Millions Impacted Across Tech, E-Commerce, & Data Privacy

Millions Impacted Across Tech, E-Commerce, & Data Privacy

From zero-day exploits to supply chain breaches and zero-click mobile vulnerabilities, the security landscape is shifting rapidly. Here is a breakdown of the critical threats, privacy developments, and breaches you need to know about right now:

1. Consumer Data Breaches & Supply Chain Exposure

Trezor Logistics Breach:
Crypto hardware maker Trezor confirmed a third-party breach via logistics partner ShipMonk, exposing contact and shipping details for 81,000+ customers. While funds and keys remain secure, users are at elevated risk for SIM-swapping, targeted phishing, and physical security threats.

Aviation Privacy Leak:
Researchers uncovered an exposed database linked to Vietnam’s Advance Passenger Information System (APIS), leaking 220M records including passport numbers, full names, and complete flight itineraries.

EdTech Vulnerabilities: Mathspace confirmed an internal data breach affecting over 1 million students, parents, and teachers following unauthorized access to its reporting environment.

2. Mobile & Application Security

WeChat Zero-Click Flaw:
Security researchers detailed a critical zero-click vulnerability in WeChat allowing device compromise through incoming calls—requiring no interaction or answer from the victim. Tencent has deployed backend patches.

Grindr Privacy Settlement:
Grindr agreed to a £26M ($35M) settlement in the UK over allegations of unauthorized sharing of sensitive user data (including HIV status) with third-party advertising partners without clear consent.

3. E-Commerce & Retail Zero-Days

Adobe Commerce / Magento ("StyleSmuggler"):
Attackers are actively exploiting a critical zero-day dubbed StyleSmuggler across Adobe Commerce and Magento stores. By abusing GraphQL and template engines, threat actors are planting backdoors to intercept credit card details directly at checkout.

4. Identity Theft & MFA Attacks

153M+ Driver’s Licenses Traded:
Scraped and stolen digital scans of driver's licenses across the U.S. and Canada harvested from third-party identity verification vendors are currently being traded on dark web forums.

Bypassing 2FA via "BigBear 2.0":

A new adversary-in-the-middle (AiTM) phishing platform has compromised thousands of Microsoft 365 accounts by intercepting live multi-factor authentication (MFA) tokens in real time.

Key Takeaway for CISOs & Security Teams:
Perimeter security is no longer enough. Supply chain vendors, vendor data retention policies, and real-time MFA bypasses continue to be primary attack vectors.

Review your third-party risks, apply emergency patches immediately, and train teams on AiTM phishing awareness.

#Cybersecurity #DataPrivacy #InfoSec #ThreatIntelligence #InfosecNews #SupplyChainRisk #ZeroDay #TechNews

What's Your Reaction?

like

dislike

love

funny

angry

sad

wow