Third-Party Trust Exploited: Brevo, Clop, and RMM Abuse

Third-Party Trust Exploited: Brevo, Clop, and RMM Abuse

•

Episode description

Third-Party Trust Exploited: Brevo, Clop, and RMM Abuse

On 14 September 2026, attackers compromised Brevo’s infrastructure, injecting malicious code into JavaScript assets that reached over 100,000 customer websites. WordPress administrators had backdoor plugins silently installed while logged in; regular visitors faced ClickFix credential-harvesting overlays. Meanwhile, the Clop threat group continues exploiting CVE-2026-12569 in PTC Windchill with a custom web shell built for rapid data exfiltration, targeting UK manufacturing and engineering supply chains. A third campaign involves Settra ransomware maintaining persistence via MeshAgent, a legitimate remote monitoring tool that endpoint security often trusts by default. All three attacks share one structural weakness: reliance on third-party platforms, scripts, and tools that UK small businesses cannot directly audit or control. This briefing walks through the mechanics of each campaign, explains why supply chain compromise scales so effectively, and sets out the specific questions business owners must ask their web developers, IT providers, and managed service providers today. No patch can protect you from a script you load from someone else’s content delivery network, and no endpoint tool will flag an RMM agent it has been trained to trust. The NCSC has published supply chain guidance repeatedly; these campaigns demonstrate how rarely it is applied in practice.

Chapters

  • Intro Mauven frames the common vulnerability across today’s campaigns: reliance on third-party platforms that UK small businesses cannot audit, patch, or monitor in real time.
  • Brevo Supply Chain Attack On 14 September 2026, attackers compromised Brevo’s infrastructure, injecting malicious JavaScript that silently installed WordPress backdoor plugins on admin machines and delivered ClickFix credential-harvesting overlays to visitors across over 100,000 customer sites.
  • CTA Mauven asks listeners to follow the show and share it with colleagues who need the briefing.
  • Clop Returns with a Custom Implant The Clop threat group is exploiting CVE-2026-12569 in PTC Windchill with a custom web shell built for rapid credential harvesting, database enumeration, and data exfiltration, targeting UK manufacturing and engineering businesses.
  • Settra Ransomware and RMM Abuse Settra ransomware maintains persistence by installing MeshAgent, a legitimate remote monitoring tool that endpoint security trusts by default, making unauthorised access harder to detect.
  • The Wider Pattern Mauven connects all three campaigns to the same structural weakness: shared platforms, scripts, and tools that businesses cannot directly control, and the persistent gap between available NCSC guidance and real-world application.
  • Outro Mauven summarises the specific actions listeners must take today: audit Brevo-linked sites, confirm PTC Windchill patches, and ask MSPs which RMM agents are authorised and how unauthorised ones would be detected.

Links

No transcript available for this episode.