ZeroHour
Country

Sweden

3 mentions in 7 days · 7 in 30 days · 8 total · first seen · last

Timeline

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

Trezor reported phishing after the Brevo breach targeted 347,000 newsletter subscribers, with 2,500 users clicking before the domain was taken down.

Threat actors who breached Trezor's third-party email provider Brevo on September 9, 2026 sent fake 'critical security alert' emails from [email protected] to 347,000 opted-in newsletter subscribers, claiming an STM32 microcontroller vulnerability exposed wallet seeds. The emails linked to a malicious app that asked users to enter their wallet backup; 2,500 users clicked before Trezor disabled the phishing domain within 20 minutes. Trezor also disclosed that a prior breach via logistics provider ShipMonk, exploited through a critical Metabase SQL injection zero-day, affected 81,000 customers and drew extortion emails from the ShinyHunters gang.

BleepingComputerupdated · 4d agofirst · 4d agoPhishing & fraud in the wild 6 sources

UK Council Attack Linked to Mass Exploitation of SonicWall Flaw

Hunt.io links a UK council attack to mass exploitation of SonicWall SMA1000 flaw CVE-2026-15409 (CVSS 10.0), enabling credential and Active Directory theft.

Hunt.io links, with moderate confidence, the July 17, 2026 attack on the Borough Council of King's Lynn and West Norfolk to mass exploitation of SonicWall SMA1000 appliances via CVE-2026-15409, an unauthenticated SSRF in the WorkPlace portal WebSocket proxy with CVSS 10.0. The operator adapted Rapid7's July 15 PoC into a 50-thread mass scanner within days and stole LDAP credentials for 534 Active Directory accounts across 160 domains, with nine environments losing SAM/LSA secrets and five losing full AD databases via DCSync. CISA added the flaw to its Known Exploited Vulnerabilities catalog and noted use in ransomware campaigns; targeting of ~200,000 Shodan-derived SonicWall addresses spanned government, healthcare, finance, universities, and manufacturing worldwide.

Security Affairs · 4d agoExploit / PoC in the wildCVE-2026-154091

Trezor warns users of email provider breach, phishing attacks

Trezor says attackers breached its third-party email provider and are phishing customers with fake STM32 entropy vulnerability alerts.

Trezor warned customers that threat actors breached its third-party email provider and sent fake 'Critical Security Alert: STM32 Entropy Vulnerability' emails from [email protected], claiming wallet seeds were exposed to brute-force attacks; the phishing domain has been taken down while Trezor investigates. This follows the ShipMonk breach, revised upward from about 14,000 to 81,000 customers (including 67,000 additional US customers) who received orders between May 10 and August 8, 2026. Attackers reportedly exploited a Metabase SQL injection zero-day to access ShipMonk data, and ShinyHunters sent extortion emails.

BleepingComputerupdated · 4d agofirst · 5d agoData breach in the wild 6 sources

Trezor customers hit with phishing calls and letters after shipping-partner breach

A breach at shipping partner ShipMonk exposed data for about 67,000 additional US Trezor customers, who now face phishing calls and QR scam letters.

SatoshiLabs, maker of Trezor hardware wallets, confirmed the August 2026 ShipMonk breach exposed names, emails, phone numbers, and shipping addresses for roughly 67,000 US customers who ordered between November 2019 and August 2021, on top of 3,889 customers affected initially. ShipMonk attributed the intrusion to attackers exploiting an SQLi zero-day in Metabase's Cloud SaaS platform and retained data past the 90-day deletion requirement. Trezor's own systems were not compromised; customers are reporting phishing calls and QR-code phishing delivered via physical letters.

Help Net Security · 7d agoData breach

Trezor data breach impact now reaches 81,000 customers

Trezor's ShipMonk breach now affects 81,000 customers, adding 67,000 US customers after Metabase exploitation by ShinyHunters-linked attackers.

Trezor expanded its August 13 breach disclosure, saying the incident at shipping partner ShipMonk now affects 81,000 customers, with 67,000 additional US customers who ordered between November 2019 and August 2021 exposed. Attackers exploited a Metabase SQL injection zero-day to access ShipMonk's systems, exposing names, emails, phone numbers, shipping addresses, and order numbers; ShipMonk reportedly received extortion emails from the ShinyHunters gang. Trezor's own systems and devices were not compromised, and affected users are warned of phishing and scams. The broader Metabase campaign also hit Tally and Framework.

BleepingComputer · 8d agoData breach in the wild

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

CERT Polska and CISA report active exploitation of Zimbra RCE CVE-2026-73570, with 267 instances compromised per Shadowserver.

CVE-2026-73570 (CVSS 8.9) enables unauthenticated command injection and remote code execution in Zimbra Collaboration before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled, via crafted SMTP requests. CISA added the flaw to its KEV catalog on August 21, 2026, with a federal patch deadline of August 24. The Shadowserver Foundation counted 267 compromised instances as of August 24, 2026, led by the US (46), Sweden (21), France (20) and Germany (17). Separately, Russia-linked Laundry Bear has weaponized Zimbra stored XSS CVE-2025-66376 against Western government and commercial mail servers since at least July 2025, delivering the ZimReaper payload.

The Hacker News · 20d agoExploit / PoC in the wildCVE-2026-73570CVE-2025-663761

Analysis of Smoke Loader in New Tsunami Campaign

Fake Japanese Meteorological Agency tsunami warning emails delivered Smoke Loader and AzoRult malware to steal credentials from targets in Japan.

A fake tsunami warning email impersonating Japan's Meteorological Agency asked recipients to click a link on a registered fake agency domain, delivering the commodity loader Smoke Loader to targets in Japan. Smoke Loader, active since 2011, is modular, and its payloads have included banking trojans, ransomware, cryptominers, password stealers, and PoS malware; the campaign later also deployed AzoRult. New samples add junk-jump obfuscation, encrypted network traffic and payload files, a unique machine ID used for tracking and encryption, and PROPagate injection into explorer.exe, with persistence via a Startup folder shortcut and RC4-encrypted C2 communication.

Palo Alto Unit 42 · 29d agoMalware in the wild

ExfilSquad Targets New Victims, Shares Data via Torrents

Extortion group ExfilSquad lists 13 new US, UK and Swedish victims and now distributes stolen data via peer-to-peer torrents.

ExfilSquad, a data-theft extortion collective that emerged in mid-2026, announced 13 new victims in the US, UK and Sweden with an August 5, 2026 negotiation deadline. The group skips ransomware, instead stealing data and threatening publication on a dark web leak site. Resecurity says its TTPs center on exploiting misconfigured Microsoft Dataverse, Power Pages, case management and CRM portals. The group now distributes stolen data through per-victim torrent trackers and web seeds, making leaks hard to contain.

Security Affairs · Aug 11, 2026Threat actor in the wild

Related CVEs

  • Unauthenticated SSRF in SonicWall SMA1000 Appliances
    CVE-2026-15409 is a server-side request forgery (SSRF, CWE-918) in the Appliance Work Place interface of SonicWall SMA1000 series appliances. A remote, unauthenticated attacker can trigger the flaw over the network, causing the appliance to issue requests to attacker-influenced or unintended internal locations. Because the CVSS vector scores scope-changed impacts on confidentiality, integrity, and availability, the SSRF is assessed as capable of reaching sensitive internal services, and reporting indicates it is being used alongside a second SMA1000 zero-day in what may be an exploitation chain. Affected organizations are those running SMA1000 appliances, including SMA 6210, SMA 7210, and SMA 8200v models, which typically act as internet-facing remote-access/VPN gateways. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2026-07-14, ransomware use is known, and EPSS assigns an 83.7% probability of exploitation within 30 days, though no public PoC is available.
    · SonicWall SMA1000 Appliances (SMA 6210 firmware) · SonicWall SMA1000 Appliances (SMA 7210 firmware) KEV ransomwarelarge
  • Unauthenticated OS Command Injection RCE in Synacor Zimbra Collaboration Suite
    CVE-2026-73570 is an OS command injection vulnerability (CWE-78) in Synacor Zimbra Collaboration Suite (ZCS) before 10.1.20, caused by improper sanitization of untrusted input during SNMP notification processing. It is triggered when the optional zimbra-snmp package is installed and SNMP notifications are enabled: an unauthenticated attacker sends specially crafted SMTP requests that the flawed notification path turns into execution of arbitrary operating system commands. Successful exploitation runs commands as the Zimbra user, giving attackers control of the mail server's service account with high confidentiality and integrity impact across the host. Only ZCS deployments running the optional SNMP component with notifications enabled are vulnerable; other Zimbra installs are not exposed to this specific flaw. The flaw is under active exploitation: CISA added it to the KEV catalog on 2026-08-21, Poland's CERT has warned of in-the-wild attacks, unpatched Zimbra servers are reported compromised, and two public proof-of-concept exploits exist.
    · Synacor Zimbra Collaboration Suite (ZCS) before 10.1.20 (when the optional zimbra-snmp package is installed and SNMP notifications are enabled) KEV PoC ×4large
  • Stored Cross-Site Scripting in Synacor Zimbra Collaboration Suite Classic UI
    Zimbra Collaboration Suite (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 is vulnerable to stored cross-site scripting through its Classic webmail interface. An attacker sends an HTML e-mail containing a Cascading Style Sheets (CSS) @import directive, and when a recipient opens that message in Classic UI, the injected content executes as script in the victim's browser session. Successful exploitation lets an attacker run arbitrary JavaScript in the Zimbra webmail context, potentially hijacking the session, reading mail, or acting as the user, consistent with the cross-scope impact reflected in the 6.1 CVSS score. Only deployments running the affected ZCS 10/10.1 versions with the Classic UI enabled are exposed; organizations on patched releases or not using Classic UI are not impacted. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-03-18, confirming exploitation in the wild, and recent reporting describes Zimbra flaws being used by Russian-aligned espionage actors against Western and Ukrainian targets.
    · Synacor Zimbra Collaboration Suite (ZCS) 10 10.x before 10.0.18 · Synacor Zimbra Collaboration Suite (ZCS) 10.1 10.1.x before 10.1.13 KEVlarge

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.