<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Breach &amp; Data Theft on Jorge Laurel</title><link>https://jorgelaurel.com/topics/breach--data-theft/</link><description>Recent content in Breach &amp; Data Theft on Jorge Laurel</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 27 Mar 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://jorgelaurel.com/topics/breach--data-theft/index.xml" rel="self" type="application/rss+xml"/><item><title>Friday Wrap Up: 27 March 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-118/</link><pubDate>Fri, 27 Mar 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-118/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;This week: a pro-Iranian group hacked the FBI Director&amp;rsquo;s personal email. North Korean hackers got hired for remote IT jobs. TeamPCP backdoored yet another PyPI package. And an iPhone exploit kit has evolved directly from the zero-click campaign that hit Russian targets back in 2023.&lt;br&gt;
&lt;br&gt;
In the &amp;ldquo;things we didn&amp;rsquo;t need&amp;rdquo; column: GlassWorm now uses the Solana blockchain to route its malware payloads, a new infostealer bypasses Chrome&amp;rsquo;s Application-Bound Encryption, and a QR code phishing campaign somehow slipped past SPF, DKIM, AND DMARC at scale — 1.6 million emails delivered, no alarm raised.&lt;br&gt;
&lt;br&gt;
It&amp;rsquo;s a lot. Click through for 34 stories across 6 categories, and maybe patch your NetScaler while you&amp;rsquo;re at it.&lt;br&gt;
&lt;br&gt;
#FWU #fridaywrapup #SupplyChainSecurity #NationStateHackers #PatchNow #Malware #DataBreach #Ransomware&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 13 March 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-116/</link><pubDate>Fri, 13 Mar 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-116/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Happy Friday the 13th! 🔪 In the spirit of the day, threat actors did NOT hold back this week.&lt;/p&gt;
&lt;p&gt;We’ve got Chrome extensions that turned evil after changing hands, an AI agent that decided to mine crypto on its own (nobody asked, buddy 🤖⛏️), a medtech giant hit by Iranian hackers claiming to have wiped 200,000 devices, and a 1 petabyte data theft claim that made storage admins everywhere break into a cold sweat.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 6 March 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-115/</link><pubDate>Fri, 06 Mar 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-115/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Happy Friday, security professionals! 🔐&lt;/p&gt;
&lt;p&gt;This week in cybersecurity served up everything from drone strikes on cloud data centers (yes, physical ones) to hackers tapping FBI wiretap systems, AI assistants getting hijacked, and your car’s tire sensors moonlighting as surveillance tools.&lt;/p&gt;
&lt;p&gt;Nation-state actors from China, North Korea, and Iran were all running active campaigns. Critical vulnerabilities hit Android, Cisco firewalls, and iOS — while global law enforcement struck back, dismantling Tycoon 2FA, seizing LeakBase, and arresting a $46M crypto thief in Saint Martin (the vacation vibes did not help).&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 27 February 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-114/</link><pubDate>Fri, 27 Feb 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-114/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another Friday, another reason to question whether your apps, APIs, and Zoom calls are working for you — or someone else. 🛡️&lt;/p&gt;
&lt;p&gt;This week’s Friday Wrap Up covers ransomware hitting chip makers and medical device companies, China-linked spies repurposing Google Sheets as a command center (productivity hack of the year, unfortunately), North Korea expanding into healthcare ransomware, and a fake Zoom meeting that installs surveillance software before you finish your first sip of coffee.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 20 February 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-113/</link><pubDate>Fri, 20 Feb 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-113/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another reminder that the internet is basically a haunted house and someone keeps adding new rooms. 🏚️&lt;/p&gt;
&lt;p&gt;This week’s Friday Wrap Up covers data breaches hitting your wallet and your wardrobe, Android malware clever enough to use Google’s own AI against you, Chrome zero-days being actively exploited, fake AI tools fooling a quarter million users, and OAuth phishing attacks that let hackers waltz through MFA like they own the place.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 13 February 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-112/</link><pubDate>Fri, 13 Feb 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-112/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another collection of reasons why your security team hasn’t slept properly since 2019. This week’s FWU brings you everything from ransomware gangs cosplaying as employee monitoring software to North Korean job applicants who are definitely not who they claim to be on LinkedIn (looking at you, “Senior DevOps Engineer”).&lt;/p&gt;
&lt;p&gt;We’ve got cloud infrastructure being turned into crime bots, Olympic ice dancers accidentally committing AI plagiarism, and the eternal question: “Is that zero-day actively exploited?” (Spoiler: yes, probably within 24 hours of the PoC dropping).&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 9 January 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-110/</link><pubDate>Fri, 09 Jan 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-110/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another wave of vulnerabilities keeping us on our toes!&lt;/p&gt;
&lt;p&gt;From nation-state hackers conducting global credential harvesting campaigns to fake AI Chrome extensions stealing nearly a million users’ data, this week proved cybersecurity professionals earn every bit of their coffee budget. Critical n8n vulnerabilities reached CVSS scores that made even hardened defenders nervous, while Chinese Salt Typhoon intrusions keep expanding in scope. Meanwhile, Disney learned that YouTube privacy violations cost $10M—turns out COPPA compliance isn’t optional.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 28 November 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-106/</link><pubDate>Fri, 28 Nov 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-106/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;This week’s cybersecurity landscape? Let’s just say the supply chain attacks are getting creative, the credential leaks are getting embarrassing, and emergency alert systems proved they’re not immune to ransomware.&lt;/p&gt;
&lt;p&gt;From worms named after sci-fi sandworms to threat groups with identity crises, we’ve got breaches affecting everything from real estate finance to your favorite analytics platforms.&lt;/p&gt;
&lt;p&gt;Oh, and reminder: those “helpful” code formatting websites? They’ve been collecting your credentials like Pokémon cards. Click through for the full roundup of this week’s digital chaos.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 21 November 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-105/</link><pubDate>Fri, 21 Nov 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-105/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another reminder that cybersecurity never sleeps—and neither do the threat actors! 😅&lt;/p&gt;
&lt;p&gt;From record-breaking DDoS attacks and zero-day exploits to nation-state espionage campaigns and AI-powered fraud, this week’s &lt;strong&gt;#FWU&lt;/strong&gt; covers the full spectrum of cyber chaos. We’re talking about breaches at major platforms, government policy debates, and even Cloudflare accidentally breaking the internet with a file that got too big (relatable, honestly).&lt;/p&gt;
&lt;p&gt;Whether you’re worried about your smart toaster joining a botnet or just want to stay informed on the latest threats, check out this week’s curated cybersecurity intel.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 24 October 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-101/</link><pubDate>Fri, 24 Oct 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-101/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another reminder that cybersecurity never takes a coffee break! ☕&lt;/p&gt;
&lt;p&gt;From botnet malware targeting your router to smart beds that won’t lie flat during cloud outages (yes, really), this week had everything. We’re talking billion-dollar breaches, quantum leaps, AI agents surfing the web, and Microsoft patches that caused more problems than they solved. Plus, ransomware victims learning the hard way that paying up doesn’t guarantee getting your data back.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 17 October 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-100/</link><pubDate>Fri, 17 Oct 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-100/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another wild week in cybersecurity! From nation-state actors breaching major tech companies to botnets going global, hackers weren’t taking any days off.&lt;/p&gt;
&lt;p&gt;We’ve got everything from AI guardrails getting schooled by basic prompt injection to a vulnerability so severe Microsoft had to break out their highest-ever severity score. Oh, and YouTube decided to take a little nap this week too.&lt;/p&gt;
&lt;p&gt;Cybersecurity stories covering everything from malware hiding in GitHub images to North Korean job scams that would make your HR department cry. Check out the full roundup to see what kept security teams caffeinated this week.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 10 October 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-099/</link><pubDate>Fri, 10 Oct 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-099/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another ransomware alliance, and somehow your mouse might be eavesdropping on you now. 🖱️👂&lt;/p&gt;
&lt;p&gt;From fake Discord alerts stealing vault credentials to North Korean hackers pocketing $2B in crypto, this week proves that cybercriminals are nothing if not creative (and disturbingly well-funded). Meanwhile, the FBI took down BreachForums and Google’s AI is learning to patch code before attackers can exploit it.&lt;/p&gt;
&lt;p&gt;The cybersecurity world never sleeps, and honestly, neither should your security team after reading this. Click through for the full rundown of breaches, malware, and the latest “why-is-that-even-possible” attack vectors.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 26 September 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-097/</link><pubDate>Fri, 26 Sep 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-097/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another batch of creative ways cybercriminals are keeping us security folks caffeinated! ☕&lt;/p&gt;
&lt;p&gt;From airports getting grounded by ransomware to AI agents accidentally becoming the world’s most helpful data thieves, this week’s threat landscape had more plot twists than a Netflix series. We saw record-breaking DDoS attacks that made previous “massive” attacks look like gentle nudges, supply chain compromises that spread faster than office gossip, and enough zero-days to make patch Tuesday feel like patch decade.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 19 September 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-096/</link><pubDate>Fri, 19 Sep 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-096/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another collection of cyber chaos! From luxury fashion brands getting their digital wardrobes raided to AI tools that apparently graduated from &amp;ldquo;Hacking 101&amp;rdquo; with honors, the threat landscape continues its creative evolution.&lt;/p&gt;
&lt;p&gt;This week&amp;rsquo;s highlights include some particularly audacious impersonation schemes (fake FBI portals, anyone?), memory attacks that work faster than your morning coffee kicks in, and evidence that retirement announcements from cybercriminals should be taken with the same grain of salt as your uncle&amp;rsquo;s fishing stories.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 05 September 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-094/</link><pubDate>Fri, 05 Sep 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-094/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;From record-breaking DDoS attacks and SVG-based phishing to zero-day exploits and AI-powered trade secret drama — this week’s threat landscape had something for everyone (except peace of mind).&lt;/p&gt;
&lt;p&gt;🔍 Russian APTs were intercepted mid-hack, North Korea’s ScarCruft went academic, and Google had to patch 120 Android flaws (yes, 120 — not a typo).&lt;/p&gt;
&lt;p&gt;🏭 Meanwhile, Bridgestone and Jaguar Land Rover hit the cyber brakes, Salesloft Drift’s supply-chain chaos keeps expanding, and a misconfigured server spilled 378GB of Navy Federal data like a coffee cup on a Monday keyboard.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 29 August 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-093/</link><pubDate>Fri, 29 Aug 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-093/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Salesforce attacks rippled into insurers and healthcare, AI-powered ransomware went live, Nevada shut down state offices, and hackers weaponized AI in the first supply chain breach.&lt;/p&gt;
&lt;p&gt;Meanwhile, $47M in scam crypto was seized, fake ID markets were dismantled, and Linux blew out 34 candles 🎂.&lt;/p&gt;
&lt;p&gt;🔍 From data theft to AI threats, the line between “attack” and “experiment” is vanishing fast.&lt;/p&gt;
&lt;p&gt;⚡ &lt;em&gt;Recaps + sources in this week’s Friday Wrap Up&lt;/em&gt; — because in cyber, “too long; didn’t read” can turn into “too late; data’s ripped.”&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 22 August 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-092/</link><pubDate>Fri, 22 Aug 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-092/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;🚨 Major Cyberattacks &amp;amp; Data Breaches&lt;/strong&gt; This week saw breaches across industries — from HR platforms to healthcare — showing how attackers continue to exploit trusted systems.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;👔 Workday discloses data breach linked to Salesforce attacks (Published on 8/18/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/hr-giant-workday-discloses-data-breach-amid-salesforce-attacks/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🍔 Hacker finds flaws in McDonald’s staff &amp;amp; partner hubs, exposing APIs and sensitive documents (Published on 8/20/2025, Dark Reading). &lt;a href="https://www.darkreading.com/cybersecurity-operations/hacker-finds-flaws-mcdonalds-staff-partner-hubs"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 25 July 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-088/</link><pubDate>Fri, 25 Jul 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-088/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;This week, it’s cyber whack-a-mole: one forum admin down, another mirror site up. Meanwhile, malware gets cuddly (hi, pandas 🐼), and brands like Microsoft remain prime phishing bait.&lt;/p&gt;
&lt;p&gt;A dash of espionage, a pinch of legal drama, and a travel scam twist—because hackers need vacations too.&lt;/p&gt;
&lt;p&gt;👇 Dive in for the full roundup before your inbox gets spoofed.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="major-cyberattacks--incidents"&gt;&lt;strong&gt;Major Cyberattacks &amp;amp; Incidents&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Breaches, takedowns, and court battles highlight the ever-evolving cyber threat landscape.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 11 July 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-086/</link><pubDate>Fri, 11 Jul 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-086/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another busy week in cybersecurity and tech.&lt;/p&gt;
&lt;p&gt;🛡️ Ransomware groups are shutting down while pivoting to data extortion, as millions of records continue leaking from major brands.&lt;/p&gt;
&lt;p&gt;🕸️ Malicious Chrome extensions, SEO poisoning attacks disguised as AI tools, and critical zero-days highlight persistent threats across the supply chain and user environments.&lt;/p&gt;
&lt;p&gt;🤖 As organizations rush to adopt agentic AI, understanding dark market dynamics, patching critical vulnerabilities, and ensuring cyber-insurance coverage remain vital for resilience.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 27 June 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-084/</link><pubDate>Fri, 27 Jun 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-084/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cyber-threats--state-linked-activity"&gt;🛡️ Cyber Threats &amp;amp; State-Linked Activity&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🕵️ Salt Typhoon hacks a Canadian telecom using Cisco flaws, confirming China-linked espionage. (Published on 6/23/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/canada-says-salt-typhoon-hacked-telecom-firm-via-cisco-flaw/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🚨 Salt Typhoon exploits router flaws to spy on global telecoms, FBI and Canada warn. (Published on 6/23/2025, Hackread). &lt;a href="https://hackread.com/salt-typhoon-targets-telecoms-router-flaws-fbi-canada/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🐺 Chinese group Silver Fox uses fake websites to spread Sainbox RAT and hidden rootkit. (Published on 6/27/2025, The Hacker News). &lt;a href="https://thehackernews.com/2025/06/chinese-group-silver-fox-uses-fake.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 30 May 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-080/</link><pubDate>Fri, 30 May 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-080/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;This week’s cyber headlines are packed with breaches, bots, BitM attacks, and even a courtroom confession. Dive into the Friday Wrap-Up to stay ahead—and maybe even stay safe. 🧠🛡️&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-threats--malware-attacks"&gt;&lt;strong&gt;Cybersecurity Threats &amp;amp; Malware Attacks&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;This week brought an array of fresh threats and major disclosures:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;⚠️ Over 70 malicious npm and VS Code packages steal user data and crypto via Discord endpoints. (Published on 5/26/2025, The Hacker News). &lt;strong&gt;&lt;a href="https://thehackernews.com/2025/05/over-70-malicious-npm-and-vs-code.html"&gt;Read More&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 21 March 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-071/</link><pubDate>Fri, 21 Mar 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-071/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;🔐 Major Data Breaches and Privacy Concerns&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🏦 Western Alliance Bank confirms data breach linked to the Cleo file transfer tool, impacting 22,000 customers. (Published on 3/18/2025, SecurityWeek). &lt;a href="https://www.securityweek.com/western-alliance-bank-discloses-data-breach-linked-to-cleo-hack/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🧬 California Cryobank warns of a data breach affecting sensitive personal information of clients. (Published on 3/18/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/sperm-donation-giant-california-cryobank-warns-of-a-data-breach/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 28 February 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-068/</link><pubDate>Fri, 28 Feb 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-068/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cybersecurity-threats--attacks"&gt;🚨 Cybersecurity Threats &amp;amp; Attacks&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🎭 Hackers exploit Google Docs and Steam to spread ACRStealer, a new infostealer malware targeting users via trusted platforms. (Published on 2/24/2025, Hackread). &lt;a href="https://hackread.com/hackers-google-docs-steam-drop-acrstealer-infostealer/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🔍 OpenAI bans ChatGPT accounts linked to Chinese threat actors who allegedly used the AI model for espionage tool development. (Published on 2/24/2025, SecurityWeek). &lt;a href="https://www.securityweek.com/openai-bans-chatgpt-accounts-used-by-chinese-group-for-spy-tools/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 31 January 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-064/</link><pubDate>Fri, 31 Jan 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-064/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cybersecurity-news--emerging-threats"&gt;🔥 Cybersecurity News &amp;amp; Emerging Threats&lt;/h3&gt;
&lt;p&gt;From zero-day exploits to ransomware attacks, here’s what’s making waves in cybersecurity this week.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🍏 Apple patches the first actively exploited zero-day of 2025, targeting iPhone users. (Published on 1/27/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/apple-fixes-this-years-first-actively-exploited-zero-day-bug/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🚨 DeepSeek AI halts new user registrations after a large-scale cyberattack disrupts operations. (Published on 1/27/2025, Hackread). &lt;a href="https://hackread.com/deepseek-large-scale-cyberattack-halts-user-registrations/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 30 January 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-063/</link><pubDate>Thu, 30 Jan 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-063/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another avalanche of cyber chaos! From dating apps getting breached (swipe left on that security posture) to 1.5 million devs accidentally installing code-stealing VS Code extensions, it’s been a wild ride.&lt;/p&gt;
&lt;p&gt;This week’s highlights: ShinyHunters went on a shopping spree, North Korean hackers are forming splinter groups like a K-pop band, and apparently 175,000 AI servers are just&amp;hellip; out there&amp;hellip; exposed. Also, half your employees are using shadow AI tools, and your C-suite is leading the charge.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 24 January 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-062/</link><pubDate>Fri, 24 Jan 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-062/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cybersecurity-breaches--attacks"&gt;🚨 Cybersecurity Breaches &amp;amp; Attacks&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🛠️ &lt;strong&gt;HPE investigates breach&lt;/strong&gt; as a hacker claims to have stolen sensitive documents from its developer environments. (Published on 1/20/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/hewlett-packard-enterprise-investigates-new-breach-claims/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🔓 &lt;strong&gt;PowerSchool data breach&lt;/strong&gt; exposes students’ and educators’ personal information in a December 2024 cyberattack. (Published on 1/21/2025, SecurityWeek). &lt;a href="https://www.securityweek.com/students-educators-impacted-by-powerschool-data-breach/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 17 January 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-060/</link><pubDate>Fri, 17 Jan 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-060/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cybersecurity-threats--vulnerabilities"&gt;🔐 Cybersecurity Threats &amp;amp; Vulnerabilities&lt;/h3&gt;
&lt;p&gt;The latest cybersecurity developments highlight ongoing threats and vulnerabilities across various sectors.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🚨 A Microsoft MFA outage is preventing users from accessing Microsoft 365 apps. (Published on 1/13/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-mfa-outage-blocking-access-to-microsoft-365-apps/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🛑 Over 4,000 web backdoors were hijacked by registering expired domains, exposing compromised systems to further risks. (Published on 1/12/2025, The Hacker News). &lt;a href="https://thehackernews.com/2025/01/expired-domains-allowed-control-over.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 3 January 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-057/</link><pubDate>Fri, 03 Jan 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-057/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-breaches-and-incidents"&gt;Cybersecurity Breaches and Incidents&lt;/h3&gt;
&lt;p&gt;🔒 &lt;strong&gt;Chinese state-sponsored hackers breached the U.S. Treasury Department&lt;/strong&gt; via a remote support platform. (Published on 12/30/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/us-treasury-department-breached-through-remote-support-platform/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🚘 &lt;strong&gt;Volkswagen, Audi, and Skoda EV owners affected by a major data breach&lt;/strong&gt; tracking over 800,000 vehicles. (Published on 12/30/2024, Hackread). &lt;a href="https://hackread.com/exposed-cloud-server-tracks-volkswagen-audi-skoda-evs/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 27 December 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-056/</link><pubDate>Fri, 27 Dec 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-056/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h4 id="threat-actors-and-malware"&gt;&lt;strong&gt;Threat Actors and Malware&lt;/strong&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🎯 Lazarus Group targets the nuclear industry using CookiePlus malware. Critical threat intelligence updates shared by Kaspersky. (Published on 12/23/2024, Hackread). &lt;a href="https://hackread.com/lazarus-group-nuclear-industry-cookieplus-malware/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🐱 Iran’s Charming Kitten deploys BellaCPP, a C++ variant of the BellaCiao malware, increasing its attack sophistication. (Published on 12/25/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/12/irans-charming-kitten-deploys-bellacpp.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 20 December 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-055/</link><pubDate>Fri, 20 Dec 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-055/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-threats-and-attacks"&gt;Cybersecurity Threats and Attacks&lt;/h3&gt;
&lt;p&gt;Staying informed about the latest cybersecurity threats and data breaches is essential for businesses and individuals alike.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🛑 Malicious ads spread Lumma Stealer via fake CAPTCHA pages, tricking users into running PowerShell commands. (Published on 12/16/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/malicious-ads-push-lumma-infostealer-via-fake-captcha-pages/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🐘 Glutton malware exploits popular PHP frameworks like Laravel and ThinkPHP, targeting multiple countries. (Published on 12/16/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/12/new-glutton-malware-exploits-popular.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 25 October 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-049/</link><pubDate>Fri, 25 Oct 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-049/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-breaches-and-threats"&gt;&lt;strong&gt;Cybersecurity Breaches and Threats&lt;/strong&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;⚠️ Internet Archive (Archive.org) suffers its second breach this month, exposing support tickets via unrotated Zendesk credentials. (Published on 10/21/2024, Hack Read). &lt;a href="https://hackread.com/internet-archive-archive-org-hacked-for-second-time/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🔧 VMware patches another remote code execution flaw exploited during a Chinese hacking contest in June 2024. (Published on 10/21/2024, SecurityWeek). &lt;a href="https://www.securityweek.com/vmware-struggles-to-fix-flaw-exploited-at-chinese-hacking-contest/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 11 October 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-047/</link><pubDate>Fri, 11 Oct 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-047/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-breaches"&gt;Cybersecurity Breaches&lt;/h3&gt;
&lt;p&gt;🚨 ADT discloses a second breach within two months, with attackers gaining access using stolen credentials to exfiltrate employee account data. (Published on 10/7/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/adt-discloses-second-breach-in-2-months-hacked-via-stolen-credentials/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🚨 LEGO’s website was hacked by cryptocurrency scammers promoting a fake Lego token that could be purchased with Ethereum. (Published on 10/7/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/legos-website-hacked-to-push-cryptocurrency-scam/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 20 Sept 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-044/</link><pubDate>Fri, 20 Sep 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-044/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="vulnerability-fixes-and-threat-patches"&gt;Vulnerability Fixes and Threat Patches&lt;/h3&gt;
&lt;p&gt;🔒 D-Link patches critical flaws in WiFi 6 routers, addressing vulnerabilities that allowed attackers to exploit hardcoded credentials and execute arbitrary code. (Published on 9/16/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/d-link-fixes-critical-rce-hardcoded-password-flaws-in-wifi-6-routers/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔑 Apple addresses major security flaws in iOS 18, warning that attackers could use Siri to access sensitive user data or control nearby devices. (Published on 9/16/2024, SecurityWeek). &lt;a href="https://www.securityweek.com/apple-patches-major-security-flaws-with-ios-18-refresh/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 13 September 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-043/</link><pubDate>Fri, 13 Sep 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-043/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/c58afca7b6e9f5e6.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-incidents-"&gt;Cybersecurity Incidents 🛡️&lt;/h3&gt;
&lt;p&gt;🚨 Highline Public Schools shuts down following a cyberattack, causing school closures and activity cancellations. (Published on 9/9/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/highline-public-schools-closes-schools-following-cyberattack/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🚨 Avis Car Rental data breach affects 300,000 customers, exposing personal information in August 2024. (Published on 9/9/2024, SecurityWeek). &lt;a href="https://www.securityweek.com/300000-impacted-by-data-breach-at-car-rental-firm-avis/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🚨 Fortinet confirms a data breach after a hacker claims to have stolen 440GB of files from their Microsoft SharePoint server. (Published on 9/12/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/fortinet-confirms-data-breach-after-hacker-claims-to-steal-440gb-of-files/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 6 September 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-042/</link><pubDate>Fri, 06 Sep 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-042/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="data-breaches--security-failures"&gt;Data Breaches &amp;amp; Security Failures&lt;/h3&gt;
&lt;p&gt;🔓 &lt;strong&gt;Verkada&lt;/strong&gt; will pay $2.95M after security lapses allowed hackers to access live feeds from 150,000 cameras. (Published on 9/2/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/verkada-to-pay-295m-for-security-failures-leading-to-breaches/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔐 &lt;strong&gt;CBIZ&lt;/strong&gt; disclosed a data breach involving unauthorized access to client information stored in specific databases. (Published on 9/2/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/business-services-giant-cbiz-discloses-customer-data-breach/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 23 Aug 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-040/</link><pubDate>Fri, 23 Aug 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-040/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-breaches-and-vulnerabilities"&gt;Cybersecurity Breaches and Vulnerabilities&lt;/h3&gt;
&lt;p&gt;🔒 FlightAware alerts users to reset passwords following a data security incident that may have exposed personal information. (Published on 8/19/2024, Bleeping Computer). &lt;a href="https://www.bleepingcomputer.com/news/security/flightaware-configuration-error-leaked-user-data-for-years/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;📱 Google Pixel phones found with a Verizon app that serves as a potential backdoor for attackers. (Published on 8/19/2024, Dark Reading). &lt;a href="https://www.darkreading.com/remote-workforce/every-google-pixel-phone-has-a-verizon-app-backdoor"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 22 August 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-039/</link><pubDate>Thu, 22 Aug 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-039/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Cars weren’t the only things being unlocked — patient records, HR data, and even McDonald’s portals were on the menu.&lt;/p&gt;
&lt;p&gt;Meanwhile, governments went after ransomware wallets, AI browsers went shopping on their own, and TikTok replaced moderators with algorithms.&lt;/p&gt;
&lt;p&gt;🔍 From zero-days to fake Europol rewards, this week proves one thing: cyber never sleeps (but maybe TikTok’s moderators finally will).&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;🚨 Major Cyberattacks &amp;amp; Data Breaches&lt;/strong&gt; This week saw breaches across industries — from HR platforms to healthcare — showing how attackers continue to exploit trusted systems.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 19 July 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-035/</link><pubDate>Fri, 19 Jul 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-035/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚨 Cybercriminals use Facebook ads to spread info-stealing malware via fake Windows themes. Stay alert! (Published on 7/15/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/facebook-ads-for-windows-themes-push-sys01-info-stealing-malware/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🚫 Kaspersky Lab announces the shutdown of its U.S. operations starting July 20. (Published on 7/15/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/kaspersky-is-shutting-down-its-business-in-the-united-states/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🛡️ Rite Aid suffers a data breach affecting older customer purchases, becoming RansomHub&amp;rsquo;s latest victim. (Published on 7/15/2024, Dark Reading). &lt;a href="https://www.darkreading.com/cyberattacks-data-breaches/rite-aid-ransomhub-victim-data-breach"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 5 July 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-032/</link><pubDate>Fri, 05 Jul 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-032/</guid><description>&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/strong&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚨 An Australian man charged for conducting an ‘evil twin’ WiFi attack on domestic flights, stealing credentials. (Published on 7/1/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/australian-charged-for-evil-twin-wifi-attack-on-plane/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔒 HubSpot is actively blocking attempts to hack customer accounts amidst ongoing cyberattacks. (Published on 7/1/2024, SecurityWeek). &lt;a href="https://www.securityweek.com/hubspot-warns-of-ongoing-cyberattacks-targeting-customer-accounts/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🛡️ Landmark Admin discloses a data breach compromising personal and medical information from May. (Published on 7/1/2024, SecurityWeek). &lt;a href="https://www.securityweek.com/landmark-admin-discloses-data-breach-impacting-personal-medical-information/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 28 June 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-030/</link><pubDate>Fri, 28 Jun 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-030/</guid><description>&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/strong&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚀 Google is testing &amp;ldquo;Digital Credential API&amp;rdquo; for Chrome on Android to enhance secure ID verification via mobile wallets. (Published on 6/24/2024, IoT and Edge). &lt;a href="https://www.bleepingcomputer.com/news/google/chrome-for-android-tests-feature-that-securely-verifies-your-id-with-sites/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;⚠️ The &amp;lsquo;GrimResource&amp;rsquo; attack exploits MSC files and an unpatched Windows XSS flaw for network breaches. Stay alert! (Published on 6/24/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/new-grimresource-attack-uses-msc-files-and-windows-xss-flaw-to-breach-networks/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 27 June 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-029/</link><pubDate>Thu, 27 Jun 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-029/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another buffet of breaches, botnets, and bureaucratic advisories! 🍽️&lt;/p&gt;
&lt;p&gt;The FBI unmasked IntelBroker using email trails, crypto wallets, and YouTube activity, reminding us that your “anonymous” OPSEC is only as good as your weakest Like button 👍.&lt;/p&gt;
&lt;p&gt;If you’re feeling overwhelmed, you’re not alone. The pace of attacks continues to remind us that no matter how strong your defenses, there’s always a misconfigured Docker API somewhere ready to turn into a crypto-mining hotspot. 🐈‍⬛💻&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 7 June 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-025/</link><pubDate>Fri, 07 Jun 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-025/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚨 A massive trove of 361 million stolen accounts has been added to Have I Been Pwned. Check if your accounts are compromised! (Published on 6/3/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/361-million-stolen-accounts-leaked-on-telegram-added-to-hibp/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔒 Security researchers discovered a high-severity vulnerability in Azure Service Tags, but Microsoft disagrees. (Published on 6/3/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/microsoft/azure-service-tags-tagged-as-security-risk-microsoft-disagrees/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 31 May 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-024/</link><pubDate>Fri, 31 May 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-024/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚀 TP-Link fixes a critical RCE bug in its popular C5400X gaming router. Stay updated! (Published on 5/27/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/tp-link-fixes-critical-rce-bug-in-popular-c5400x-gaming-router/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔒 Hackers are targeting Check Point VPNs in a campaign to breach enterprise networks. Stay secure! (Published on 5/27/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/hackers-target-check-point-vpns-to-breach-enterprise-networks/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;💳 A Moroccan cybercrime group is stealing up to $100K daily through sophisticated gift card fraud. Be cautious! (Published on 5/27/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/05/moroccan-cybercrime-group-steals-up-to.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 24 May 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-023/</link><pubDate>Fri, 24 May 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-023/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚨 Microsoft introduces &amp;lsquo;Recall&amp;rsquo; for Windows 11, an AI feature that records your activities for easy search. (Published on 5/20/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/microsoft/windows-11-recall-ai-feature-will-record-everything-you-do-on-your-pc/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🛡️ The latest BiBi Wiper malware version now deletes the disk partition table, complicating data recovery. (Published on 5/20/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/new-bibi-wiper-version-also-destroys-the-disk-partition-table/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔒 American Radio Relay League (ARRL) suffers a cyberattack, causing disruptions and potential data breach. (Published on 5/20/2024, SecurityWeek). &lt;a href="https://www.securityweek.com/american-radio-relay-league-hit-by-cyberattack/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 03 May 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-018/</link><pubDate>Fri, 03 May 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-018/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🔐 Google thwarted 2.28 million malicious app attempts on Play Store in 2023, enhancing user security (Published on 4/29/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/04/google-prevented-228-million-malicious.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🌐 &amp;lsquo;Muddling Meerkat&amp;rsquo; linked to China, manipulates DNS to scan global internet networks (Published on 4/29/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/04/china-linked-muddling-meerkat-hijacks.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🏥 Kaiser Permanente reveals data breach affecting 13.4 million, exposing personal details (Published on 4/29/2024, SecurityWeek). &lt;a href="https://www.securityweek.com/kaiser-permanente-discloses-data-breach-impacting-13-4-million-patients/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 12 April 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-015/</link><pubDate>Fri, 12 Apr 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-015/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚨 Greylock McKinnon Associates reports a major data breach, exposing over 340,000 Social Security numbers. Stay vigilant! (Published on 4/8/2024, TechCrunch). &lt;a href="https://techcrunch.com/2024/04/08/hackers-stole-340000-social-security-numbers-from-government-consulting-firm/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔓 D-Link NAS devices with critical vulnerabilities won&amp;rsquo;t receive patches, putting 92,000 devices at risk. (Published on 4/8/2024, Ars Technica). &lt;a href="https://arstechnica.com/security/2024/04/hackers-actively-exploit-critical-remote-takeover-vulnerabilities-in-d-link-devices/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;💸 Nearly 2,000 WordPress sites have been compromised to trick visitors with fake NFT pop-ups and crypto drainers. Be cautious! (Published on 4/8/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/hackers-deploy-crypto-drainers-on-thousands-of-wordpress-sites/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 5 April 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-014/</link><pubDate>Fri, 05 Apr 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-014/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🛒 &lt;strong&gt;Shopping Platform PandaBuy Data Leak Impacts 1.3 Million Users&lt;/strong&gt; - Over 1.3 million PandaBuy users&amp;rsquo; data leaked. (4/1/2024, BleepingComputer) &lt;a href="https://www.bleepingcomputer.com/news/security/shopping-platform-pandabuy-data-leak-impacts-13-million-users/"&gt;Read more&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;📱 &lt;strong&gt;AT&amp;amp;T Confirms 73M Customers Affected in Data Leak&lt;/strong&gt; - AT&amp;amp;T admits data on 73M customers leaked on Dark Web. (4/1/2024, Dark Reading) &lt;a href="https://www.darkreading.com/remote-workforce/att-confirms-73m-customers-affected-data-leak"&gt;Read more&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 15 March 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-010/</link><pubDate>Fri, 15 Mar 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-010/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🛡️ &amp;ldquo;Knowledge base for Microsoft SCCM attack techniques exposed&amp;rdquo; - 3/11/2024, BleepingComputer &lt;a href="https://www.bleepingcomputer.com/news/security/researchers-expose-microsoft-sccm-misconfigs-usable-in-cyberattacks/"&gt;Read more&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🚨 &amp;ldquo;CISA offline after Ivanti breach, details scarce&amp;rdquo; - 3/11/2024, Dark Reading &lt;a href="https://www.darkreading.com/cyberattacks-data-breaches/ivanti-breach-cisa-systems-offline"&gt;Read more&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;⌨️ &amp;ldquo;Typosquatting attacks continue to thrive&amp;rdquo; - 3/11/2024, Dark Reading &lt;a href="https://www.darkreading.com/threat-intelligence/typosquatting-wave-shows-no-signs-of-abating"&gt;Read more&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;📸 &amp;ldquo;Midjourney bans Stability AI for image-scraping&amp;rdquo; - 3/11/2024, Ars Technica &lt;a href="https://arstechnica.com/information-technology/2024/03/in-ironic-twist-midjourney-bans-rival-ai-firm-employees-for-scraping-its-image-data/"&gt;Read more&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 8 March 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-009/</link><pubDate>Fri, 08 Mar 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-009/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;💳 American Express warns of a third-party breach exposing credit cards. (3/4/2024, BleepingComputer) &lt;a href="https://www.bleepingcomputer.com/news/security/american-express-credit-cards-exposed-in-vendor-data-breach/"&gt;Read more&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🎣 Hackers use phishing to steal Windows NTLM hashes. (3/4/2024, BleepingComputer) &lt;a href="https://www.bleepingcomputer.com/news/security/hackers-steal-windows-ntlm-authentication-hashes-in-phishing-attacks/"&gt;Read more&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔒 GitHub battles millions of malicious repos. (3/4/2024, Dark Reading) &lt;a href="https://www.darkreading.com/application-security/millions-of-malicious-repositories-flood-github"&gt;Read more&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🛑 Meta faces massive outage across top social apps. (3/5/2024, TechCrunch) &lt;a href="https://techcrunch.com/2024/03/05/facebook-instagram-and-threads-are-all-down-in-massive-meta-outage-on-super-tuesday/"&gt;Read more&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 28 February 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-007/</link><pubDate>Wed, 28 Feb 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-007/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cybersecurity-threats--attacks"&gt;🚨 Cybersecurity Threats &amp;amp; Attacks&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🎭 Hackers exploit Google Docs and Steam to spread ACRStealer, a new infostealer malware targeting users via trusted platforms. (Published on 2/24/2025, Hackread). &lt;a href="https://hackread.com/hackers-google-docs-steam-drop-acrstealer-infostealer/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🔍 OpenAI bans ChatGPT accounts linked to Chinese threat actors who allegedly used the AI model for espionage tool development. (Published on 2/24/2025, SecurityWeek). &lt;a href="https://www.securityweek.com/openai-bans-chatgpt-accounts-used-by-chinese-group-for-spy-tools/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 24 January 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-002/</link><pubDate>Wed, 24 Jan 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-002/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cybersecurity-breaches--attacks"&gt;🚨 Cybersecurity Breaches &amp;amp; Attacks&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🛠️ &lt;strong&gt;HPE investigates breach&lt;/strong&gt; as a hacker claims to have stolen sensitive documents from its developer environments. (Published on 1/20/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/hewlett-packard-enterprise-investigates-new-breach-claims/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🔓 &lt;strong&gt;PowerSchool data breach&lt;/strong&gt; exposes students’ and educators’ personal information in a December 2024 cyberattack. (Published on 1/21/2025, SecurityWeek). &lt;a href="https://www.securityweek.com/students-educators-impacted-by-powerschool-data-breach/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item></channel></rss>