pull down to refresh

Threat actors may have compromised the email provider(s) used by Trezor and BitBox; malicious emails claiming both have bad RNGs that require security updates are being sent and the emails don't appear to be spoofed. No such security advisory has been issued!


Trezor posted here, about attackers breached Trezor’s third-party email provider. and them attackers distributed a message titled “Critical Security Alert: STM32 Entropy Vulnerability.”Here


BitBox posted here, about BitBox users received a closely related “Microcontroller Entropy Vulnerability” message.

Another one this morning: My email inbox this morning:

reply
12 sats \ 0 replies \ @justin_shocknet 10 Sep -21 sats

Another one for the jar

#1566417