CVE-2026-65058PoC

MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

4.0/ 10 priority

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-08-06); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-06: 1Mentions · 2026-08-08: 1Mentions · 2026-08-19: 1PoC Mentioned / Linked · 2026-08-06: 1PoC Mentioned / Linked · 2026-08-08: 1Exploit Tool / Code · 2026-08-06: 1Exploit Tool / Code · 2026-08-08: 1Patch / Workaround · 2026-08-19: 1Technical Details · 2026-08-06: 1Technical Details · 2026-08-19: 108-0608-0808-19
Signal classification3 categories
PoC
133.3%
General
133.3%
Patch
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-08-061
PoC1
2026-08-081
General1
2026-08-191
Patch1
Full discourse3 posts
  • Mishaboar@mishaboar
    General

    Two more repos we have flagged from the same "dev". Stay away! One targeting @Trezor users and improvised researchers, another with a generic "wallet recovery tool". On @Github (reported yesterday): - iktok90-design/trezor-cve-2026-65058 - iktok90-design/wallet-recovery-tool

    Post summary

    The post alerts users to two flagged GitHub repositories related to CVE‑2026‑65058, implying availability of proof‑of‑concept code but providing no further details on exploitation, patches, or technical specifics.

    5701903.0K
    88.8K followersView on X
  • ThreatWire@ThreatWire_
    PoC

    🚨 CRITICAL: A public PoC is available for CVE-2026-65058, a Trezor Safe vulnerability affecting firmware < 2.8.7. The flaw creates a display/signing mismatch: Trezor shows only the first 256 bytes of calldata but signs the full transaction payload, allowing hidden data during confirmation. PoC: https://github.com/iktok90-design/trezor-cve-2026-65058 #CyberSecurity #CryptoSecurity #Trezor #Web3 #CVE #Infosec #crypto

    Post summary

    The tweet highlights a publicly available PoC for CVE-2026-65058, a Trezor firmware flaw that mismatches display and signing, and supplies a GitHub link to the exploit code. No evidence of active exploitation or patching is mentioned.

    040711.1K
    1.5K followersView on X
  • Josh@JoshDoesDefi
    Patch

    Security warning: CVE-2026-65058 affected Trezor Safe 3, 5 and 7 transaction signing. Update to firmware 70c9b0c or later, and verify every transaction on-device. https://t.co/B7xOFor58Z

    Post summary

    The warning highlights CVE-2026-65058 as affecting transaction signing on Trezor Safe devices and recommends updating firmware to 70c9b0c or later along with on-device transaction verification.

    01010118
    639 followersView on X

Explore more