Odaily Planet Daily report: A login system vulnerability at the email platform Brevo allowed attackers to access 138 customer accounts and send phishing emails to approximately 347,000 Trezor newsletter subscribers. Accounts from BitBox and the cryptocurrency portfolio and tax reporting platform CoinTracking were also used to send similar fraudulent emails.
Trezor stated that the phishing email had the subject line “Critical Security Alert: STM32 Entropy Vulnerability,” with a link directing users to an application requesting their wallet backup. Trezor disabled the associated domain via DNS within 20 minutes, but approximately 2,500 people had visited the link; the risk has been communicated to all 347,000 subscribers.
Brevo stated that attackers exploited a misconfiguration in the single sign-on permission boundaries to access all organizations reachable by invited users; six accounts were used to send phishing emails, and contact data from 43 accounts was exfiltrated. BitBox and CoinTracking reported no evidence of compromised company credentials, funds, or recovery phrases, but have treated the associated email addresses as potentially accessed. (Cointelegraph)
