Brevo Supply-Chain Attack Infected Over 100,000 Websites

2026-09-19T08:51:36Z•a0e999667c7ed4bc6fabda3e9baa37b303fa6d15f0580615b4ac85d4b5133988
CVE-2026-76460CVE-2026-91843APTAcronis-BackupCISA-KEVCentral-AsiaCheck-PointCisco-ISEDDoSGoogle-PixelIranaccessibility-abuseandroid-malwarechosen-brickcredential-theftcritical-infrastructurecybercrimedata-breachmalwaremaritime-securityratHatroot-code-executionspiceRATsupply-chain-attackunauthenticated-rce

What happened

Security Affairs feed covering major cybersecurity developments, including a Brevo supply-chain compromise affecting more than 100,000 websites, a Gyazo breach exposing approximately 23 million records, Android and Windows malware campaigns, attacks against maritime critical infrastructure, DDoS-for-hire disruption, and newly cataloged actively exploited vulnerabilities. The most urgent item is Check Point CVE-2026-91843, a CVSS 9.8 unauthenticated root code-execution flaw, alongside CISA KEV additions affecting Cisco ISE, Acronis Backup, and Google Pixel devices.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
a0e999667c7ed4bc6fabda3e9baa37b303fa6d15f0580615b4ac85d4b5133988
Enrichment time
2026-09-19T08:51:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.