Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
A supply chain attack involving Brevo leveraged embedded customer widgets to serve injected scripts across numerous sites. The compromised assets loaded unauthorized remote code that installed WordPress backdoors for administrators and displayed click-to-fix overlays to site visitors, affecting thousands of customer domains.
