Brevo Supply-Chain Attack Infected Over 100,000 Websites

2026-09-19T02:51:37Z•0c3d2e9360ff06424600e4136d8545c910acba5ca01d2e04a6d5ba146582eca6
CVE-2026-76460CVE-2026-91843APTAcronisCISA-KEVCentral-AsiaCheck-PointCisco-ISEDDoSGoogle-PixelIranandroid-malwarecritical-infrastructurecybercrimedata-breachmalwaremaritime-cybersecuritysupply-chain-attacksurveillance-malwareunauthenticated-code-executionvulnerability

What happened

Security news covers a Brevo supply-chain compromise affecting potentially over 100,000 websites, a Gyazo breach exposing approximately 23 million records, Android and Windows surveillance malware, maritime cyberattacks, threat-actor infrastructure targeting Central Asia, a DDoS-for-hire takedown, and actively exploited vulnerabilities added to CISA’s KEV catalog. Check Point CVE-2026-91843 enables unauthenticated root code execution with a CVSS score of 9.8, while CVE-2026-76460 affects Cisco ISE authentication.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
0c3d2e9360ff06424600e4136d8545c910acba5ca01d2e04a6d5ba146582eca6
Enrichment time
2026-09-19T02:51:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Brevo Supply-Chain Attack Infected Over 100,000 Websites · Baitaphish