Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Customer engagement platform Brevo fell victim to a supply chain attack that resulted in malicious code being injected into over 100,000 websites.
Brevo was initially hacked on September 10, when a threat actor exploited a vulnerability in Brevo’s handling of SAML SSO to access 138 accounts, including one belonging to cryptocurrency storage provider Trezor.
The attackers sent phishing emails from six of the accounts and exported the contacts of 43 accounts, Brevo said in an incident notice.
The company closed the unauthorized access, but the attackers returned on September 14, when they used a compromised long-lived Cloudflare API key to deploy a worker.
That worker injected malicious scripts into brevo.com and sibforms.com, and into three JavaScript files that Brevo’s customers embed into their websites, the company said in a post-mortem.
“The script showed selected visitors a fake ‘Cloudflare, verify you are human’ page that instructed them to...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE