Brevo’s post-mortem (covered 2026-09-18) describes a supply-chain hit: a compromised long-lived Cloudflare API key let an attacker publish a Worker that injected malicious scripts into brevo.com, sibforms.com, and three JavaScript files customers embed. The window was about 5.5 hours on 2026-09-14. Victims saw a fake “Cloudflare verify you are human” ClickFix prompt (paste and run a command). On WordPress with a logged-in admin, the payload tried to install a plugin. Sansec estimates 100,000+ sites loaded affected components during a roughly four-hour serve window. Brevo says app.brevo.com, APIs, email, and account data were not modified at source — the damage was in the customer-facing embeds.

Same day, SecurityWeek reports Microsoft disclosed 18 fixes across Azure and Copilot AI — mostly elevation of privilege in Azure Arc, AI Foundry, Logic Apps, Cosmos DB, Container Registry, Fabric, Dataverse, and M365 Copilot, plus info-disclosure in Copilot/AML and one Azure Portal spoofing issue. Those cloud/AI fixes are server-side (no customer patch action). Separately, Windows elevation-of-privilege CVE-2026-85921 still needs a Windows update; Microsoft rates exploitation “less likely.” The same write-up notes the latest Patch Tuesday covered a record 970 product vulnerabilities.

Livermore takeaway: if you use Brevo/Sendinblue forms or widgets, audit WordPress plugins and admin activity from Sep 14, and treat any ClickFix “paste this command” moment as a full endpoint incident. For M365/Copilot shops, treat AI and SaaS privilege paths as first-class — and confirm endpoints are current for CVE-2026-85921.