Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics. [...]

Pokémon Center has begun notifying customers in the United Kingdom and Germany about a third-party data breach that exposed personal and order information. The incident stemmed from a cyberattack on CEVA Logistics, a vendor Pokémon Center uses to fulfill and ship orders from PokemonCenter.com in those regions.
CEVA Logistics, a subsidiary of the CMA CGM Group, confirmed it was the victim of a cyberattack that began on July 30, 2026. The breach compromised CEVA's systems between July 29 and August 1, affecting multiple retailers in Europe. This attack also impacted Valve, which previously informed its European Steam hardware customers that their names, addresses, phone numbers, email addresses, and product order details were stolen.
According to Pokémon Center's notification emails, unauthorized parties may have obtained customers' full names, mailing addresses, phone numbers, email addresses, and specific details about the contents of their PokemonCenter.com orders. The company emphasized that other customer-related information was not affected and that CEVA does not have access to customers' payment card details.
The cyberattack has led to significant disruptions, including shipping delays and the cancellation of some Pokémon Center orders. While a notice on the Pokémon Center UK website acknowledges delays, customers have reported receiving cancellation emails for various merchandise, not just highly anticipated collection products. The specific reason why the breach necessitated cancellations rather than just delays remains unclear.
CEVA Logistics operates 1,000 warehouses and handled 15 million shipments in 2025, reporting $18.3 billion in revenue. The attack disrupted eight of its European warehouses, contributing to the shipping issues. Valve's breach notification indicated that CEVA typically retains delivery-related information for up to 90 days post-order, though it is not confirmed if the same retention period applies to Pokémon Center customer data.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.