News

Global-e Breach Exposes Crypto Wallets via API Flaw; Microsoft Offers Copilot Uninstall Tool; UK Criminalizes AI Deepfakes; Nigeria Mandates Crypto-ID Linkage

Global-e Breach Exposes Crypto Wallets via API Flaw; Microsoft Offers Copilot Uninstall Tool; UK Criminalizes AI Deepfakes; Nigeria Mandates Crypto-ID Linkage

TL;DR * Global-e third-party breach compromises 50,000+ customer orders, exposing Ledger wallet data through compromised vendor system * Microsoft enables enterprise admins to uninstall Copilot via documented Group Policy on Windows 11 Insider Preview * UK moves to criminalize AI-generated sexual deepfakes and revokes X’s self-regulatory status amid growing public
Barista @ Cafecito
Alphabet Surpasses Apple in Market Cap as Google Cloud and Gemini AI Drive $4.1T Valuation; Estée Lauder Upgraded on Asia Growth; Torq Ltd. Raises $140M in Series C

Alphabet Surpasses Apple in Market Cap as Google Cloud and Gemini AI Drive $4.1T Valuation; Estée Lauder Upgraded on Asia Growth; Torq Ltd. Raises $140M in Series C

TL;DR * Alphabet’s market cap surpasses $3.97 trillion as Google Cloud grows 33–34% YoY and Gemini AI drives re-rating amid rising AI infrastructure demand * Torq Ltd. raises $140M in Series C funding at $1.2B valuation, expanding AI-driven security hyperautomation platform with enterprise clients including PepsiCo and
Barista @ Cafecito
Instagram Data Breach Exposes 17.5M Users, Grok AI Blocked in Malaysia and Indonesia, WEX API Keys Sold on Dark Web

Instagram Data Breach Exposes 17.5M Users, Grok AI Blocked in Malaysia and Indonesia, WEX API Keys Sold on Dark Web

TL;DR * Malwarebytes reports 17.5 million Instagram accounts compromised via 2024 API leak, exposing usernames, physical addresses, and phone numbers; users advised to enable 2FA * CVE-2026-01-11: Unauthenticated remote code execution vulnerability discovered in OpenCode AI coding assistant server (port 4096), enabled by default prior to v1.1.10 * Grok
Barista @ Cafecito
OpenAI, Trend Micro, HPE, and Microsoft Patch Critical Zero-Click and RCE Vulnerabilities Amid Surge in Telecom and Cloud Exploits

OpenAI, Trend Micro, HPE, and Microsoft Patch Critical Zero-Click and RCE Vulnerabilities Amid Surge in Telecom and Cloud Exploits

TL;DR * OpenAI patches ZombieAgent and ShadowLeak vulnerabilities in ChatGPT connectors, enabling zero-click exfiltration of Gmail, GitHub, and Outlook data via memory and file upload exploits * Trend Micro releases Critical Patch Build 7190 to remediate CVE-2025-69258 allowing unauthenticated remote code execution in Apex Central via DLL injection into MsgReceiver.exe
Barista @ Cafecito