Trezor released a security update a few days ago for both Trezor One and Trezor T. According to
this article, 3 vulnerabilities submitted via the responsible disclosure have been fixed in that update.
Does Trezor offer a way to check their devices to make sure they are genuine?
Beside holograms on the packaging, Trezor should check the integrity of the bootloader which is responsible for checking the firmware.
Here you can find more information. It's a bit different for each model.