Security news

Showing 1–50 of 170
Clear filters

August 25, 2026

Security

Cosmos Labs Urges Some EVM Chains to Halt After KiiChain, TAC and MANTRA Incidents

Cosmos Labs urges affected EVM chains to halt over security incident Cosmos Labs has told affected networks in contact with its team to suspend operations during an ongoing Cosmos EVM security incident, after KiiChain, TAC and MANTRA linked recent attacks to shared EVM infrastructure flaws. KiiChain said 148,326,583.15 KII was drained on Aug. 22 before it halted the chain, while TAC said an exploit moved 2,985,651,403 TAC; Cosmos Labs has not publicly confirmed whether all incidents came from one flaw.

Security

Kraken Says HTX-Linked Dust Transfers Temporarily Triggered Customer Account Locks

Kraken restores accounts after alleged HTX-linked dust attack Kraken said it briefly locked some customer accounts after wallets it identified as linked to HTX sent about 12,000 tiny transfers to Kraken-related addresses between Aug. 17 and Aug. 24. The exchange called it a dust attack aimed at tripping AML controls by placing U.K.- and EU-sanctioned funds into user accounts; access has since been restored, while the sanctioned funds remain frozen and Kraken says it is working with authorities.

Security

Socket ties 77 Firefox extension identities to crypto wallet theft campaign

Socket links 77 Firefox add-ons to crypto wallet theft campaign Security firm Socket says a campaign it calls the Offside Wallet Theft Factory used 77 Firefox extension identities, with 40 confirmed malicious, to impersonate OKX, Rabby Wallet, TronLink and other Web3 tools and steal recovery phrases or private keys. Some were modified Rabby builds that exfiltrated stored data, credentials and clipboard contents, while nine sports-score apps were later updated into wallet stealers to exploit existing installs.

Security

Chainalysis Operation Lighthouse Generated 14,300 CSAM Investigation Leads

Chainalysis-led CSAM crypto sweep identifies suspects in 125 countries Chainalysis said its multi-day Operation Lighthouse sprint with more than nine law enforcement agencies, 13 private-sector partners and non-profits generated 14,300 investigative leads, flagged 7,700+ suspect accounts, and identified CSAM-linked suspects in 125 countries. The operation reviewed 29,120 crypto addresses and digital identifiers tied to more than 100 suspected CSAM platforms and networks.

Security

Term Labs governance takeover drained $8.5M after attacker spent about $951

Term Labs governance takeover drains $8.5M from strategy vaults An attacker spent about $951 to buy a controlling stake in Term Labs’ governance token, passed malicious proposals on Aug. 23, 2026, and drained roughly $8.5 million from strategy vaults. The haul included 2,843 ETH and 1.68 million USDC, later swapped for about 1.6 million DAI. Term Labs shut all Meta Vault deposits and revoked DAO governance roles, while keeping withdrawals open.

Security

Cosmos Labs urges Cosmos EVM chains to halt after attacks hit multiple networks

Cosmos Labs urges Cosmos EVM chains to halt after attacks hit MANTRA, TAC and KiiChain Cosmos Labs told affected Cosmos EVM chains on Aug. 25 to coordinate validator halts as it responds to a security incident that has already hit MANTRA, TAC and KiiChain. KiiChain said 148.3 million KII were drained on Aug. 22 before validators stopped the network, while TAC said one account was drained and MANTRA said no user funds were affected. Cosmos Labs has not yet published the root cause or total losses and is preparing a patch and restart guidance.

August 24, 2026

Security

TAC Protocol Rebounds After Exploit, Says Shared Cosmos EVM Code Was at Fault

TAC says exploit came from shared Cosmos EVM code, not its own chain TAC Protocol said the August 22 exploit that forced validators to halt the chain was caused by a vulnerability in the shared Cosmos EVM precompile layer, not TAC’s own code. The attacker drained a single account before transactions were stopped at block 24,671,475, and TAC said only the native $TAC token was stolen. The token has since rebounded about 53% from its all-time low, but remains roughly 97% below its June 30 peak.

Security

Fake Google ad for Hyperliquid linked to Inferno drainer in $550,000 USDC theft

Hyperliquid user loses $550,000 USDC in phishing attack tied to Inferno drainer A Hyperliquid user lost about 550,019 USDC after clicking a Google sponsored ad that led to a fake version of the trading platform, while Salus linked the theft infrastructure to the Inferno drainer ecosystem. Salus said the phishing group bought the ad and spoofed the site, while the backend service handled the drain and automatically split proceeds, with one address receiving 80%.

Security

Sandbox bridge exploit minted 329 trillion fake SAND on Base, but losses stayed near $675,000

Sandbox exploit mints 329T fake SAND on Base, drains about $675,000 An attacker abused the approveAndCall function in The Sandbox’s SAND omnichain token on Base to seize LayerZero delegate permissions and mint 329.24 trillion unbacked SAND across 703 events on Aug. 21-22. Despite a nominal face value near $49 billion, the attacker extracted about 14.75 million SAND from the Ethereum OFT Adapter and converted it to roughly 80 ETH, or around $675,000, before Sandbox disabled bridging on Base and BNB Smart Chain.

Security

Besu Discloses Five Fixed Security Flaws After Releasing Urgent Node Update

Besu fixes five security flaws in Ethereum client update 26.7.1 Ethereum client Besu said five security vulnerabilities found by Certik were fixed in version 26.7.1, released July 27, with detailed advisories published on Aug. 14. Certik said the delayed disclosure was intentional: releasing the patch first gave node operators time to upgrade before attack details became public. The flaws could have let attackers exhaust node memory or threads, affecting availability and consensus processing.

Security

Term Finance Shuts Meta Vaults After Estimated $8.5 Million Governance Exploit

Term Finance closes Meta Vaults after $8.5M governance exploit Term Labs permanently closed its Term Meta Vaults after an attacker allegedly used majority control of a thinly held governance token to seize the strategy vaults and drain about $8.5 million, including 2,843 ETH and 1.68 million USDC swapped to DAI. The loss was roughly 68% of the vault product’s $12.45 million pre-attack holdings; deposits are now blocked, withdrawals remain open, and Term said its core borrowing and lending markets were unaffected.

Security

Estonia Revokes Zondacrypto License as Missing Executives and Frozen Funds Deepen Crisis

Estonia revokes Zondacrypto license as users stay locked out of funds Estonia’s Financial Intelligence Unit revoked BB Trade Estonia OÜ’s license on June 29, effectively shutting down Zondacrypto days before the EU’s July 1 MiCA deadline, while customers remained unable to access deposits and the platform had been offline since April. Recoveris said the exchange’s main Bitcoin hot wallet fell 99.7% to 0.086 BTC by April 1 and traced about $21 million sent to Kraken; Polish prosecutors have since folded the case into an organized-crime probe.

August 23, 2026

Security

Term Labs Says Governance Attack Drained About $8.5M From Term Finance Vaults

Term Labs says governance exploit drained $8.5M from Term Finance vaults Term Labs said a governance exploit hit several Term Finance vaults, with initial data showing the attacker used protocol rules rather than a code bug to withdraw about $8.5M in ETH and DAI. On-chain data cited in the report shows the attacker controlled four of the five drained vaults after converting share tokens into governance tokens, then used an Aug. 17 proposal and a six-day delay to change vault parameters and move the funds.

August 22, 2026

Security

MANTRA Chain Restarts Mainnet After 30-Hour Halt Triggered by Cosmos-EVM Flaw

MANTRA Chain restarts after 30-hour mainnet halt MANTRA Chain resumed block production around 5:30 a.m. UTC on Aug. 22 after deploying v8.4.0 to patch a Cosmos-EVM vulnerability that had halted mainnet transaction processing for about 30 hours. The team said two MANTRA-managed wallets were affected, but user balances were unchanged, no rollback was needed, and token holders did not need to take action.

Security

BounceBit to End Standalone Layer 1 and Move BB to BNB Chain After $3M Exploit

BounceBit to shut standalone Layer 1 after $3M BB token exploit BounceBit said it will wind down its standalone Evmos-based Layer 1 and migrate BB to BNB Chain after an attacker exploited an authorization flaw to move about 286.5 million BB tokens, worth roughly $3 million, across nine wallets. The team halted block production about 40 minutes after detecting the attack and said it will use a pre-attack snapshot to reverse unauthorized transfers and work with exchanges to restore customer balances.

Security

Two Binance Employees Detained at UAE Airports During Fraud Inquiry

UAE police briefly detained Binance staff in fraud probe Police in the United Arab Emirates stopped two Binance employees at airports and questioned a third in July as part of a fraud inquiry into funds moving through the exchange. All three were released, and Binance said the staff were asked for standard statements in routine inquiries tied to third-party fund flows, were not targets, and were promptly cleared.

August 21, 2026

Security

Coinkite Issues Coldcard Firmware Overhaul After Seed Flaw Linked to $100M in Bitcoin Theft

Coinkite pushes Coldcard security overhaul after seed flaw tied to $100M+ thefts Coinkite has released new firmware for Coldcard Mk4, Mk5 and Q wallets after a seed-generation flaw was linked to more than $100 million in stolen Bitcoin, and urged users to upgrade to 5.6.1 or 1.5.1Q. The update fixes issues in signing, USB data handling, firmware validation, Delta Mode and backups, and now requires users to add entropy when creating a seed with at least 65 key presses, 50 dice rolls or 128 coin flips. Users whose seeds were generated on affected versions between 2021 and July 2026 are being told to create a new seed on the updated firmware and move their BTC, while Coinkite said the thefts,

Security

India tells Google to shut down Firebase accounts linked to banking scam networks

India orders Google to remove Firebase accounts tied to banking scams India’s cybercrime agency I4C sent Google at least three notices in August seeking the shutdown of hundreds of Firebase accounts after tracing 57 Firebase-hosted websites and databases to fake banking apps and phishing operations. The notices said seven pages mimicked SBI, ICICI Bank and Axis Bank login screens, while other Firebase databases collected stolen card details, one-time passwords and malware data.

Security

BounceBit to retire its chain after $3.1 million BB token exploit

BounceBit to shut down chain after $3.1M BB token exploit BounceBit said it is sunsetting BounceBit Chain after hackers exploited an authorization flaw in an Evmos-based vesting and lockup module, moving 286 million BB tokens from nine wallets between Aug. 19 and 20. The firm said it cannot safely upgrade the discontinued Evmos infrastructure, so non-attacker balances will be reissued as BEP-20 BB on BNB Chain using a pre-exploit snapshot.

Security

Besu discloses five patched security flaws addressed in Ethereum client version 26.7.1

Besu details five patched security flaws in Ethereum client 26.7.1 Besu published advisories on Aug. 14 for five vulnerabilities privately reported by CertiK and fixed in version 26.7.1, released July 27. The flaws affected the Java-based Ethereum client’s peer-to-peer, RPC, WebSocket and consensus-facing interfaces and, in affected configurations, could exhaust memory or threads, disrupting node availability or consensus processing.

Security

USENIX Research Raises Phishing Concerns Around Ethereum’s EIP-7702 Delegation

USENIX research flags abuse risks in Ethereum’s EIP-7702 delegation Security research presented at the USENIX Security Symposium linked 63% of analyzed EIP-7702 authorization transactions to attacker-controlled contracts and identified more than $2.3 million in confirmed thefts from automated wallet-draining activity. The researchers did not describe a core Ethereum protocol bug; the risk is users being tricked into signing malicious wallet delegation authorizations.

Security

Check Point says 2,000 hacked WordPress sites were used to target crypto users

Check Point links StopAndProtect to 2,000 hacked WordPress sites Check Point Research said a group it calls StopAndProtect has turned nearly 2,000 poorly maintained WordPress sites into a malware network that steals crypto wallet seeds, passwords and files from Windows PCs via fake CAPTCHA pages. Logs from the attackers’ own exposed servers showed more than 6,000 unique IP infections by July 24, over 700 archives of stolen files and 20,000-plus victim screenshots.

Security

MANTRA Chain Pauses Network and Freezes Transactions After Unexplained Incident

MANTRA Chain halts network and freezes all transactions after incident MANTRA Chain has halted its network and frozen all transactions and endpoints after what the team called an incident affecting the chain. The disruption has hit deposits and withdrawals, and MANTRA asked exchanges and ecosystem partners to suspend trading in its native token while engineering and security teams investigate with external partners. No cause or recovery timeline has been disclosed.

August 20, 2026

Security

Fake AML screening sites use wallet approvals to steal crypto, researchers warn

Fake crypto AML checker sites trick users into wallet-draining approvals Malwarebytes says fraudulent anti-money laundering screening sites are impersonating services like AMLBot and prompting users to connect a wallet, sign a transaction, or pay a small “fee” to see a fake compliance result. Genuine wallet screening only requires a public address, not wallet connection or signing. Researchers found the same scam kit being rebranded under different names and logos.

Security

Check Point Links StopAndProtect Malware Campaign to Nearly 2,000 Hacked WordPress Sites

StopAndProtect hit 6,000+ IPs via hacked WordPress sites, Check Point says Check Point Research says the StopAndProtect operation used nearly 2,000 compromised WordPress sites to infect Windows users with fake CAPTCHA prompts that triggered PowerShell malware, stealing passwords, seed phrases and crypto wallet files, then spreading through networks and USB drives before locking screens or deploying ransomware. By July 24, researchers linked the campaign to more than 6,000 IPs and found 700+ archives of stolen data and 31,000+ victim screenshots exposed by the attackers’ own security mistakes.

Security

Rapid7 says crypto phishing campaign targeted 885,000 phone numbers across multiple markets

Rapid7 identifies crypto phishing campaign targeting 885,000 phone numbers Rapid7 said a phishing operation it calls Operation Asterix targeted about 885,000 phone numbers across several countries, using fake wallet-provider sites and support messages to steal crypto. The campaign matched 5,576 accounts to Binance users and impersonated Crypto.com, Ledger, Trezor, and Exodus; Rapid7 said about 13% of targeted accounts were hit and AI tools were a significant part of the operation.

Security

Binance Says It Helped Block $1.2 Million DAO Treasury Governance Attack

Binance says it helped stop $1.2M DAO treasury attack before execution Binance said on Aug. 18 that its monitoring team detected a malicious governance proposal targeting an unnamed DAO and, with less than 48 hours before execution, warned the project and coordinated with exchanges to close token deposits. The proposal was then voted down, blocking access to about $1.2 million in treasury tokens, while Binance did not name the project or token involved.

August 19, 2026

Security

Decred Issues Mandatory v2.1.6 Update to Fix Consensus, Mixing, and DoS Flaws

Decred releases mandatory v2.1.6 patch for consensus and mixing flaws Decred has issued a mandatory v2.1.6 update to fix a critical consensus vulnerability, a potential periodic deanonymization attack in its transaction mixing system, and several network DoS risks. The patch updates the mixclient protocol, changes how mixing sessions expire, and requires all users to upgrade to avoid running on a forked network; older dcrwallet clients will no longer mix with updated wallets.

Security

Maya Protocol pauses network after exploit drains an estimated $1.7 million

Maya Protocol halts network after exploit drains $1.7 million Maya Protocol paused its network after an attacker exploited six chained software bugs to steal about $1.7 million, including roughly 20 BTC and $300,000 in other assets, co-founder Aalux said. A preliminary analysis said a single 23-message transaction withdrew 48.87 million CACAO and helped crash the token 88.7% from about $0.115 to $0.013, while the team works on a fix to resume swaps.

August 18, 2026

Security

BitBox fixes two severe hardware wallet flaws in BitBox02 and Nova

BitBox patches two severe hardware wallet vulnerabilities BitBox has released a firmware update for BitBox02 and BitBox02 Nova fixing two severe flaws: one that could have let a malicious host install firmware on unconfigured Multi editions, and another in Silent Payments that could have locked Bitcoin to an unintended address. The company said neither issue was exploited and no user funds were reported lost.

Security

Three August Crypto Data Breaches Exposed 253,487 Customers in Four Days

Three crypto customer data breaches expose 253,487 users in four days SafePal, Trezor and Israeli broker Bits of Gold disclosed breaches between Aug. 13 and Aug. 16 that exposed a combined 253,487 customers’ names, phone numbers, addresses and purchase data. Trezor’s ShipMonk breach and Bits of Gold’s roughly 200,000-user breach were both tied to Metabase flaw CVE-2026-72898, while SafePal said a third-party order tracking plugin exposed 39,798 records. No keys or funds were stolen.

Security

Wallet Linked to 2022 Pando Rings Hack Moves ETH to Tornado Cash Again

Pando Rings exploiter swaps $3M DAI for ETH, sends 800 ETH to Tornado Cash A wallet tied to the 2022 Pando Rings oracle hack reactivated on Aug. 18 after two months of inactivity, swapping 3 million DAI for about 1,570 ETH via CoW Protocol, Onchain Lens reported. Around 800 ETH worth roughly $1.52 million was then sent to Tornado Cash in eight transactions, moving funds still traceable to the original exploit.

Security

Harmony to Rewind Chain After Exploit Minted 2.385 Trillion ONE

Harmony Protocol to roll back network after 2.385 trillion ONE exploit Harmony developers said they will rewind the chain to Aug. 11 after an Aug. 12 exploit let an attacker mint and transfer 2.385 trillion ONE through flaws in cross-shard receipt validation and quorum verification. The rollback will reset Shard 0 and Shard 1 to pre-breach checkpoints, discarding 141,628 blocks on Shard 0 as well as 109,126 user transactions and 315 staking transactions.

August 17, 2026

Security

Fake The Odyssey Pirated Downloads Used to Spread Lumma Stealer, Bitdefender Warns

Bitdefender warns fake Odyssey rips are spreading Lumma Stealer Bitdefender said fake pirated downloads of The Odyssey are circulating as supposed WEBRip and Blu-ray files but are actually Windows executables that install Lumma Stealer, malware that targets crypto wallets, browser passwords, payment data and remote desktop credentials. The malware also steals authentication cookies, which can let attackers hijack accounts even when MFA is enabled.

Security

Harmony proposes Aug. 11 rollback to remove forged ONE after network incident

Harmony proposes Aug. 11 rollback after forged ONE mint Harmony plans to restart its blockchain from two Aug. 11 checkpoints to remove ONE created in a forged mint, discarding all later activity including 109,126 regular transactions and 315 staking transactions. The network said validators would resume from shard 0 block 92,730,035 and shard 1 block 94,978,279, using replacement databases and client v2026.1.2 to reject the abnormal block hashes tied to the incident.

Security

BitMart shutdown faces pressure over frozen withdrawals and unpaid wage claims

BitMart shutdown draws scrutiny over frozen withdrawals and unpaid staff BitMart is facing fresh criticism as users report they still cannot withdraw funds and employees say their final month’s salary and compensation remain unpaid, even as the exchange says it is preparing an “orderly” shutdown. The company promised proof of reserves on May 23 but has yet to publish it; spot and futures trading are set to end on Aug. 26, with full closure scheduled for Jan. 31, 2027.

Security

Galaxy Research says Coldcard-related Bitcoin losses have exceeded $115 million

Galaxy: Coldcard losses top $115M as 1,778.58 BTC swept from 8,680 addresses Galaxy Research said Coldcard-related losses have reached more than $115 million, covering 1,778.58 BTC swept from 8,680 addresses since July 30 in data through Aug. 13. The firm said none of the stolen coins predate Coldcard’s March 17, 2021 firmware release, while the biggest sweep wave took about $70.2 million, or 61% of the total, draining 1,195 addresses in 41 minutes across nine blocks.

Security

Study Estimates $575 Million Lost to Address Misuse on Ethereum and BNB Chain

USENIX-backed study links address mistakes to $575M in ETH and BNB losses Researchers from Sun Yat-sen University, Peking University and Zhejiang University said on-chain analysis of millions of Ethereum and BNB Chain addresses found 65,340 high-risk cases of “address misuse” tied to testnet addresses, reused contracts and wallets with exposed private keys. The study estimates losses of about $575 million, including 104,245 ETH and 9,045 BNB sent to compromised wallets and 22,738 ETH plus 8,681 BNB sent to the wrong contract type.

Security

Apple fixes Mac screen-sharing bug exploited to install Monero miners

Apple patches Mac screen-sharing flaw used to install Monero miners Hackers exploited a pre-authentication flaw in Apple’s Mac screen-sharing feature to take full control of multiple internet-exposed Macs and covertly install Monero mining software, the Netherlands’ National Cyber Security Centre said. Apple fixed the bug on August 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9, and Microsoft researchers urged users to update immediately.

August 16, 2026

Security

SafePal says 39,798 customer orders were exposed in access-control breach

SafePal says nearly 39,800 customer orders exposed in security incident SafePal said an access-control flaw exposed order data for about 39,798 customers who placed orders between March 2 and April 11, including names, contact details, shipping addresses and purchase information. The company said seed phrases, private keys, wallet passwords and funds were not exposed, the flaw has been fixed, and affected users were notified as SafePal warned of phishing attempts using the stolen order details.

Security

Bits of Gold investigates third-party breach that may have exposed customer data

Bits of Gold probes third-party breach exposing customer data Israel-regulated crypto broker Bits of Gold said a cyber incident tied to a third-party support and analytics system may have exposed customer names, ID numbers, emails, phone numbers, IPs, bank account details and public wallet addresses. The company said customer funds, crypto, passwords, ID scans and full card details were not affected, and it has blocked access, disconnected the system and notified authorities.

August 15, 2026

Security

Sherlock Audit Found 96 XRPL Bugs Before Proposed Features Reached Mainnet

Sherlock audit finds 2 critical XRPL bugs before mainnet activation Ripple’s two-week Sherlock audit contest uncovered 96 valid vulnerabilities in five proposed XRP Ledger amendments, including two critical flaws that could have drained accounts without private keys or silently burned XRP through repeated fee charges. Ripple paid $309,000 from a $550,000 RLUSD prize pool, and both affected features were rewritten and shipped in xrpld 3.3.0 on Aug. 6 without being activated on mainnet.

Security

French Tax Agency Says 678,438 Taxpayers Were Exposed in Data Breach

French tax agency confirms data breach affecting 678,438 taxpayers France’s General Directorate of Public Finances said threat actors accessed and extracted addresses and real estate data tied to 678,438 taxpayers after compromising internal servers, with access cut off on June 12. The agency said login data was not exposed and it will notify affected people next week, while French crypto holders warned the leak could raise the risk of targeted “wrench attacks.”

August 14, 2026

Security

Galaxy: Confirmed Coldcard Bitcoin Theft Losses Exceed 1,778 BTC

Galaxy says Coldcard exploit thefts top 1,778 BTC Galaxy Research said the Coldcard seed-recreation exploit has now drained more than 1,778 BTC, about $112 million, from confirmed owner-attributed thefts since July 30, and warned the final figure will likely be higher. The firm said no confirmed attack activity has appeared after Aug. 6, likely because vulnerable holders migrated or most funds were already drained, but 1,531 BTC remains parked in attacker-controlled addresses.

Security

Singapore says fake crypto job scams and system breaches caused $11.8 million in losses

Singapore warns of $11.8M fake job scam targeting crypto and tech firms Singapore police and cyber agencies said a scam built around fake job offers and compromised software systems caused $11.8 million in losses. In one case, a LinkedIn approach led a victim to run malware in a bogus coding test on a company device; it stole a session token, bypassed MFA, accessed a Bitbucket code repository, and helped attackers alter internal systems and move funds by evading transaction and approval checks.

Security

Google Suspends Advertiser After Reported $550,000 Hyperliquid Phishing Loss

Google suspends advertiser after reported $550,000 Hyperliquid phishing loss A Hyperliquid user appears to have lost about 550,019 USDC on Aug. 13 after interacting with a phishing site allegedly promoted through a Google search ad, based on on-chain transfers flagged by FlashRescue co-founder Darcy. Google said it suspended the advertiser tied to the campaign, while available evidence does not indicate any breach of Hyperliquid’s blockchain or trading protocol.

August 13, 2026

Security

Trezor says ShipMonk breach exposed order data for about 13,700 customers

Trezor data breach exposes details of nearly 13,700 customers Trezor said a breach at shipping partner ShipMonk exposed customer order data for about 13,700 users across seven countries after an unauthorized party accessed ShipMonk systems. The leaked data included names, emails, phone numbers and shipping addresses for 11,742 customers, while 1,947 others had names, cities and emails exposed; Trezor said its internal systems and hardware wallets were not compromised.

Security

Six npm Packages Used Ethereum Wallet Data to Conceal Malware Control Servers

Sonatype flags six npm packages using Ethereum wallet to hide malware C2 Sonatype Research Labs said six npm packages used an attacker’s Ethereum wallet to fetch command-and-control server addresses, including three compromised real libraries: @kolbo/mcp@1.57.1, agentgui@1.0.1127 and godot-kit@1.0.1786316795. The same payload also appeared in envpack-conf@1.0.1, postcss-initial-provider@3.0.4 and tailwindcss-motion-advanced@1.0.1; Sonatype urged anyone who installed them to remove the packages and check for second-stage code execution.

Security

Trezor says shipping partner breach exposed some customer addresses and phone numbers

Trezor warns customer data leaked in third-party shipping breach Trezor said a third-party shipping partner exposed some customer phone numbers and shipping addresses, while its own systems, devices, private keys and wallet backups were not compromised. The company said only customers who received notification emails were affected, with the impact limited by a policy requiring partners to delete or anonymize order data 90 days after delivery. It is now accelerating an Anonymous Delivery option in the EU by September and in the US by year-end.

Security

Researchers Detail 'Zoomsday' Zoom Flaws That Enabled Zero-Click Meeting Takeovers

Researchers disclose Zoom flaws that enabled zero-click device takeover in meetings Israeli cybersecurity firm A Security said a researcher used fewer than 20 AI prompts to find three Zoom vulnerabilities and build a working “Zoomsday” exploit in under 24 hours, allowing code execution on another participant’s device with no click, download or approval. Zoom released fixes between June 22 and July 20, but users on older app versions still need to update because server-side protections cannot fully stop the attack in end-to-end encrypted meetings.