SafePal says a breach exposed personal data of 39,798 customers, but not wallet credentials, private keys, seed phrases, or payment information. SafePal disclosed a data breach affecting about 39,798 customers after hackers exploited a vulnerability in its order-tracking plugin. The flaw exposed information linked to orders placed between March 2, 2025, and April 11, 2026, […]

SafePal, a Singapore-based cryptocurrency security firm, has confirmed a data breach impacting approximately 39,798 customers. The incident, disclosed on August 17, 2026, stemmed from an authorization flaw within an order-tracking plugin used by the company. This vulnerability allowed unauthorized access to customer order information for purchases made between March 2, 2025, and April 11, 2026.
The exposed data includes customers' names, email addresses, shipping addresses, phone numbers, and specific purchase details. SafePal emphasized that critical wallet credentials such as seed phrases, private keys, wallet passwords, bank details, payment card numbers, or government IDs were not compromised, as the company does not collect or store such sensitive financial information. There is no evidence that the breach directly led to unauthorized access to customer wallets or funds.
The disclosure followed a threat actor's attempt to advertise the stolen data on a cybercrime forum, claiming the same number of affected customers. SafePal has since confirmed the security incident and individually notified all affected customers via email on August 16, urging them to verify their status.
The company warned that the exposed order data could be leveraged by attackers for more sophisticated phishing attempts. These could include fake support calls, emails, fraudulent refund offers, deceptive firmware updates, or malicious websites designed to trick users into revealing additional information or wallet credentials.
While the breach itself does not necessitate moving assets, SafePal advised that any customer who has shared a seed phrase or private key in response to a suspicious message, website, phone call, or letter should consider that wallet compromised. In such cases, users should create a new wallet using a trusted SafePal device or official application and immediately transfer any remaining funds.
SafePal has implemented a fix for the identified vulnerability and introduced additional security measures. An independent security firm is reportedly reviewing the fix and the company's order-processing systems. Furthermore, SafePal has reduced its data retention period to 90 days for relevant information, contacted affected logistics partners, and established a dedicated support channel for inquiries.
The company has also identified and removed over 30 fraudulent websites and phishing links related to the incident. SafePal stated it would continue to monitor for scams, investigate potential risks, and provide updates through its official channels. Customers who have experienced financial losses directly linked to the breach are encouraged to contact SafePal, which is collaborating with specialists to trace stolen on-chain assets.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.