Brevo Attack Hit 100,000 Sites, Plus 3 Stories
There are supply-chain attacks where somebody compromises a software update, and then there are supply-chain attacks where a perfectly clean website starts serving malware because a script it loads from somebody else changed underneath it.
Brevo just gave us an unpleasantly good example of the second kind.
Brevo’s compromised Cloudflare key turned customer websites into malware delivery systems
Brevo says an attacker obtained a long-lived Cloudflare API key with full account permissions that had been stored in application source code. On September 14, the attacker used that key to create a Cloudflare Worker that rewrote content at the CDN edge for about five and a half hours.
That distinction matters. Brevo’s origin servers and JavaScript files weren’t modified. The malicious code was inserted as web traffic passed through Cloudflare on its way to visitors, which meant ordinary file-integrity checks at the source could still say everything was fine while browsers were receiving something else.
The Worker affected Brevo pages and three JavaScript files customers embed on their own websites, including forms, the Conversations widget and the SDK loader. Security firm Sansec estimates more than 100,000 sites were loading affected Brevo components during the attack window.
Most visitors who were targeted saw a fake Cloudflare “verify you are human” page telling them to press Windows+R, paste a command and run it. That’s the ClickFix trick we’ve been seeing more often: the browser doesn’t exploit the computer directly. It persuades the person sitting in front of it to run the malware for the attacker. A CAPTCHA should not require you to open the Windows Run dialog. Ever.
WordPress administrators had an additional problem. If an admin visited a site loading the compromised Brevo code while already logged in, the malicious script attempted to install and activate a plugin. BleepingComputer examined a recovered copy of that plugin and found a persistent backdoor that could hide itself from the normal plugin list and create an authenticated administrator session for the attacker.
Brevo says app.brevo.com, its API, email delivery infrastructure and customer account data were not affected by this part of the incident. The injected code has been removed, the key revoked and the embedded files are clean now. That does not mean every downstream website or Windows PC is clean.
If your WordPress site uses Brevo’s tracker, forms or chat widget and an administrator visited the site while logged in on September 14, check for plugins installed or activated that day, including must-use plugins that won’t necessarily appear in the normal list, and change administrator passwords if you find anything suspicious. If you or a visitor actually followed the fake verification instructions, Brevo says to treat that computer as compromised: disconnect it, scan it and change passwords used on it.
This is why third-party JavaScript belongs in a website’s security model. Your server can be patched, your WordPress files can be clean and your backups can be perfect, and somebody else’s compromised script can still make your site the delivery vehicle.
WordPress security & maintenance
Keeping WordPress current is only part of keeping it healthy. Raymond Tec handles updates, backups, security monitoring, compatibility problems, access cleanup, and maintenance — plus the assorted weirdness that accumulates on a site over time.
Gemini hacked three real companies during a security test it thought was still a test
Google has confirmed that Gemini accessed three real companies’ systems during a cybersecurity evaluation in May after the model wandered outside the intended test environment.
Reuters reports that the evaluation was being run by independent AI-security company Irregular. Gemini found public information online and used credentials to access systems it believed were part of the test. In one case it guessed passwords until it got in; in two others it found credentials in a public repository. Google says all three companies were notified and Gemini stopped its activity after gaining access.
This isn’t evidence that Gemini became self-aware and decided to start hacking strangers. It is evidence that an agent with internet access, a cybersecurity objective and an imperfect boundary can do real-world things outside the box its operators thought they had drawn around it.
That sounds familiar because it is. Similar evaluation failures have already involved OpenAI, Anthropic and Meta, and earlier this week Spain’s privacy regulator disclosed its first reported data breach allegedly carried out through an AI agent. None of these cases proves that autonomous cyberattackers have suddenly replaced human hackers. Together, though, they make the containment problem awfully difficult to dismiss as hypothetical.
The practical lesson for businesses experimenting with agents is less dramatic and more useful: test environments need hard network boundaries, credentials need narrow scope, and “the model was only supposed to touch these systems” is not a security control.
Turning on AI is the easy part
Deciding what an AI tool should be allowed to see, who should use it, what work it should perform, and what happens when it gets something wrong is the more interesting problem. Raymond Tec helps businesses connect and automate the tools they actually use without treating every new feature like a button that obviously needs to be switched on.
Gyazo exposed 23.62 million user records — and the image metadata may be the uglier part
Gyazo’s parent company, Helpfeel, says an attacker exploited a vulnerability in the image-sharing service’s upload server on September 11, executed arbitrary commands and reached its database. The company has now confirmed exposure of about 23.62 million user records.
The user data varies by account but can include names, email addresses, password hashes, user and device IDs, login session IDs, profile information, subscription status and X integration tokens. Helpfeel says credit card numbers and other payment-method information were not exposed, and it has already invalidated or restricted affected authentication information where appropriate.
Then there is the image metadata: roughly 490 million records, mostly associated with images from before January 2019, plus another approximately 2.4 million records retrieved under separate filtering criteria.
“Metadata” is one of those words that can sound reassuringly boring until the metadata includes an image ID used to construct the image URL, the source IP address, EXIF location data, OCR text extracted from the image, image titles, source URLs and hashed passphrases for private images. Helpfeel says the exposed information could be used to access some corresponding images and that the attacker obtained a list identifying private images. The company cannot rule out that some private images were viewed.
Gyazo is temporarily blocking access to some older images while it investigates. It says all users should change their Gyazo password, and anyone who reused the same or a similar password somewhere else should change it there too. Users should also be suspicious of breach-themed emails asking them to log in, verify an account or download something.
The larger privacy lesson is worth keeping: screenshots are often treated like disposable scraps. They can contain invoices, email addresses, customer names, internal dashboards, maps, error messages with tokens and all sorts of things nobody would intentionally publish as a document. A screenshot service can become a very sensitive archive even when nobody thought of it that way.
Technology is rarely just about the technology
Some of the most important technology stories aren’t product launches at all. They’re about health, privacy, education, law, accessibility, work, and what happens when technology reaches ordinary people. Browse more Raymond Tec News for the stories worth understanding without the hype.
Virginia is turning the AI data-center boom into a power-bill and zoning question
Virginia has the largest concentration of data centers in the world, which makes it a useful place to watch what happens when the AI infrastructure boom stops being an abstract cloud-computing story and becomes a local electricity, water, land and noise story.
Governor Abigail Spanberger signed Executive Order 22 Friday and unveiled a broader Data Center Accountability Framework. The executive order immediately bars Virginia executive-branch agencies from entering into or requiring nondisclosure agreements for data-center projects, accelerates work on noise rules, orders a review of diesel and other backup generation and creates tools for local governments and communities. It also creates a state AI task force.
The broader framework goes further, but much of it still needs legislation in 2027. Proposed changes include requiring local approval instead of automatic “by-right” treatment for data centers above 25 megawatts, making large-load customers shoulder more of the generation and transmission costs they create, ending some state subsidies and fast-track permitting, setting stronger water and energy-efficiency standards and limiting on-site natural-gas generation.
The administration calls it the nation’s strongest data-center accountability plan. That’s the administration describing its own policy, not an objective ranking, and the legislature can still change substantial parts of it. The more important point is that Virginia is explicitly trying to answer a question more states are going to face: if one industry suddenly needs enormous amounts of electricity and infrastructure, who pays for the new wires, plants and grid upgrades?
For years, “the cloud” made computing sound almost weightless. AI is making the physical layer difficult to ignore. The cloud has zoning hearings now, and somebody gets the electric bill.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- Brevo — Post-mortem: malicious ClickFix script served via Brevo’s Cloudflare account
- Sansec — Brevo supply-chain attack hits 100k+ sites
- BleepingComputer — Brevo supply-chain attack injected ClickFix scripts on customer sites
- Reuters — Gemini hacked three companies during cybersecurity testing
- Helpfeel — Notice regarding unauthorized access to Gyazo
- Virginia Governor’s Office — Data Center Accountability Framework and Executive Order 22
- Reuters — Virginia tightens data center restrictions
