Affecting European contract logistics operations at eight Ceva warehouses, the incident caused shipment delays for multiple customers. The post Ceva Logistics Operations Disrupted by Cyberattack appeared first on SecurityWeek.

Ceva Logistics has reportedly experienced a cyberattack that has disrupted its European contract logistics operations. The incident has specifically impacted eight of Ceva's warehouses, leading to shipment delays for an unspecified number of customers.
The nature of the cyberattack has not been detailed, but such incidents commonly involve ransomware, data-wiping malware, or denial-of-service attacks. In the context of logistics, these types of attacks can cripple critical systems responsible for inventory management, warehouse automation, shipping manifests, and communication with transportation partners. The disruption of these systems directly impedes the ability to process, track, and dispatch goods, leading to the reported delays.
Logistics companies are particularly attractive targets for cybercriminals due to their central role in global supply chains. An attack can have a cascading effect, impacting not only the primary target but also numerous upstream and downstream businesses reliant on their services. The reported impact on contract logistics suggests that systems managing third-party warehousing, distribution, and fulfillment services were specifically compromised.
Mitigation strategies for this class of cyberattack typically involve robust network segmentation to contain breaches, comprehensive backup and recovery plans to restore operations, and incident response protocols to manage the fallout. Regular security audits, employee training on phishing and social engineering, and the timely application of security patches are also standard practices to reduce the attack surface. For operational technology (OT) environments often found in warehouses, specific cybersecurity measures are required to protect industrial control systems.
Organizations facing such disruptions often prioritize restoring critical operational systems, communicating transparently with affected customers, and investigating the root cause of the breach. This investigation typically involves forensic analysis to determine the entry point, the extent of data compromise, and the specific malware or attack techniques used.
The incident at Ceva Logistics underscores the persistent and evolving threat landscape facing critical infrastructure and global supply chains. As businesses become increasingly interconnected and reliant on digital systems for core operations, the potential for cyberattacks to cause significant physical and economic disruption continues to grow. This event serves as another reminder of the imperative for comprehensive cybersecurity strategies across all sectors.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.