A suspected supply-chain compromise involving Brevo has exposed visitors and WordPress administrators across more than 100,000 websites to malware. Attackers allegedly abused Brevo-hosted JavaScript assets, signup forms, unsubscribe pages and chat widgets to distribute a WordPress backdoor and ClickFix social-engineering payloads. Brevo, formerly Sendinblue, disclosed a separate security incident on September 10 involving an SAML […]
Read the original article:
