Tech News
← Home  ·  All topics

Phishing Attacks

3 GoKawiil briefs on this topic

Trezor confirms 347,000 emails exposed via Brevo breach, 2,500 users phished

Trezor disclosed that a breach at its third-party email provider Brevo let attackers send fake security alerts to its opt-in newsletter subscribers, reaching roughly 347,000 email addresses. The fraudulent messages warned of a fake microcontroller vulnerability and pushed recipients to a malicious app requesting wallet backup phrases; Trezor says 2,500 people clicked the link before it disabled the domain within 20 minutes.

Trezor's email vendor breached, used to send fake security-alert phishing emails

Trezor alerted customers that attackers compromised its third-party email provider and used the legitimate [email protected] address to send phishing emails warning of a fake 'STM32 Entropy Vulnerability' in its hardware wallets. The company took down the malicious domain and is investigating how attackers gained access to its email infrastructure. This follows an earlier breach disclosed in August involving shipping partner ShipMonk, which exposed personal data of roughly 81,000 customers across multiple countries.

Researchers Catalog 39 Attack Techniques Targeting Passkey Systems

Security researchers, including work from SpecterOps, have documented at least 39 distinct methods that can undermine passkey authentication despite the underlying FIDO2 cryptography remaining secure. These techniques target the surrounding infrastructure rather than the cryptographic keys themselves, including browsers, operating systems, password managers, sync services, Bluetooth transport, and account recovery workflows. Many have working proof-of-concept tools, and some techniques are already surfacing in real-world attack activity.