflare environment, unconfirmed by Brevo. Brevo separately disclosed a September 10 SAML SSO incident in which an attacker accessed 138 accounts, sent phishing from six, and exported contacts from 43.

GBHackersupdated · 7h agofirst · 11h agoMalware in the wild 5 sources

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.