LIVE · cybersecurity feed
Live wire
OpenAI locks down Astra over potential critical cyber capabilitiesCritical Flaws Discovered in Belgian eID Software Used by 2 Million PeopleSecurity Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITIONWebmail CSS Attacks Expose a New Risk for AI-Powered Email ToolsMetabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataCVE-2026-8037 · CISA Adds Progress LoadMaster Command Injection Flaw to KEV CatalogSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersNew CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
breach

Cyberattack on Steam hardware shipper leaks names, addresses, and order data

Video game publisher Valve is alerting customers in Europe to a data breach at CEVA Logistics, its Steam hardware shipping partner. Reports from affected customers began surfacing on social media earlier today, after Valve started sending out data breach notification emails. “Between July 29 2026 and August 1, 2026, a cyberattack hit CEVA Logistics, the company that ships Steam hardware to custome

zeroday.news ·

Valve, the video game publisher, has begun notifying European customers of a data breach at CEVA Logistics, its shipping partner for Steam hardware. The incident, which occurred between July 29 and August 1, 2026, potentially exposed personal information and order details for customers who purchased Steam hardware in Europe.

Valve stated that it was informed by CEVA Logistics on August 7, 2026, that a cyberattack likely compromised customer data. The affected information includes names, street addresses, postal codes, cities, countries, phone numbers, and email addresses associated with Steam accounts. Additionally, the type and price of the ordered hardware were exposed. CEVA Logistics retains this delivery information for up to 90 days post-order, and Valve is contacting all customers whose orders fall within this timeframe.

According to Valve, CEVA Logistics does not have access to sensitive data such as payment information, passwords, or Steam Guard codes, and these were not impacted by the breach. The company emphasized that no password changes or account setting adjustments are necessary for Steam accounts as a result of this incident.

Customers are being warned to be vigilant against potential phishing attempts via email, SMS, or phone calls. These fraudulent messages may reference specific hardware orders and personal addresses to appear legitimate, asking for confirmation of delivery, payment of small fees, or login credentials to verify orders. Valve advises treating all such communications as fake.

CEVA Logistics has reportedly isolated the compromised systems, taken them offline, and engaged external investigators to probe the incident. Valve is actively seeking more details from CEVA regarding the nature of the breach and the extent of the data compromised. The company is also in the process of notifying relevant data protection authorities in the affected European countries.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Metabase zero-day exploited to access Framework customer data

Framework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day vulnerability in the Metabase business intelligence service. According to the notification sent to affected Framework customers, the attackers accessed names, email addresses, phone numbers, physical addresses, and login IP addresses,

security

Poland uncovers second heat plant cyberattack that went hidden for months

The incident occurred on the same day as coordinated cyberattacks struck more than 30 other renewable energy installations and a larger heat plant, as Poland publicly disclosed in January.

security

Senate Democrats introduce bill to distribute $300 million annually to shore up water system cybersecurity

Two Democratic senators introduced legislation that would allocate $300 million each year to fund cybersecurity improvements for the water and wastewater sector.

vulnerability

Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant

Atlassian fixed a flaw letting one crafted link make its Rovo AI assistant exfiltrate company data

security

UK man tied to The Com sentenced for abusing 117 victims

Justin Swaddle, who was a minor when he committed the crimes, coerced children across multiple countries into self-harm and sexual abuse using threats tied to their personal information, authorities said. The post UK man tied to The Com sentenced for abusing 117 victims appeared first on CyberScoop.

security

Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification

Cisco is proud to announce a landmark achievement: Secure Email Threat Defense has officially achieved FedRAMP Class D (High) certification!