
Fake HBO Max ads on Reddit pushed a ClickFix lure that could install info-stealing malware.
TechCrunch reports that scammers targeted hundreds of thousands of Trezor crypto wallet customers after a breach at email provider Brevo enabled phishing emails with malicious links.

Trezor warned customers that a company it relies on was hacked, exposing customer data to attackers for the second time in as many months. TechCrunch reports that the incident involved Brevo, a marketing technology company Trezor uses to send newsletters.
According to Trezor, the breach allowed hackers to send around 347,000 phishing emails to Trezor customers. The messages included a malicious link that appeared to come from the wallet maker.
The malicious link downloaded an app that asked victims for their wallet backup password. One email subject line cited by Trezor was “Critical Security Alert: STM32 Entropy Vulnerability.”
The key risk is direct and severe: with a stolen wallet password, an attacker can irreversibly steal a person’s funds on the public blockchain. Customers should treat urgent wallet-security messages, downloads, QR codes, and password prompts as high-risk unless verified through trusted channels.
Brevo said hackers accessed 138 Brevo accounts to send the mass phishing messages. The company said the attackers abused a flaw that meant access was “not properly scoped.”
Brevo also said the hackers’ access was “wrongly granted” to all organizations the attackers’ accounts could reach. The incident highlights how third-party vendors can become a security weak point for companies that rely on them for customer communications and operations.
Trezor said its products, wallets, and account system were not affected by the Brevo incident. Still, the exposed email addresses may be used again in future phishing attacks, and Trezor said it was reevaluating its vendor relationships.
The Brevo breach follows a separate incident involving shipping partner ShipMonk, which exposed names, phone numbers, email addresses, and postal addresses of at least 81,000 people who bought and received Trezor hardware. TechCrunch notes that such data can increase risks for crypto owners, including targeted physical attacks intended to extract passwords.

Fake HBO Max ads on Reddit pushed a ClickFix lure that could install info-stealing malware.

A reported AI-agent campaign hit RubyGems with malicious packages, public-data scraping, and attempted API key theft.

Anthropic says Claude was used in cyber, weapons, surveillance and model-distillation cases.
Nvidia’s CEO sees cybersecurity as AI’s next major business use case.