星球日报
星球日报|9月 11, 2026 04:30
[Brevo Login Vulnerability Causes Phishing Emails Sent to 347,000 Trezor Subscribers, BitBox and CoinTracking Accounts Also Affected] Odaily Planet Daily News: A vulnerability in the login system of the email platform Brevo allowed attackers to access 138 customer accounts and send phishing emails to approximately 347,000 Trezor newsletter subscribers. Accounts belonging to BitBox and the cryptocurrency portfolio and tax reporting platform CoinTracking were also used to send similar scam emails. Trezor stated that the phishing email was titled 'Critical Security Alert: STM32 Entropy Vulnerability,' with links directing users to an application requesting wallet backups. Trezor disabled the associated domain via DNS within 20 minutes, but approximately 2,500 people had already accessed the link. All 347,000 subscribers were subsequently warned of the risk. Brevo explained that attackers exploited a misconfiguration in single sign-on permission boundaries, gaining access to all organizations accessible to invited users. Six accounts were used to send phishing emails, and contact data from 43 accounts was exported. BitBox and CoinTracking stated that no company credentials, funds, or recovery phrases have been found to be compromised so far, but the associated email addresses are being treated as potentially accessed. (Cointelegraph)
+5
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads