AI Weekly Malaysia

Summaries

Short AI and tech summaries with source links, signal scores, and why each update matters for builders, founders, and Malaysian tech workers.

Reset

Showing 1-5 of 5 results

DateProviderScoreSummary
11 Aug 2026, 9:24 PMThe Register5.5 Cyberattack on logistics giant CEVA delivers customer data into the wrong hands

A cyberattack on CEVA Logistics between July 29 and August 1 disrupted eight European warehouses and exposed customer data from major clients including Valve, Bol, ING, and Ajax. Valve confirmed attackers likely stole names, addresses, phone numbers, emails, and order details for Steam hardware customers, though no payment info or passwords were exposed since CEVA doesn't hold them. Bol halted data exchanges with CEVA and took affected fulfillment center products offline, with some orders canceled or delayed.

Why: If you ship physical products through a third-party logistics provider, this is your template for what goes wrong: your fulfillment partner holds customer PII you can't fully control, and a breach there becomes your customer communication problem. The practical move is to audit what data your logistics/fulfillment vendors actually retain and for how long — Valve noted CEVA keeps it for 90 days — and push contractually for shorter retention and minimal data fields. Also worth reviewing whether your vendor risk process covers the phishing fallout scenario Valve described, where attackers quote real order details back to customers.

10 Aug 2026, 10:20 PMTechCrunch5.5 A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond

Ceva Logistics, a France-headquartered shipping giant with $18.3B revenue and over 1,000 warehouses, was hacked starting July 29, affecting at least 8 European warehouses and causing shipping delays. Customer personal data (names, addresses, phone numbers, emails) was stolen for clients including Bol, De Bijenkorf, Ajax, ING, Ace & Tate, and Valve/Steam, with Valve notifying customers on August 7.

Why: If you ship physical goods through third-party logistics providers, this is a concrete reminder that your customer PII lives in systems you don't control — and that a breach at your warehouse partner becomes your breach notification problem. Review what customer data your fulfillment or shipping vendors can access and whether you're contractually obligated to notify customers when that vendor is compromised, as Bol and Valve had to do here.

11 Aug 2026, 12:15 AMThe Register4.0 LexisNexis pulls three services offline after suspicious server activity

LexisNexis took Diligence, Metabase API, and Newsdesk offline after detecting unusual activity on third-party vendor-managed servers. Diligence returned over the weekend with partial content; Newsdesk and Metabase API were expected back progressively on Monday. LexisNexis explicitly stated the outage is NOT connected to the CVSS 10.0 SQL injection flaw disclosed by Metabase (the BI platform) on August 6, which has already been linked to a confirmed breach at laptop maker Framework.

Why: If you run Metabase BI in your stack, the CVSS 10.0 SQL injection zero-day disclosed August 6 is the actionable item here, not the LexisNexis outage. Patch or check your Metabase instance immediately. The LexisNexis story itself is a reminder that third-party vendor dependencies can take your service offline for days with no clear timeline.

14 Aug 2026, 6:29 PMThe Register3.5 Crypto wallet maker Trezor confirms 13,000 customers' details exposed in logistics breach

Trezor confirmed that a breach at its logistics partner ShipMonk exposed personal data of over 13,000 customers who ordered hardware wallets between May 10 and August 8, including names, email addresses, phone numbers, and shipping addresses across the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. ShipMonk was subject to Trezor's 90-day data retention policy, but earlier orders may also be affected, and Trezor warned affected customers to expect increased phishing attempts.

Why: If your SaaS or startup uses third-party logistics or fulfillment partners that handle customer PII, this is a concrete reminder that your vendor retention policies are only as good as your vendor's enforcement. The breach specifically shows that even a 90-day retention clause did not prevent earlier-order data from being exposed, meaning founders shipping physical products should audit whether partners actually delete or anonymize data on schedule rather than assuming contractual terms are followed.

14 Aug 2026, 4:46 PMThe Register3.5 Scottish prosecutors cast eye over leaky supplier after staff data exposed

Scotland's prosecution service warned 300 staff that names, roles, and work emails may have been exposed through a supplier breach detected on August 5, tied to an online data maturity assessment. The supplier is unnamed and the intrusion method is unclear, though The Register notes it may be connected to a recently disclosed Metabase cloud zero-day that allowed admin access to connected databases—Framework was also affected.

Why: If you run Metabase Cloud, check whether you were exposed to the zero-day disclosed this month and review what connected databases an admin-level attacker could have reached. The Scottish incident itself is a reminder that data collected for seemingly low-stakes assessments (surveys, maturity exercises) still becomes a breach surface when stored by third parties.

Top