๐ฅ BREACHES & INCIDENTS
- ShipMonk breach exposes data of 13,689 Trezor customers
A ShipMonk breach exposed personal data belonging to 13,689 Trezor customers.
- Trezor customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal were affected.
- The exposed data included names, phone numbers, email addresses, shipping addresses, cities, and order numbers.
- Full details were taken for 11,742 customers; names, cities, and email addresses were exposed for another 1,947.
- ShipMonk reported unauthorized access to systems storing Trezor order data for orders shipped from May 10 through August 8, creating targeted phishing risk.
- Trezor said its systems, hardware wallets, private keys, and wallet backups were not compromised. ๐ Source: x.com ยท ๐ Coverage: decrypt.co ยท ๐ via Cyber Security News, cryptika.com (discovered)
๐ CVEs & KEV
- CVE-2026-73625 โ CVSS 8.7 โ GitPython before 3.1.54 Remote Code Execution via kwarg value smugglingGitPyt...
- CVE-2026-73622 โ CVSS 8.7 โ GitPython before 3.1.55 Environment Variable Exfiltration via Remote.add()Git...
- CVE-2026-73618 โ CVSS 8.7 โ Budibase Server before 3.40.0 NoSQL Injection via JSON ParameterBudibase Serv...
- CVE-2026-73612 โ CVSS 8.6 โ File Browser before v2.63.22 Authorization Bypass via Recursive OperationsFil...
- CVE-2026-73623 โ CVSS 7.7 โ GitPython before 3.1.54 Remote Code Execution via --templateGitPython before ...
- CVE-2026-73611 โ CVSS 7.6 โ File Browser 2.50.0 through 2.63.21 JWT Expiration BypassFile Browser version...
- CVE-2026-73624 โ CVSS 7.2 โ GitPython before 3.1.54 Arbitrary File Overwrite via diffGitPython versions b...
- CVE-2026-73620 โ CVSS 7.2 โ GitPython before 3.1.57 Arbitrary File Overwrite and ReadGitPython before 3.1...
- CVE-2026-73613 โ CVSS 7.2 โ filebrowser before 2.63.19 Out-of-Scope File Deletion via Symlinkfilebrowser ...
- CVE-2026-73619 โ CVSS 7.1 โ GitPython before 3.1.57 Arbitrary File Read via Repo.archive()GitPython befor...
- CVE-2026-73617 โ CVSS 7.1 โ Budibase before 3.40.0 NoSQL Injection via MongoDB datasourceBudibase before ...
- CVE-2026-68868 โ CVSS 6.5 โ Apache Airflow Google provider: google Secret Manager backend: team scope is ...
- CVE-2026-73627 โ CVSS 6.0 โ JupyterLab 4.6.0 Plugin Manager Lock-Rule Enforcement BypassJupyterLab (pip p...
๐ต๏ธ RESEARCH & DEEP DIVES
-
Jewelbug APT Runs Browser Espionage and Cryptocurrency Fraud Campaigns Jewelbug conducted large-scale espionage and cryptocurrency fraud campaigns.
- Jewelbug targeted government, military, police, telecommunications, and aerospace organizations across Asia and the Middle East.
- The group stole browser cookies, session tokens, credentials, email bodies, browsing history, screenshots, and traffic.
- A malicious Chrome and Firefox extension called "PDF Viewer" requested broad permissions and remotely controlled victims' browsers.
- Compromised government webmail platforms delivered the extension and Antino backdoor through planted scripts and fake update prompts.
- Jewelbug's XG-Web panel recorded more than 580,000 stolen browser cookies, 2,300 exfiltrated email bodies, and more than one million implant check-ins. ๐ Source: sed-cms.broadcom.com ยท ๐ Coverage: security.com ยท ๐ via Cyber Security News
-
Industrial ransomware incidents rose 12% to 1,140 in Q2 2026 Dragos identified 1,140 ransomware incidents affecting industrial organizations in Q2 2026.
- Manufacturing organizations accounted for 747 incidents, or 65% of the total.
- Enterprise IT, ERP, virtualization, identity, and remote-access systems supporting OT were the main targets.
- Dragos found no Q2 cases involving direct ICS access or