The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Computer Hardware
Breach intelligence, attack campaigns, and threat reports targeting the Computer Hardware sector.
Explore Other Sectors
Computer Hardware Threat Reports
Trezor Supply Chain Attack: When Legitimate Email Infrastructure Becomes a Weapon
In September 2026, cryptocurrency hardware wallet maker Trezor warned customers that threat actors had breached its third-party email provider and were conducting sophisticated phishing attacks. The attackers sent fake "critical security alert" emails from help@trezor.io, claiming a hardware microcontroller vulnerability in STM32 chips could expose wallet seeds to brute-force attacks. This incident followed a previous breach of Trezor's shipping provider ShipMonk in August 2026, which compromised data from 81,000 customers across multiple countries. The ShipMonk breach exploited a critical SQL injection zero-day vulnerability in the Metabase analytics platform, with the ShinyHunters extortion gang subsequently targeting the company. This incident highlights the growing trend of supply chain attacks targeting cryptocurrency platforms and the increasing sophistication of phishing campaigns that leverage compromised legitimate infrastructure to bypass security controls and user awareness training.
1 week ago
Kill Chain
ShineyHunters Exploit Zero-Day to Breach Trezor's Shipping Partner
In August 2026, hardware wallet manufacturer Trezor disclosed that 67,000 U.S. customers had their personal data exposed through a breach at shipping provider ShipMonk. The ShineyHunters extortion gang exploited CVE-2026-72898, a critical SQL injection vulnerability in Metabase with a CVSS score of 10.0, to gain unauthorized access to ShipMonk's systems. The exposed data included customer names, email addresses, phone numbers, shipping addresses, and order numbers from November 2019 to August 2021, despite Trezor's repeated requests for data deletion per their 90-day retention policy. This supply chain attack highlights how third-party vulnerabilities can impact customer data even when primary security measures are robust. This incident demonstrates the growing threat of supply chain compromises targeting logistics and fulfillment providers, with attackers increasingly exploiting zero-day vulnerabilities in business intelligence platforms to access customer databases across multiple organizations simultaneously.
2 weeks ago
Kill Chain
GPUThor Rowhammer Attack Bypasses NVIDIA GPU Security in 2026 Breakthrough
In August 2026, University of Toronto researchers disclosed GPUThor, a sophisticated Rowhammer attack targeting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC). The attack impacts RTX A6000, A5000, A4500, and A4000 models, enabling attackers to achieve denial-of-service conditions and privilege escalation to root access on host systems. GPUThor uses non-uniform hammering techniques to generate up to 377,000 bit flips per gigabyte, vastly exceeding previous GPU Rowhammer attacks and successfully bypassing NVIDIA's recommended ECC mitigation through multi-bit corruption exploitation. This hardware vulnerability represents a significant evolution in GPU-based attacks as organizations increasingly rely on shared GPU infrastructure for AI workloads and cloud computing. The attack highlights critical security gaps in hardware-level protections and the growing attack surface presented by specialized computing hardware in enterprise environments.
4 weeks ago
Kill Chain
GPUThor Rowhammer Attack Defeats NVIDIA ECC Protection in AI Infrastructure
University of Toronto researchers disclosed GPUThor, a sophisticated Rowhammer attack that bypasses NVIDIA's Error-Correcting Code (ECC) protections on Ampere-class workstation GPUs including RTX A4000, A4500, A5000, and A6000 models. The attack exploits undocumented GPU behaviors to avoid Target Row Refresh mitigations, achieving bit-flip rates up to 377,000 flips per GB and enabling denial-of-service conditions and root-level privilege escalation within 1.1 minutes. GPUThor demonstrates 4,548 to 23,597 times higher effectiveness than previous GPU Rowhammer attacks, posing significant risks to AI infrastructure and cloud environments relying on these widely deployed GPU models for machine learning workloads. This vulnerability highlights the growing sophistication of hardware-level attacks targeting AI infrastructure as organizations increasingly depend on GPU-accelerated computing for critical business operations and model training.
4 weeks ago
Kill Chain
Unisoc Modem Vulnerability: Millions of Android Devices at Risk
In August 2026, researchers at SSD Secure Disclosure identified a critical security vulnerability in Unisoc's T612 modem firmware. By chaining a previously disclosed remote code execution (RCE) flaw with a newly discovered memory isolation weakness, attackers can gain privileged access to the Android kernel on affected devices. The exploit involves delivering a malicious payload to the modem and then initiating a video call, which the victim must answer to trigger the attack. This vulnerability impacts devices from manufacturers such as Realme, Xiaomi, and Motorola, leaving millions of users at risk. The significance of this discovery lies in the increasing prevalence of sophisticated attack chains targeting mobile devices. As threat actors continue to exploit firmware-level vulnerabilities, it underscores the necessity for robust security measures and timely firmware updates to protect user data and device integrity.
1 month ago
Kill Chain
Trezor Data Breach 2026: Lessons in Supply Chain Security
In August 2026, Trezor, a leading cryptocurrency hardware wallet manufacturer, disclosed a data breach affecting nearly 14,000 customers. The breach occurred through their shipping and logistics provider, ShipMonk, whose systems were compromised via a vulnerability in the third-party analytics platform Metabase. This incident exposed customers' full names, shipping addresses, email addresses, and phone numbers. Trezor's internal systems and devices remained secure, but the exposed personal information heightened the risk of targeted phishing attacks against affected individuals. This breach underscores the critical importance of securing third-party service providers, as vulnerabilities in external platforms can directly impact primary organizations and their customers. The incident also highlights the evolving tactics of cybercriminals, who exploit supply chain weaknesses to access sensitive data, emphasizing the need for comprehensive security measures across all operational facets.
1 month ago
Kill Chain
State-Sponsored Cyber Attacks on AI Supply Chain in 2026
In 2026, the global race to dominate artificial intelligence (AI) has intensified, with nations vying for control over critical minerals, semiconductor production, and AI model development. This competition has led to increased state-sponsored cyber operations targeting every link in the AI supply chain, from mining companies to data centers and AI research institutions. Notably, Chinese state-sponsored hackers have been implicated in sophisticated cyber espionage campaigns aimed at extracting sensitive information and disrupting competitors' advancements in AI technologies. The urgency of securing the AI development chain has never been more critical. As AI becomes deeply integrated into various sectors, the potential for cyber threats to disrupt economies and national security has escalated. Organizations must adopt comprehensive cybersecurity strategies to protect against these evolving threats, ensuring the resilience of their AI infrastructures.
1 month ago
Kill Chain
New Interrupt Injection Attack Bypasses Spectre v2 Defenses on Intel and AMD CPUs
In August 2026, researchers from MIT's Computer Science and Artificial Intelligence Laboratory (CSAIL) disclosed a novel attack technique named 'Interrupt Injection.' This method exploits a timing vulnerability in Intel and AMD CPUs, allowing unprivileged Linux programs to inject hardware interrupts precisely between the processor's branch predictor sanitization and its subsequent use by the kernel. This re-poisoning of the branch predictor can lead to speculative execution vulnerabilities, enabling attackers to leak arbitrary kernel memory. Demonstrations on AMD Zen 2 processors running Linux 6.14 with default Spectre v2 mitigations showed data leakage rates of 5.47 bytes per second with 91.97% accuracy, sufficient to extract sensitive files like /etc/shadow in multiple attempts. The attack requires only local code execution without elevated privileges, posing significant risks to shared systems utilizing affected processors. This incident underscores the persistent challenges in securing speculative execution mechanisms within modern CPUs. Despite existing mitigations for Spectre v2 vulnerabilities, the discovery of Interrupt Injection highlights the need for continuous vigilance and adaptation in hardware and software defenses. Organizations must stay informed about emerging threats and ensure timely application of patches to protect sensitive data from sophisticated side-channel attacks.
1 month ago
Kill Chain
COLDCARD Wallet RNG Flaw Results in Massive Bitcoin Theft
In late July 2026, a critical vulnerability in COLDCARD hardware wallets was exploited, leading to the theft of approximately $88.6 million in Bitcoin from thousands of users. The flaw, identified in the wallet's random number generator (RNG), resulted in predictable seed phrases, allowing attackers to reconstruct private keys and access funds. The attack unfolded in multiple waves, with the first occurring on July 30, 2026, draining over 1,083 BTC from 1,196 addresses within 41 minutes. Subsequent waves increased the total to 1,367 BTC stolen from 4,585 addresses. The attackers prioritized high-value wallets, with one victim losing $1.8 million. This incident underscores the critical importance of secure RNG implementations in cryptocurrency hardware wallets. The exploitation of deterministic RNGs highlights a significant vulnerability, emphasizing the need for rigorous security audits and prompt firmware updates to protect digital assets.
1 month ago
Kill Chain
Decade-Long Vulnerability in Microsoft Secure Boot Uncovered
In July 2026, researchers discovered a critical vulnerability in Microsoft's Secure Boot, a feature designed to protect devices from firmware infections. This flaw, present for 13 of Secure Boot's 14-year existence, allowed attackers to bypass protections using outdated, signed firmware images known as shims. These shims, some dating back to 2013, remained signed by Microsoft despite known defects, enabling unauthorized code execution during system boot and facilitating persistent malware infections. This incident underscores the importance of rigorous certificate management and timely revocation processes. The prolonged exposure highlights potential oversight in Microsoft's security protocols, emphasizing the need for continuous monitoring and updating of security measures to prevent similar vulnerabilities. ([pcgamer.com](https://www.pcgamer.com/software/operating-systems/turns-out-microsofts-secure-boot-was-little-better-than-a-busted-lock-for-about-a-decade/?utm_source=openai))
1 month ago
Kill Chain
Outdated UEFI Bootloaders Pose Security Risks
In July 2026, researchers identified 11 outdated UEFI shim bootloaders, all signed by Microsoft, that remained trusted components within the Secure Boot framework. These bootloaders, versions 0.9 and earlier, lacked modern security protections and could be exploited by attackers to bypass Secure Boot, allowing the execution of malicious code during the boot process and establishing persistent access below the operating system level. Microsoft addressed the issue by revoking these vulnerable bootloaders in June 2026 through Secure Boot revocation updates. However, systems that have not applied these updates remain susceptible to boot-level attacks, as the revoked shims continue to be trusted on unpatched machines. This incident underscores the critical importance of timely firmware updates and the need for organizations to maintain vigilance over the security of their boot processes to prevent potential exploits.
2 months ago
Kill Chain
LabubaRAT: A New Rust-Based RAT Disguised as NVIDIA Software
In July 2026, cybersecurity researchers identified LabubaRAT, a previously undocumented Rust-based remote access trojan (RAT) that masquerades as NVIDIA software to infiltrate Windows systems. The malware establishes a persistent foothold, enabling attackers to profile the host, identify security tools, execute commands, transfer files, capture screenshots, and proxy traffic through the compromised system. LabubaRAT employs multiple communication methods, including HTTPS, WebView2, and DNS tunneling, to maintain access even if one pathway is detected and blocked. The attack initiates with an executable named "nvidia-sysruntime.exe," which impersonates NVIDIA's container runtime toolkit. Instead of hard-coding its command-and-control (C2) information, the malware accepts runtime configurations via command-line arguments, allowing operators to define parameters such as server details and polling intervals. This flexibility enables the reuse of the same binary across different infrastructures and campaigns without modification. Once deployed, LabubaRAT conducts discovery operations to inventory installed web browsers and security products, gathering information on the host's environment to tailor its functionality accordingly. The malware's capabilities include command execution, PowerShell and JavaScript execution, screenshot capture, file upload and download, archive handling, and SOCKS5 proxy support. These features provide attackers with comprehensive control over the infected host, facilitating data exfiltration and further malicious activities. The emergence of LabubaRAT underscores the evolving sophistication of malware designed to evade detection by masquerading as legitimate software. Its use of Rust, a language known for its performance and safety features, highlights a trend among threat actors to adopt modern programming languages to develop more robust and stealthy malware. Organizations must remain vigilant and implement robust security measures to detect and mitigate such threats.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports