Hackers stole the customers’ shipping information, including names, addresses, email addresses, and phone numbers. The post 14,000 Trezor Customers Impacted by Data Breach at ShipMonk appeared first on SecurityWeek.

A recent report indicates that approximately 14,000 customers of Trezor, a hardware wallet manufacturer, have had their shipping information compromised in a data breach affecting ShipMonk, a third-party logistics provider. The stolen data reportedly includes names, physical addresses, email addresses, and phone numbers belonging to these customers.
The incident centers on ShipMonk, which handles fulfillment services for various companies, including Trezor. This type of breach highlights the supply chain risks inherent in modern e-commerce, where sensitive customer data often resides with multiple vendors beyond the primary service provider. For Trezor customers, the exposure of shipping details could lead to various follow-on attacks, even though the core security of their hardware wallets remains unaffected.
The compromised information—names, addresses, email addresses, and phone numbers—constitutes personally identifiable information (PII). While not directly compromising financial assets or cryptographic keys, this data is highly valuable for social engineering and phishing campaigns. Attackers could leverage this information to craft convincing phishing emails or SMS messages impersonating Trezor or other related services, attempting to trick victims into revealing further sensitive data or downloading malware.
This class of data breach typically occurs through vulnerabilities in web applications, misconfigured cloud storage, or compromised employee credentials at the third-party service provider. Attackers often exploit weaknesses in authentication mechanisms, inject malicious code, or leverage unpatched software to gain unauthorized access to databases containing customer records. Once access is gained, data exfiltration can occur rapidly and often without immediate detection.
For customers impacted by such breaches, common mitigation advice includes heightened vigilance against unsolicited communications. Users should be wary of any emails, text messages, or phone calls that appear to be from Trezor or related entities, especially those requesting personal information, login credentials, or prompting urgent action. It is always recommended to navigate directly to official websites for any account management or support inquiries, rather than clicking links in suspicious messages.
Organizations that rely on third-party vendors for data processing or storage are typically advised to implement robust vendor risk management programs. This includes conducting thorough security assessments of third-party providers, ensuring strong data encryption practices, implementing multi-factor authentication for all access points, and establishing clear data retention and incident response protocols. Regular security audits and penetration testing can also help identify and remediate vulnerabilities before they are exploited.
This incident underscores the persistent challenge of securing customer data across complex digital supply chains. Even companies with strong internal security, like hardware wallet manufacturers, remain exposed to risks originating from their partners. The broader context of cybersecurity continues to emphasize that an organization's security posture is often only as strong as its weakest link within its network of vendors and service providers.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.