from tonytins@pawb.social to cybersecurity@infosec.pub on 19 Sep 17:31
https://pawb.social/post/50291188
Brevo, formerly known as Sendinblue, is a French cloud-based marketing and customer communication platform whose clients include eBay, Louis Vuitton and Michelin.
The company was first compromised on September 10, when attackers exploited a vulnerability in its SAML SSO system and gained access to 138 accounts, including one belonging to cryptocurrency hardware wallet maker Trezor. Six accounts were used to send phishing emails, while contact data was exported from 43 accounts.
Brevo blocked the unauthorized access, but attackers returned four days later using a compromised, long-lived Cloudflare API key. They used the key to deploy a malicious Cloudflare Worker that injected code into Brevo’s websites and three JavaScript files embedded in customer sites.
threaded - newest