11 min read
BrevoSAML SSO+6 more
How a Flawed SSO Invitation Flow Turned Brevo Into a Phishing Launchpad for 347,000 Crypto Users
An attacker exploited how Brevo's SAML SSO handles organization invitations to reach 138 customer accounts, including Trezor and BitBox, then used Trezor's own newsletter list to push a fake hardware vulnerability alert to 347,000 subscribers.
Sep 15, 20260