Trezor Brevo breach blog cover — fake 'Critical Security Alert: STM32 Entropy Bug' phishing email that passed SPF, DKIM, and DMARC

Trezor: 347,000 Users Phished After Attackers Breached Its Email Provider.

Carlos Finos

On September 9th, attackers compromised Brevo (the email platform behind Trezor's newsletter) and sent a fake security alert to roughly 347,000 subscribers. Trezor wasn't the only one hit: BitBox and CoinTracking got caught in the same net. The email looked legitimate to subscribers. It came from the official help@trezor.io address, with headers referring to mailing.trezor.io, and it passed standard SPF, DKIM,

Opsek graphic on a YubiKey 5C reading "A synced passkey no longer qualifies," announcing OpenAI's physical security key requirement for Trusted Access for Cyber accounts and how to enroll in

OpenAI now requires security keys for TAC members: how to enroll in Advanced Account Security

Carlos Finos

If you are part of OpenAI's Trusted Access for Cyber (TAC) program, there is a new requirement to act on. From September 1, 2026, individual TAC members must turn on Advanced Account Security (AAS) and sign in with a physical security key. A passkey synced through a password manager will not qualify. This guide covers what TAC is, what AAS changes on your account, which login option to

Signal Secure Backups: how to set them up and where to store the recovery key

Signal Secure Backups: how to set them up and where to store the recovery key

Carlos Finos

Signal used to have one hard rule: your messages lived on your device and nowhere else. Lose the phone, lose the history. That changed. Signal Secure Backups are now live on Android and iOS. They are end-to-end encrypted, opt-in, and Signal cannot read them. If your Signal threads touch treasury approvals, deployment coordination or incident response, this is worth ten minutes of your attention. Setup takes five.

Operational security finally has a standard, and we're accredited to certify it

Operational security finally has a standard, and we're accredited to certify it

Opsek

Ask where the biggest crypto losses actually come from, and it's rarely a flaw in the smart contract code. It's usually a hijacked domain, a compromised signer, a treasury transaction that looked routine, a support account that got phished, a deploy key sitting in the wrong place. The biggest hacks of the past few years went around the contract instead of breaking it. Operational failures are

Opsek’s Pablo Sabbatella Joins the DSS 2026 Review Committee

Opsek’s Pablo Sabbatella Joins the DSS 2026 Review Committee

Opsek

Behind every great security conference is a group of people reading through hundreds of submissions, looking for the talks that will teach the audience something real. At the DeFi Security Summit, that work runs through the Review Committee, which reads every talk and workshop proposal and helps the strongest, most useful research find its way to the stage. It's quiet, detailed work, and it's a big

Would you pass this test? Play our social engineering game

Would you pass this test? Play our social engineering game

Louis Marquenet

You think you're smart enough to spot any scam? Good. We built something to check. 99% of stolen funds in Web3 today are not smart contract hacks anymore, they're Operational Security issues: social engineering, fake job interviews, malicious Zoom calls. Most Web3 hacks don't start onchain, they start on someone's laptop. The Bybit hack ($1.4bn) started with a developer getting social

YubiKey: "Security Key" vs "Passkey", what actually changes in your login flow

YubiKey: "Security Key" vs "Passkey", what actually changes in your login flow

Louis Marquenet

When you set up a YubiKey, you get two main options: register it as a security key, or save a passkey on it. Both are phishing-resistant, both use the same crypto under the hood. So what's the actual difference, and which one should you use? This article breaks down what each mode is, what it does inside your authentication flow, and which setup is the strongest. If


Stay in the loop

Subscribe to get the latest updates, straight to your inbox.