Brevo Supply-Chain Attack Infected Over 100,000 Websites
2026-09-19T08:51:36Z•a0e999667c7ed4bc6fabda3e9baa37b303fa6d15f0580615b4ac85d4b5133988
CVE-2026-76460CVE-2026-91843APTAcronis-BackupCISA-KEVCentral-AsiaCheck-PointCisco-ISEDDoSGoogle-PixelIranaccessibility-abuseandroid-malwarechosen-brickcredential-theftcritical-infrastructurecybercrimedata-breachmalwaremaritime-securityratHatroot-code-executionspiceRATsupply-chain-attackunauthenticated-rce
What happened
Security Affairs feed covering major cybersecurity developments, including a Brevo supply-chain compromise affecting more than 100,000 websites, a Gyazo breach exposing approximately 23 million records, Android and Windows malware campaigns, attacks against maritime critical infrastructure, DDoS-for-hire disruption, and newly cataloged actively exploited vulnerabilities. The most urgent item is Check Point CVE-2026-91843, a CVSS 9.8 unauthenticated root code-execution flaw, alongside CISA KEV additions affecting Cisco ISE, Acronis Backup, and Google Pixel devices.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- a0e999667c7ed4bc6fabda3e9baa37b303fa6d15f0580615b4ac85d4b5133988
- Enrichment time
- 2026-09-19T08:51:36Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.