Build with CoinStats’ all-in-one API. Learn more

EnglishDeutsch日本語中文EspañolFrançaisՀայերենNederlandsРусскийItalianoPortuguêsTürkçe포트폴리오 추적기암호화폐가격Crypto API통합뉴스RWA 시장획득블로그NFT위젯DeFi 포트폴리오 추적기파생상품ETF Flows크립토 게이밍24시간 보고서홍보 자료API 문서

Brevo login flaw enabled phishing email targeting 347K Trezor subscribers

5일 전
상승세:

0

하락세:

0

Brevo login flaw enabled phishing email targeting 347K Trezor subscribers

Trezor told Cointelegraph that the phishing email was sent to 347,000 subscribers and said it is treating every address as “known to the attacker and possibly reusable for phishing.”

An attacker exploited a flaw in email platform Brevo’s login system to access 138 client accounts, enabling a phishing email to reach roughly 347,000 Trezor newsletter subscribers and similar fraudulent messages to be distributed through accounts belonging to hardware wallet maker BitBox and crypto portfolio tracking and tax-reporting platform CoinTracking.

In a Thursday postmortem, Brevo said six accounts were used to send phishing emails, contacts were exported from 43 and 93 accounts showed no meaningful activity. The platform did not specify whether the categories overlapped. 

The attacker created a Brevo account, enabled single sign-on and invited legitimate Brevo users into the configuration. Brevo said access should have been confined to that organization, but an authorization boundary failed and granted access to every organization the invited users could reach.

Read more

5일 전
상승세:

0

하락세:

0

한 곳에서 모든 암호화폐, NFT 및 DeFi 를 관리하세요

시작하는 데 사용하는 포트폴리오를 안전하게 연결하세요.