Trezor's email provider was breached, and attackers sent fake emails from real Trezor email addresses. The fake email is titled "Critical Security Alert: STM32 Entropy Vulnerability" and claims a hardware defect in Trezor devices. Remember that wallet vendors will never ask