Skip to content
archivesupply chain · 18 Sep 2026 · 09:46 UTC

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

last 60 dispatches · spectrum

Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts.

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected