Trezor Data Breach Expands to 81,000 Customers After ShipMonk Failure
A breach at Trezor's shipping provider ShipMonk has grown to affect 81,000 customers after the provider failed to delete data as contractually required.
ToolsA breach at Trezor's shipping provider ShipMonk has grown to affect 81,000 customers after the provider failed to delete data as contractually required.
ToolsMicrosoft is fixing a bug causing Teams and new Outlook to crash on ARM devices after August 2026 Patch Tuesday updates. A temporary workaround is available.
GuidesA new Shai-Hulud variant scans 469 locations for developer credentials, up from 189. Securing the credential layer is now the core supply chain defense priority
ThreatsComcast has added WiFi-based motion detection to its routers. The feature can share motion data with third parties, including law enforcement.
VPN & PrivacyNovocure disclosed a mid-August cyberattack exposing over 1,400 U.S. patient records and employee contact data. No medical devices were accessed.
ThreatsA price-manipulation attack on Tectonic drained $74 million in borrowed assets. Cronos halted and restored the blockchain to a pre-exploit state.
Tools
Two root RCE vulnerabilities in the Unitree G1 EDU robot allow network-adjacent and BLE-based code execution. No confirmed fixed firmware version exists.
AI tools let cybercriminals profile victims faster and cheaper than ever. Here's what the threat looks like and what you can still control.
Australian Federal Police arrested two Western Australia men linked to TeamPCP, a cybercrime group behind a sweeping software supply chain attack campaign.
A supply-chain attack on Android car head units uses a legitimate update app to spread malware that builds a proxy botnet or commits ad fraud.
Intel, Nvidia, and IBM are embedding post-quantum cryptography into hardware. Enterprises are urged to act now against harvest-now, decrypt-later attacks.
ToxicPanda 2.0 adds 167 remote commands and targets 349 financial institutions. GoldDigger expands to South Africa and the U.K. via fake airline and retail apps
Comcast's new Xfinity Shield platform uses existing WiFi signals to detect motion inside homes. Privacy questions remain over data retention and third-party dis
A critical GitLab flaw rated CVSS 9.4 requires no authentication to exploit. Self-managed users should patch immediately or restrict GraphQL access.
Two new papers examine how LLMs fail to control sensitive information flow based on context, and how reasoning and reinforcement learning may help.