Cybersecurity

Fake Malwarebytes ZIPs, Signed VS Code Stealers, and PDF Backdoors: How Trust, Not Zero-Days, Is Breaching Enterprises

Fake Malwarebytes ZIPs, Signed VS Code Stealers, and PDF Backdoors: How Trust, Not Zero-Days, Is Breaching Enterprises

TL;DR * Malwarebytes Campaign Tricks Users into Downloading Fake Software via DLL Sideloading, Stealing Crypto and Credentials * Cybercriminals Exploit Visual Studio Code Marketplace with Evelyn Stealer Extension to Steal Source Code and Cloud Tokens * Microsoft Enforces Intune Security Policies, Blocking Business Email Access for Non-Compliant Apps Since Jan 19,
Barista @ Cafecito
Verizon’s $20 Credit After 10-Hour 911 Outage & Google’s Silent Earbud Hack: When Convenience Kills Security

Verizon’s $20 Credit After 10-Hour 911 Outage & Google’s Silent Earbud Hack: When Convenience Kills Security

Verizon’s network crashed for 10 hours — 911 services degraded, $600M lost, and their ‘solution’? A $20 credit. Meanwhile, Google’s Fast Pair bug lets hackers eavesdrop on your earbuds… silently. No password. No alert. Just betrayal. Are your devices safe? #Cybersecurity #VerizonOutage #GoogleFastPair #BluetoothHack #Privacy #SecurityFail Verizon’s $20
Barista @ Cafecito
China-linked APT UAT-8837 Exploits Zero-Day to Hijack Critical Infrastructure; Iran Spoofs GPS to Sabotage Starlink; ICE Leak Exposes Surveillance Machine; AI Code Agents Generate 69 Flaws; Copilot Leaks Chat History via One-Click URL

China-linked APT UAT-8837 Exploits Zero-Day to Hijack Critical Infrastructure; Iran Spoofs GPS to Sabotage Starlink; ICE Leak Exposes Surveillance Machine; AI Code Agents Generate 69 Flaws; Copilot Leaks Chat History via One-Click URL

TL;DR * UAT-8837 APT actor exploits CVE-2025-53690 zero-day to compromise North American critical infrastructure via credential harvesting and Earthworm malware * Iranian state actors jam Starlink terminals using GPS spoofing, disrupting satellite connectivity for 24 minutes per session and degrading bandwidth to 10% in targeted regions * ICE
Barista @ Cafecito
Global-e Breach Exposes Crypto Wallets via API Flaw; Microsoft Offers Copilot Uninstall Tool; UK Criminalizes AI Deepfakes; Nigeria Mandates Crypto-ID Linkage

Global-e Breach Exposes Crypto Wallets via API Flaw; Microsoft Offers Copilot Uninstall Tool; UK Criminalizes AI Deepfakes; Nigeria Mandates Crypto-ID Linkage

TL;DR * Global-e third-party breach compromises 50,000+ customer orders, exposing Ledger wallet data through compromised vendor system * Microsoft enables enterprise admins to uninstall Copilot via documented Group Policy on Windows 11 Insider Preview * UK moves to criminalize AI-generated sexual deepfakes and revokes X’s self-regulatory
Barista @ Cafecito