Valve has alerted European customers of its Steam hardware that a data breach at its shipping partner, CEVA Logistics, has exposed personal information. The exposed data includes names, addresses, phone numbers, and Steam account emails, along with details of hardware orders. While passwords and payment information were not compromised, the exposed data could be used in sophisticated phishing and delivery scams.

Valve has issued a warning to European customers who recently purchased hardware through its Steam platform, advising them to be vigilant against potential delivery scams following a cyberattack on its shipping partner, CEVA Logistics. The incident, which occurred between July 29 and August 1, 2026, exposed personal information including names, home addresses, phone numbers, Steam email addresses, and details of hardware orders.
Valve confirmed it was notified of the breach on August 7 and began notifying affected customers on August 10. The company emphasized that its own systems were not compromised and that customer passwords and payment information remain secure. The breach specifically affected data held by CEVA Logistics, which handles deliveries for Steam hardware in Europe.
CEVA Logistics typically retains delivery data for approximately 90 days post-shipment. This means any customer in Europe who received a Steam Deck, Steam Controller, or Steam Machine within the last three months could be impacted. The exposed data includes the customer's name, street address, postal code, city, country, phone number, the email address linked to their Steam account, and specifics about the ordered hardware, such as type and price. The exact number of affected customer records has not been disclosed by either Valve or CEVA.
Reports indicate that Dutch retailers Bol and De Bijenkorf were also informed of the same CEVA incident on August 1 and subsequently alerted their customers.
The primary concern stemming from this data exposure is the potential for highly convincing phishing attempts. Scammers can leverage the stolen information to craft emails, text messages, or even phone calls that accurately reference a customer's genuine order and delivery address. These fraudulent communications might then request a small customs or redelivery fee, ask for confirmation of delivery, or prompt the user to sign in to verify their order, all designed to trick recipients into divulging further sensitive information or clicking malicious links.
Valve's advice to customers is to treat any unsolicited message concerning a recent Steam hardware order as potentially fraudulent, regardless of how accurate the details appear. The company reiterated that Steam Support communicates with users only through its official help page and never via email, Steam Chat, or Discord. While a password reset is not immediately necessary due to the nature of the breach, Valve recommends maintaining strong, unique passwords and enabling Steam Guard's two-factor authentication.
This incident is not Valve's first encounter with security challenges. In May 2025, a threat actor attempted to sell a dataset purportedly containing 89 million Steam user records, which Valve later clarified were older SMS messages with expired two-factor codes routed through an unpartnered third party. A more direct breach occurred in November 2011, exposing records from 35 million users, including usernames, emails, and encrypted credit card details.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed