Find notable cyber news and cases, enriched with sources, timelines, and signals.

Brevo hit by network compromise

Incident
First reported
Last updated
Happening score
H score 57
1 unique sources, 1 articles

Summary

Hide ▲

Brevo confirmed a Cloudflare API key compromise that let attackers inject ClickFix scripts into its web properties, exposing customer-facing pages to malicious content injection. The compromise affected Brevo-hosted pages and customer-embedded JavaScript for roughly five and a half hours on September 14. Brevo said app.brevo.com, its email delivery infrastructure, and customer account data were not affected.

Related Happenings

Brevo-abused Trezor security-alert phishing campaign

Campaign
H score45 First: 11.09.2026 10:55 Last: 11.09.2026 10:55 Sources 1

About this happening: A Brevo-abused phishing campaign targeted Trezor newsletter subscribers with fake security-alert emails, reaching 347,000 email addresses and driving 2,500 click...

ShinyHunters-linked Salesforce intrusion campaign

Campaign
H score45 First: 14.07.2026 09:19 Last: 14.07.2026 09:19 Sources 1

About this happening: A ShinyHunters-linked campaign is abusing Salesforce trust relationships to access CRM data across retail, education, and manufacturing tenants. The operation combines...

Ghost CMS CVE-2026-26980 ClickFix campaign

Campaign
H score42 First: 24.05.2026 17:12 Last: 24.05.2026 17:12 Sources 1

About this happening: A large-scale campaign is exploiting CVE-2026-26980 in Ghost CMS to plant malicious JavaScript and drive ClickFix lure pages, putting exposed sites and their visit...

Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations

Threat Actor Meta
H score82 First: 05.03.2026 08:51 Last: 05.03.2026 08:51 Sources 1

About this happening: Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...

Latest development: 17.05.2026 17:43

eSentire says Tycoon2FA now uses device-code phishing to target Microsoft 365 accounts, with invoice-themed lure emails carrying Trustifi click-tracking URLs that redirect through Trustifi, Cloudflare Workers, obfuscated JavaScript layers, and a fake Microsoft CAPTCHA page before sending victims to microsoft.com/devicelogin. The kit also adds anti-analysis defenses, including detection of Selenium, Puppeteer, Playwright, and Burp Suite, plus blocks for security vendors, VPNs, sandboxes, AI crawlers, and cloud providers.

Timeline

  1. 17.09.2026 20:11 2 articles · 2h ago

    Brevo hit by network compromise

    Initial Disclosure

    Attackers used a stolen Cloudflare API key to create a malicious Worker that rewrote Brevo content at the CDN edge on September 14. The injection window lasted from 16:07 to 20:30 UTC before the Worker was removed.

    Show sources