<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Malware &amp; Trojans on Jorge Laurel</title><link>https://jorgelaurel.com/topics/malware--trojans/</link><description>Recent content in Malware &amp; Trojans on Jorge Laurel</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 03 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://jorgelaurel.com/topics/malware--trojans/index.xml" rel="self" type="application/rss+xml"/><item><title>Friday Wrap Up: 3 April 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-119/</link><pubDate>Fri, 03 Apr 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-119/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;This week in cybersecurity was a masterclass in how fast things can go sideways. 🔐&lt;/p&gt;
&lt;p&gt;Ransomware operators are now completing full attacks in under an hour. AI platforms you use every day shipped critical vulnerabilities. A supply chain attack hit a JavaScript library with 100M+ weekly downloads. And someone accidentally leaked 512,000 lines of AI source code — which attackers immediately weaponized into a malware campaign on GitHub.&lt;/p&gt;
&lt;p&gt;If your patch queue looks overwhelming right now, you’re not alone. Chrome, Cisco, F5, Fortinet, and more all dropped critical fixes this week — many already under active exploitation before patches shipped.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 27 March 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-118/</link><pubDate>Fri, 27 Mar 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-118/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;This week: a pro-Iranian group hacked the FBI Director&amp;rsquo;s personal email. North Korean hackers got hired for remote IT jobs. TeamPCP backdoored yet another PyPI package. And an iPhone exploit kit has evolved directly from the zero-click campaign that hit Russian targets back in 2023.&lt;br&gt;
&lt;br&gt;
In the &amp;ldquo;things we didn&amp;rsquo;t need&amp;rdquo; column: GlassWorm now uses the Solana blockchain to route its malware payloads, a new infostealer bypasses Chrome&amp;rsquo;s Application-Bound Encryption, and a QR code phishing campaign somehow slipped past SPF, DKIM, AND DMARC at scale — 1.6 million emails delivered, no alarm raised.&lt;br&gt;
&lt;br&gt;
It&amp;rsquo;s a lot. Click through for 34 stories across 6 categories, and maybe patch your NetScaler while you&amp;rsquo;re at it.&lt;br&gt;
&lt;br&gt;
#FWU #fridaywrapup #SupplyChainSecurity #NationStateHackers #PatchNow #Malware #DataBreach #Ransomware&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 13 March 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-116/</link><pubDate>Fri, 13 Mar 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-116/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Happy Friday the 13th! 🔪 In the spirit of the day, threat actors did NOT hold back this week.&lt;/p&gt;
&lt;p&gt;We’ve got Chrome extensions that turned evil after changing hands, an AI agent that decided to mine crypto on its own (nobody asked, buddy 🤖⛏️), a medtech giant hit by Iranian hackers claiming to have wiped 200,000 devices, and a 1 petabyte data theft claim that made storage admins everywhere break into a cold sweat.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 20 February 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-113/</link><pubDate>Fri, 20 Feb 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-113/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another reminder that the internet is basically a haunted house and someone keeps adding new rooms. 🏚️&lt;/p&gt;
&lt;p&gt;This week’s Friday Wrap Up covers data breaches hitting your wallet and your wardrobe, Android malware clever enough to use Google’s own AI against you, Chrome zero-days being actively exploited, fake AI tools fooling a quarter million users, and OAuth phishing attacks that let hackers waltz through MFA like they own the place.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 9 January 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-110/</link><pubDate>Fri, 09 Jan 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-110/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another wave of vulnerabilities keeping us on our toes!&lt;/p&gt;
&lt;p&gt;From nation-state hackers conducting global credential harvesting campaigns to fake AI Chrome extensions stealing nearly a million users’ data, this week proved cybersecurity professionals earn every bit of their coffee budget. Critical n8n vulnerabilities reached CVSS scores that made even hardened defenders nervous, while Chinese Salt Typhoon intrusions keep expanding in scope. Meanwhile, Disney learned that YouTube privacy violations cost $10M—turns out COPPA compliance isn’t optional.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 12 December 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-108/</link><pubDate>Fri, 12 Dec 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-108/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another avalanche of zero-days, ransomware victims, and creative attack techniques that make you wonder if threat actors ever sleep (spoiler: they don’t).&lt;/p&gt;
&lt;p&gt;From Chrome getting exploited in the wild to malware hiding in VS Code extensions—because apparently, even our dev tools need therapy now—this week had it all. We’ve got nation-state shenanigans, AI security guardrails, and someone at Accenture allegedly fudging DoD compliance (yikes).&lt;/p&gt;
&lt;p&gt;Click through for the full breakdown before your CISO asks if you’ve seen the latest Chrome patch.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 5 December 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-107/</link><pubDate>Fri, 05 Dec 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-107/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another reminder that cybercriminals are getting creative while defenders scramble to keep up! From malware disguising itself as helpful browser extensions to hackers learning poetry (yes, really) to break AI systems, this week had it all.&lt;/p&gt;
&lt;p&gt;We’re talking massive DDoS attacks breaking records, nation-states playing the long game with backdoors, and even an Aussie getting jail time for fake airport Wi-Fi. Plus, the eternal struggle continues: zero trust is still more “aspirational framework” than “accomplished mission” for most organizations.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 28 November 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-106/</link><pubDate>Fri, 28 Nov 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-106/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;This week’s cybersecurity landscape? Let’s just say the supply chain attacks are getting creative, the credential leaks are getting embarrassing, and emergency alert systems proved they’re not immune to ransomware.&lt;/p&gt;
&lt;p&gt;From worms named after sci-fi sandworms to threat groups with identity crises, we’ve got breaches affecting everything from real estate finance to your favorite analytics platforms.&lt;/p&gt;
&lt;p&gt;Oh, and reminder: those “helpful” code formatting websites? They’ve been collecting your credentials like Pokémon cards. Click through for the full roundup of this week’s digital chaos.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 7 November 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-103/</link><pubDate>Fri, 07 Nov 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-103/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another wild week in cybersecurity where insider threats meet nation-state attacks, AI-powered malware rewrites itself hourly, and even our security pros are allegedly moonlighting with ransomware gangs. 🤦‍♂️&lt;/p&gt;
&lt;p&gt;From YouTube ghost networks spreading infostealers through fake videos to logic bombs hiding in code packages set to detonate in 2027 (mark your calendars!), the threat landscape keeps getting more creative—and concerning 😳 .&lt;/p&gt;
&lt;p&gt;The Congressional Budget Office got breached, Samsung phones were compromised via malicious images, and ChatGPT vulnerabilities could leak your AI conversations. Meanwhile, the cybercrime equivalent of a corporate merger just happened with three major gangs joining forces 💸 .&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 31 October 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-102/</link><pubDate>Fri, 31 Oct 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-102/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Happy Halloween! 🎃&lt;/p&gt;
&lt;p&gt;This week’s cyber threats are scarier than any haunted house. We’ve got banking trojans that disguise themselves as humans, nation-state ghosts haunting European diplomats, and AI tools conjuring up security nightmares that would make Frankenstein nervous.&lt;/p&gt;
&lt;p&gt;Ransomware ghouls are back with new tricks, supply chain vampires are draining developer credentials, and Microsoft’s DNS went dark like a haunted mansion.&lt;/p&gt;
&lt;p&gt;Whether you’re more afraid of deepfakes, zero-days, or your cloud services vanishing into thin air, this week’s wrap-up has something to give every security professional the chills.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 24 October 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-101/</link><pubDate>Fri, 24 Oct 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-101/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another reminder that cybersecurity never takes a coffee break! ☕&lt;/p&gt;
&lt;p&gt;From botnet malware targeting your router to smart beds that won’t lie flat during cloud outages (yes, really), this week had everything. We’re talking billion-dollar breaches, quantum leaps, AI agents surfing the web, and Microsoft patches that caused more problems than they solved. Plus, ransomware victims learning the hard way that paying up doesn’t guarantee getting your data back.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 17 October 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-100/</link><pubDate>Fri, 17 Oct 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-100/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another wild week in cybersecurity! From nation-state actors breaching major tech companies to botnets going global, hackers weren’t taking any days off.&lt;/p&gt;
&lt;p&gt;We’ve got everything from AI guardrails getting schooled by basic prompt injection to a vulnerability so severe Microsoft had to break out their highest-ever severity score. Oh, and YouTube decided to take a little nap this week too.&lt;/p&gt;
&lt;p&gt;Cybersecurity stories covering everything from malware hiding in GitHub images to North Korean job scams that would make your HR department cry. Check out the full roundup to see what kept security teams caffeinated this week.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 12 September 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-095/</link><pubDate>Fri, 12 Sep 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-095/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;💥 This week in cyber was one for the history books.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;📦 The world’s largest supply chain attack hit npm, with billions of downloads tainted.&lt;br&gt;
⚡ Nation-state espionage escalated as China-linked groups ramped up campaigns tied to trade negotiations.&lt;br&gt;
💻 Ransomware evolved yet again, with &lt;strong&gt;HybridPetya&lt;/strong&gt; breaking UEFI Secure Boot and Akira exploiting SonicWall appliances.&lt;br&gt;
📱 Meanwhile, Samsung scrambled to patch a WhatsApp-linked zero-day, and Apple unveiled a five-year project to shut down spyware developers.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 05 September 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-094/</link><pubDate>Fri, 05 Sep 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-094/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;From record-breaking DDoS attacks and SVG-based phishing to zero-day exploits and AI-powered trade secret drama — this week’s threat landscape had something for everyone (except peace of mind).&lt;/p&gt;
&lt;p&gt;🔍 Russian APTs were intercepted mid-hack, North Korea’s ScarCruft went academic, and Google had to patch 120 Android flaws (yes, 120 — not a typo).&lt;/p&gt;
&lt;p&gt;🏭 Meanwhile, Bridgestone and Jaguar Land Rover hit the cyber brakes, Salesloft Drift’s supply-chain chaos keeps expanding, and a misconfigured server spilled 378GB of Navy Federal data like a coffee cup on a Monday keyboard.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 22 August 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-092/</link><pubDate>Fri, 22 Aug 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-092/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;🚨 Major Cyberattacks &amp;amp; Data Breaches&lt;/strong&gt; This week saw breaches across industries — from HR platforms to healthcare — showing how attackers continue to exploit trusted systems.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;👔 Workday discloses data breach linked to Salesforce attacks (Published on 8/18/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/hr-giant-workday-discloses-data-breach-amid-salesforce-attacks/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🍔 Hacker finds flaws in McDonald’s staff &amp;amp; partner hubs, exposing APIs and sensitive documents (Published on 8/20/2025, Dark Reading). &lt;a href="https://www.darkreading.com/cybersecurity-operations/hacker-finds-flaws-mcdonalds-staff-partner-hubs"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 8 Aug 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-090/</link><pubDate>Fri, 08 Aug 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-090/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚨 Zero-days, crypto-stealing extensions, and AI-weaponized attacks—it&amp;rsquo;s been a week full of cybersecurity “achievements.” Also: Perplexity&amp;rsquo;s scraping scandal, scammy snail mail, and AI that might be a little too curious. Full roundup below!&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="malware--vulnerabilities"&gt;&lt;strong&gt;Malware &amp;amp; Vulnerabilities&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;From zero-days in security appliances to flaws in Exchange, Axis, and IP cameras—this week was a buffet of critical bugs waiting to be exploited.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🛡️ SonicWall probing potential zero-day in SSL VPN after 20+ targeted attacks (Published on 8/4/2025, The Hacker News). &lt;a href="https://thehackernews.com/2025/08/sonicwall-investigating-potential-ssl.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 01 August 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-089/</link><pubDate>Fri, 01 Aug 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-089/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🔐 From AI-fueled deepfake threats to prompt injection vulnerabilities in cutting-edge tools, the cybersecurity battlefield keeps getting messier.&lt;/p&gt;
&lt;p&gt;Ransomware crews, phishing scams, and espionage actors all made headlines this week.&lt;/p&gt;
&lt;p&gt;Click through for a concise digest of what’s hot (and hacked) in cyber. 💥&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;Malware &amp;amp; Vulnerabilities&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;From AI-generated threats to prompt injection and phishing tricks, attackers are exploiting everything from popular dev tools to critical infrastructure.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🧪 AI-generated malicious npm package drained Solana wallets from over 1,500 users before takedown (Published on 8/1/2025, The Hacker News). &lt;a href="https://thehackernews.com/2025/08/ai-generated-malicious-npm-package.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 25 July 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-088/</link><pubDate>Fri, 25 Jul 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-088/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;This week, it’s cyber whack-a-mole: one forum admin down, another mirror site up. Meanwhile, malware gets cuddly (hi, pandas 🐼), and brands like Microsoft remain prime phishing bait.&lt;/p&gt;
&lt;p&gt;A dash of espionage, a pinch of legal drama, and a travel scam twist—because hackers need vacations too.&lt;/p&gt;
&lt;p&gt;👇 Dive in for the full roundup before your inbox gets spoofed.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="major-cyberattacks--incidents"&gt;&lt;strong&gt;Major Cyberattacks &amp;amp; Incidents&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Breaches, takedowns, and court battles highlight the ever-evolving cyber threat landscape.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 18 July 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-087/</link><pubDate>Fri, 18 Jul 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-087/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;Cybersecurity Tools &amp;amp; Techniques&lt;/strong&gt; New developments in tools and frameworks are shaping both offense and defense in the cybersecurity landscape.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🛠️ TREVORspray is a fast, stealthy credential spray toolkit for Azure, Okta, and OWA login portals. (Published on 7/14/2025, Darknet). &lt;a href="https://www.darknet.org.uk/2025/07/trevorspray-credential-spray-toolkit-for-azure-okta-owa-more/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🛡️ MITRE introduces AADAPT framework to defend financial systems and crypto assets. (Published on 7/15/2025, Dark Reading). &lt;a href="https://www.darkreading.com/vulnerabilities-threats/mitre-aadapt-framework-financial-systems"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 27 June 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-084/</link><pubDate>Fri, 27 Jun 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-084/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cyber-threats--state-linked-activity"&gt;🛡️ Cyber Threats &amp;amp; State-Linked Activity&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🕵️ Salt Typhoon hacks a Canadian telecom using Cisco flaws, confirming China-linked espionage. (Published on 6/23/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/canada-says-salt-typhoon-hacked-telecom-firm-via-cisco-flaw/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🚨 Salt Typhoon exploits router flaws to spy on global telecoms, FBI and Canada warn. (Published on 6/23/2025, Hackread). &lt;a href="https://hackread.com/salt-typhoon-targets-telecoms-router-flaws-fbi-canada/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🐺 Chinese group Silver Fox uses fake websites to spread Sainbox RAT and hidden rootkit. (Published on 6/27/2025, The Hacker News). &lt;a href="https://thehackernews.com/2025/06/chinese-group-silver-fox-uses-fake.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 13 June 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-082/</link><pubDate>Fri, 13 Jun 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-082/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;This week’s Friday Wrap-Up brings a dense mix of cyber drama and tech evolution: from state-sponsored exploits and zero-click spyware to novel threats using smartwatches.&lt;/p&gt;
&lt;p&gt;Big tech players like Meta and Google are making AI splashes, while law enforcement cracks down on massive malware networks. Catch the highlights, breaches, patches, and pivots in one place—because your inbox deserves clarity. Click through for the full update!&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cyber-espionage--nation-state-activity"&gt;&lt;strong&gt;Cyber Espionage &amp;amp; Nation-State Activity&lt;/strong&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🚫 OpenAI bans ChatGPT accounts tied to nation-state actors using AI for espionage and fraud (Published on 6/9/2025, Dark Reading). &lt;a href="https://www.darkreading.com/threat-intelligence/openai-bans-chatgpt-accounts-nation-state-threat-actors"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 6 June 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-081/</link><pubDate>Fri, 06 Jun 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-081/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Ever feel like your network is safer when it’s unplugged and buried in a lead box? Same.&lt;/p&gt;
&lt;p&gt;This week in the Friday Wrap Up: ransomware operators got unmasked, GPU bugs need urgent hugs (a.k.a. patches), and fake CAPTCHAs are convincing users to hack themselves. From hospital breaches to solar device hijacks, the digital drama never disappoints.&lt;/p&gt;
&lt;p&gt;If you like your cyber news fresh, punchy, and slightly panic-inducing (with a side of professionalism), check out this week’s Friday Wrap-Up. You bring the coffee, we’ll bring the chaos.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 30 May 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-080/</link><pubDate>Fri, 30 May 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-080/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;This week’s cyber headlines are packed with breaches, bots, BitM attacks, and even a courtroom confession. Dive into the Friday Wrap-Up to stay ahead—and maybe even stay safe. 🧠🛡️&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-threats--malware-attacks"&gt;&lt;strong&gt;Cybersecurity Threats &amp;amp; Malware Attacks&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;This week brought an array of fresh threats and major disclosures:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;⚠️ Over 70 malicious npm and VS Code packages steal user data and crypto via Discord endpoints. (Published on 5/26/2025, The Hacker News). &lt;strong&gt;&lt;a href="https://thehackernews.com/2025/05/over-70-malicious-npm-and-vs-code.html"&gt;Read More&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 23 May 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-079/</link><pubDate>Fri, 23 May 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-079/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🎉 Back from vacation and fully recharged—sunburned but secure! ☀️🔐 Missed a week, but fear not: your favorite Friday Wrap Up is back and packed tighter than a phishing kit on a USB stick.&lt;/p&gt;
&lt;p&gt;This week’s headlines are a buffet of cyber-chaos: ransomware gangs get sneakier, Chrome plays password nanny, and someone gave 40,000 iOS apps a little too much freedom. Also, Microsoft’s playing sheriff, Signal&amp;rsquo;s playing defense, and a student hacker’s playing guilty.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 9 May 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-078/</link><pubDate>Fri, 09 May 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-078/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;🔐 Cyber Threats &amp;amp; Malware Surge&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Cybercriminals continue to evolve tactics—from exploiting zero-days to using supply-chain attacks and AI developer tools. Here’s what’s making headlines:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🛑 Signal clone used by Trump official ceases operations after reported hack. (Published on 5/5/2025, Ars Technica). &lt;a href="https://arstechnica.com/security/2025/05/signal-clone-used-by-trump-official-stops-operations-after-report-it-was-hacked/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🚨 New ransomware attack uses &amp;ldquo;Bring Your Own Installer&amp;rdquo; to bypass EDR protections. (Published on 5/5/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/new-bring-your-own-installer-edr-bypass-used-in-ransomware-attack/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 25 April 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-076/</link><pubDate>Fri, 25 Apr 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-076/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🎉 This Week in Cyber: From AI Phishing to ATM Hacking – We’ve Seen It All&lt;/p&gt;
&lt;p&gt;If you thought cybercriminals might slow down in April… plot twist! 😅&lt;/p&gt;
&lt;p&gt;This week’s headlines brought:&lt;/p&gt;
&lt;p&gt;- AI-powered phishing toolkits that scale scams faster than startups scale servers 🤖💸&lt;/p&gt;
&lt;p&gt;- Ransomware attacks hitting hospitals, cities, and schools — because clearly nothing is sacred anymore 🏥🏛️&lt;/p&gt;
&lt;p&gt;- Spoofed emails that even Google thought were legit 🫣&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 11 April 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-074/</link><pubDate>Fri, 11 Apr 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-074/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚨 This week in cybersecurity: breakfast got breached, NASCAR took a pit stop for ransomware, and a new AI hacking assistant named Xanthorox hit the dark web like it’s applying for a job at Anonymous HQ.&lt;/p&gt;
&lt;p&gt;Meanwhile, “Lovable” AI turns out to be &lt;em&gt;a little too&lt;/em&gt; lovable to cybercriminals, WhatsApp had a Windows-flavored vulnerability, and someone really should check on those 4 million Chrome users installing sketchy extensions with “Featured” badges.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 4 April 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-073/</link><pubDate>Fri, 04 Apr 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-073/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It’s been a busy week in cybersecurity — the kind that makes your firewall sweat and your SOC team rethink their life choices.&lt;/p&gt;
&lt;p&gt;From phishing-as-a-service platforms like Lucid going global with their spammy ambitions, to malware dressing up in stealth mode and pretending it’s just “advanced persistence,” attackers are working overtime.&lt;/p&gt;
&lt;p&gt;Meanwhile, vulnerabilities in everything from solar tech to AI platforms remind us that no codebase is safe from bugs (especially the kind that moonlight as backdoors).&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 21 March 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-071/</link><pubDate>Fri, 21 Mar 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-071/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;🔐 Major Data Breaches and Privacy Concerns&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🏦 Western Alliance Bank confirms data breach linked to the Cleo file transfer tool, impacting 22,000 customers. (Published on 3/18/2025, SecurityWeek). &lt;a href="https://www.securityweek.com/western-alliance-bank-discloses-data-breach-linked-to-cleo-hack/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🧬 California Cryobank warns of a data breach affecting sensitive personal information of clients. (Published on 3/18/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/sperm-donation-giant-california-cryobank-warns-of-a-data-breach/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 14 March 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-070/</link><pubDate>Fri, 14 Mar 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-070/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-threats--incidents-"&gt;&lt;strong&gt;Cybersecurity Threats &amp;amp; Incidents&lt;/strong&gt; 🔥&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🚨 &lt;strong&gt;Americans lost a record $12.5 billion to fraud in 2024&lt;/strong&gt;, marking a 25% increase from the previous year. (Published on 3/10/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/us-govt-says-americans-lost-record-125-billion-to-fraud-in-2024/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🏴‍☠️ A &lt;strong&gt;former employee was found guilty of a revenge kill-switch scheme&lt;/strong&gt;, locking out users if their account was disabled. (Published on 3/10/2025, Dark Reading). &lt;a href="https://www.darkreading.com/cyberattacks-data-breaches/ex-employee-guilty-revenge-kill-switch-scheme"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 28 February 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-068/</link><pubDate>Fri, 28 Feb 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-068/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cybersecurity-threats--attacks"&gt;🚨 Cybersecurity Threats &amp;amp; Attacks&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🎭 Hackers exploit Google Docs and Steam to spread ACRStealer, a new infostealer malware targeting users via trusted platforms. (Published on 2/24/2025, Hackread). &lt;a href="https://hackread.com/hackers-google-docs-steam-drop-acrstealer-infostealer/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🔍 OpenAI bans ChatGPT accounts linked to Chinese threat actors who allegedly used the AI model for espionage tool development. (Published on 2/24/2025, SecurityWeek). &lt;a href="https://www.securityweek.com/openai-bans-chatgpt-accounts-used-by-chinese-group-for-spy-tools/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 21 February 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-067/</link><pubDate>Fri, 21 Feb 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-067/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cybersecurity-threats--exploits"&gt;🛡️ Cybersecurity Threats &amp;amp; Exploits&lt;/h3&gt;
&lt;p&gt;Cyberattacks are evolving, with new malware, vulnerabilities, and nation-state threats emerging. Stay informed and vigilant!&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🛑 &lt;strong&gt;Microsoft detects a new XCSSET macOS malware variant&lt;/strong&gt; targeting sensitive user data, including crypto wallets and Notes app content. (Published on 2/17/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/microsoft-spots-xcsset-macos-malware-variant-used-for-crypto-theft/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 7 February 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-065/</link><pubDate>Fri, 07 Feb 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-065/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cybersecurity-news--threats"&gt;🔥 Cybersecurity News &amp;amp; Threats&lt;/h3&gt;
&lt;p&gt;From AI impersonation to major vulnerabilities, here are some stories that shaped cybersecurity this week.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🎭 DeepSeek AI tools are being impersonated on PyPI by infostealer malware targeting developers. (Published on 2/3/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/deepseek-ai-tools-impersonated-by-infostealer-malware-on-pypi/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🏦 The Coyote banking trojan expands its reach, now targeting 1,030 sites and 73 financial institutions. (Published on 2/3/2025, The Hacker News). &lt;a href="https://thehackernews.com/2025/02/coyote-malware-expands-reach-now.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 31 January 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-064/</link><pubDate>Fri, 31 Jan 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-064/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cybersecurity-news--emerging-threats"&gt;🔥 Cybersecurity News &amp;amp; Emerging Threats&lt;/h3&gt;
&lt;p&gt;From zero-day exploits to ransomware attacks, here’s what’s making waves in cybersecurity this week.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🍏 Apple patches the first actively exploited zero-day of 2025, targeting iPhone users. (Published on 1/27/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/apple-fixes-this-years-first-actively-exploited-zero-day-bug/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🚨 DeepSeek AI halts new user registrations after a large-scale cyberattack disrupts operations. (Published on 1/27/2025, Hackread). &lt;a href="https://hackread.com/deepseek-large-scale-cyberattack-halts-user-registrations/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 30 January 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-063/</link><pubDate>Thu, 30 Jan 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-063/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another avalanche of cyber chaos! From dating apps getting breached (swipe left on that security posture) to 1.5 million devs accidentally installing code-stealing VS Code extensions, it’s been a wild ride.&lt;/p&gt;
&lt;p&gt;This week’s highlights: ShinyHunters went on a shopping spree, North Korean hackers are forming splinter groups like a K-pop band, and apparently 175,000 AI servers are just&amp;hellip; out there&amp;hellip; exposed. Also, half your employees are using shadow AI tools, and your C-suite is leading the charge.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 16 January 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-059/</link><pubDate>Thu, 16 Jan 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-059/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🎢 This week’s cybersecurity rollercoaster: where Wi-Fi crashes with one packet, Chrome extensions cosplay as your HR portal, and ZIP files contain more layers than a lasagna made by someone with commitment issues.&lt;/p&gt;
&lt;p&gt;The big picture? Attackers are getting sophisticated (looking at you, Predator spyware that learns from failure), infrastructure is falling over (RIP Verizon, enjoy your $20), and apparently two missing characters almost took down AWS. Two. Characters.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 10 January 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-058/</link><pubDate>Fri, 10 Jan 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-058/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-threats-and-attacks"&gt;&lt;strong&gt;Cybersecurity Threats and Attacks&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;These stories highlight the latest cybersecurity threats, including malware, nation-state hacks, and unconventional attack methods.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🛡️ FireScam malware disguises itself as &amp;ldquo;Telegram Premium&amp;rdquo; to steal data and maintain remote control of Android devices. Stay vigilant! (Published on 1/6/2025, The Hacker News). &lt;a href="https://thehackernews.com/2025/01/firescam-android-malware-poses-as.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 27 December 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-056/</link><pubDate>Fri, 27 Dec 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-056/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h4 id="threat-actors-and-malware"&gt;&lt;strong&gt;Threat Actors and Malware&lt;/strong&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🎯 Lazarus Group targets the nuclear industry using CookiePlus malware. Critical threat intelligence updates shared by Kaspersky. (Published on 12/23/2024, Hackread). &lt;a href="https://hackread.com/lazarus-group-nuclear-industry-cookieplus-malware/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🐱 Iran’s Charming Kitten deploys BellaCPP, a C++ variant of the BellaCiao malware, increasing its attack sophistication. (Published on 12/25/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/12/irans-charming-kitten-deploys-bellacpp.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 20 December 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-055/</link><pubDate>Fri, 20 Dec 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-055/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-threats-and-attacks"&gt;Cybersecurity Threats and Attacks&lt;/h3&gt;
&lt;p&gt;Staying informed about the latest cybersecurity threats and data breaches is essential for businesses and individuals alike.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🛑 Malicious ads spread Lumma Stealer via fake CAPTCHA pages, tricking users into running PowerShell commands. (Published on 12/16/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/malicious-ads-push-lumma-infostealer-via-fake-captcha-pages/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🐘 Glutton malware exploits popular PHP frameworks like Laravel and ThinkPHP, targeting multiple countries. (Published on 12/16/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/12/new-glutton-malware-exploits-popular.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 13 December 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-054/</link><pubDate>Fri, 13 Dec 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-054/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="category-critical-infrastructure-and-software-risks"&gt;Category: &lt;strong&gt;Critical Infrastructure and Software Risks&lt;/strong&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;⚠️ 90% of software in U.S. critical infrastructure contains code developed in China, posing systemic risks. (Published on 12/9/2024, Dark Reading). &lt;a href="https://www.darkreading.com/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🛠️ Forrester panel explores software supply chain vulnerabilities and global IT security challenges. (Published on 12/10/2024, InformationWeek). &lt;a href="https://www.informationweek.com/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 29 November 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-053/</link><pubDate>Fri, 29 Nov 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-053/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-threats-and-exploits"&gt;Cybersecurity Threats and Exploits&lt;/h3&gt;
&lt;p&gt;Key updates on critical vulnerabilities and sophisticated hacking campaigns targeting diverse platforms worldwide.&lt;/p&gt;
&lt;p&gt;🔓 mySCADA patches critical vulnerabilities in myPRO systems, which allowed remote unauthenticated system takeovers. (Published on 11/25/2024, SecurityWeek). &lt;a href="https://www.securityweek.com/vulnerabilities-expose-myscada-mypro-systems-to-remote-hacking/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🛡 Malware leveraging BYOVD techniques uses Avast’s anti-rootkit driver to disable antivirus protections. (Published on 11/25/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/11/researchers-uncover-malware-using-byovd.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 22 November 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-052/</link><pubDate>Fri, 22 Nov 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-052/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-threats-and-exploits"&gt;Cybersecurity Threats and Exploits&lt;/h3&gt;
&lt;p&gt;Newly discovered vulnerabilities and sophisticated hacking campaigns reveal the ongoing evolution of cyber threats across platforms and technologies.&lt;/p&gt;
&lt;p&gt;🔓 Chinese hackers exploit a Fortinet VPN zero-day vulnerability using the DeepData toolkit to steal credentials. (Published on 11/18/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-fortinet-vpn-zero-day-to-steal-credentials/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🎯 Fake discount sites mimic legitimate brands to exploit Black Friday shopping activity and steal customer information. (Published on 11/18/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/11/fake-discount-sites-exploit-black.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 15 November 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-051/</link><pubDate>Fri, 15 Nov 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-051/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-threats-and-exploits"&gt;Cybersecurity Threats and Exploits&lt;/h3&gt;
&lt;p&gt;Emerging cyber threats and vulnerabilities that highlight the evolving tactics of attackers targeting various platforms and industries.&lt;/p&gt;
&lt;p&gt;🛠 Revamped Remcos RAT targets Microsoft Windows users, exploiting known RCE vulnerabilities in Microsoft Office and WordPad. (Published on 11/11/2024, Dark Reading). &lt;a href="https://www.darkreading.com/application-security/revamped-remcos-rat-microsoft-windows-users"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 8 November 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-050/</link><pubDate>Fri, 08 Nov 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-050/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-threats-and-exploits"&gt;Cybersecurity Threats and Exploits&lt;/h3&gt;
&lt;p&gt;A roundup of recent cybersecurity incidents and newly discovered vulnerabilities impacting various platforms and users worldwide.&lt;/p&gt;
&lt;p&gt;🚨 DocuSign’s Envelopes API is being exploited to send fake invoices, mimicking brands like Norton and PayPal. (Published on 11/4/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/docusigns-envelopes-api-abused-to-send-realistic-fake-invoices/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔍 Google’s AI tool, Big Sleep, uncovers a zero-day vulnerability in the SQLite database engine, marking a first in AI-assisted vulnerability discovery. (Published on 11/4/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/11/googles-ai-tool-big-sleep-finds-zero.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 25 October 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-049/</link><pubDate>Fri, 25 Oct 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-049/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-breaches-and-threats"&gt;&lt;strong&gt;Cybersecurity Breaches and Threats&lt;/strong&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;⚠️ Internet Archive (Archive.org) suffers its second breach this month, exposing support tickets via unrotated Zendesk credentials. (Published on 10/21/2024, Hack Read). &lt;a href="https://hackread.com/internet-archive-archive-org-hacked-for-second-time/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🔧 VMware patches another remote code execution flaw exploited during a Chinese hacking contest in June 2024. (Published on 10/21/2024, SecurityWeek). &lt;a href="https://www.securityweek.com/vmware-struggles-to-fix-flaw-exploited-at-chinese-hacking-contest/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 20 Sept 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-044/</link><pubDate>Fri, 20 Sep 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-044/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="vulnerability-fixes-and-threat-patches"&gt;Vulnerability Fixes and Threat Patches&lt;/h3&gt;
&lt;p&gt;🔒 D-Link patches critical flaws in WiFi 6 routers, addressing vulnerabilities that allowed attackers to exploit hardcoded credentials and execute arbitrary code. (Published on 9/16/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/d-link-fixes-critical-rce-hardcoded-password-flaws-in-wifi-6-routers/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔑 Apple addresses major security flaws in iOS 18, warning that attackers could use Siri to access sensitive user data or control nearby devices. (Published on 9/16/2024, SecurityWeek). &lt;a href="https://www.securityweek.com/apple-patches-major-security-flaws-with-ios-18-refresh/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 13 September 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-043/</link><pubDate>Fri, 13 Sep 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-043/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/c58afca7b6e9f5e6.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-incidents-"&gt;Cybersecurity Incidents 🛡️&lt;/h3&gt;
&lt;p&gt;🚨 Highline Public Schools shuts down following a cyberattack, causing school closures and activity cancellations. (Published on 9/9/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/highline-public-schools-closes-schools-following-cyberattack/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🚨 Avis Car Rental data breach affects 300,000 customers, exposing personal information in August 2024. (Published on 9/9/2024, SecurityWeek). &lt;a href="https://www.securityweek.com/300000-impacted-by-data-breach-at-car-rental-firm-avis/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🚨 Fortinet confirms a data breach after a hacker claims to have stolen 440GB of files from their Microsoft SharePoint server. (Published on 9/12/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/fortinet-confirms-data-breach-after-hacker-claims-to-steal-440gb-of-files/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 23 Aug 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-040/</link><pubDate>Fri, 23 Aug 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-040/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-breaches-and-vulnerabilities"&gt;Cybersecurity Breaches and Vulnerabilities&lt;/h3&gt;
&lt;p&gt;🔒 FlightAware alerts users to reset passwords following a data security incident that may have exposed personal information. (Published on 8/19/2024, Bleeping Computer). &lt;a href="https://www.bleepingcomputer.com/news/security/flightaware-configuration-error-leaked-user-data-for-years/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;📱 Google Pixel phones found with a Verizon app that serves as a potential backdoor for attackers. (Published on 8/19/2024, Dark Reading). &lt;a href="https://www.darkreading.com/remote-workforce/every-google-pixel-phone-has-a-verizon-app-backdoor"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 22 August 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-039/</link><pubDate>Thu, 22 Aug 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-039/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Cars weren’t the only things being unlocked — patient records, HR data, and even McDonald’s portals were on the menu.&lt;/p&gt;
&lt;p&gt;Meanwhile, governments went after ransomware wallets, AI browsers went shopping on their own, and TikTok replaced moderators with algorithms.&lt;/p&gt;
&lt;p&gt;🔍 From zero-days to fake Europol rewards, this week proves one thing: cyber never sleeps (but maybe TikTok’s moderators finally will).&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;🚨 Major Cyberattacks &amp;amp; Data Breaches&lt;/strong&gt; This week saw breaches across industries — from HR platforms to healthcare — showing how attackers continue to exploit trusted systems.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 9 August 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-037/</link><pubDate>Fri, 09 Aug 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-037/</guid><description>&lt;hr&gt;
&lt;h3 id="its-been-a-busy-week-in-cybersecurity-and-time-for-a-friday-wrap-up-here-are-some-of-the-interesting-stories-from-this-past-week"&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/h3&gt;
&lt;hr&gt;
&lt;p&gt;🚨 The Hunters International ransomware group is using the new SharpRhino malware to target IT workers and breach corporate networks. (Published on 8/5/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/hunters-international-ransomware-gang-targets-it-workers-with-new-sharprhino-malware/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔍 One in five enterprise IT admins report state-sponsored attacks aiming to infiltrate their supply chains. (Published on 8/5/2024, Malware Analysis). &lt;a href="https://malware.news/t/1-in-5-companies-say-state-sponsored-attacks-try-to-penetrate-supply-chain/84883"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 2 August 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-036/</link><pubDate>Fri, 02 Aug 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-036/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🔒 Microsoft reports ransomware gangs exploiting VMware ESXi authentication bypass vulnerability. Stay alert! (Published on 7/29/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-ransomware-gangs-exploit-vmware-esxi-auth-bypass-in-attacks/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;⚠️ Stargazer Goblin creates 3,000 fake GitHub accounts to spread malware, earning $100,000 in illicit profits. (Published on 7/29/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/07/stargazer-goblin-creates-3000-fake.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🛡️ A critical security flaw in Acronis Cyber Infrastructure exploited in the wild; now patched. (Published on 7/29/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/07/critical-flaw-in-acronis-cyber.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 19 July 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-035/</link><pubDate>Fri, 19 Jul 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-035/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚨 Cybercriminals use Facebook ads to spread info-stealing malware via fake Windows themes. Stay alert! (Published on 7/15/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/facebook-ads-for-windows-themes-push-sys01-info-stealing-malware/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🚫 Kaspersky Lab announces the shutdown of its U.S. operations starting July 20. (Published on 7/15/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/kaspersky-is-shutting-down-its-business-in-the-united-states/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🛡️ Rite Aid suffers a data breach affecting older customer purchases, becoming RansomHub&amp;rsquo;s latest victim. (Published on 7/15/2024, Dark Reading). &lt;a href="https://www.darkreading.com/cyberattacks-data-breaches/rite-aid-ransomhub-victim-data-breach"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 18 July 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-034/</link><pubDate>Thu, 18 Jul 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-034/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another wild week in cybersecurity! From hackers giving Elmo a social media crisis and ransomware taking a shot at Russian vodka, to DDoS attacks making 2024 look like a warm-up act—there’s plenty to keep security pros and IT teams busy (and probably a little stressed).&lt;/p&gt;
&lt;p&gt;We’ve got everything:&lt;br&gt;
• &lt;strong&gt;Stealthy new hacking tools&lt;/strong&gt; targeting Azure, Okta, and more&lt;br&gt;
• &lt;strong&gt;Major malware campaigns&lt;/strong&gt; sneaking through npm and even Microsoft Teams&lt;br&gt;
• &lt;strong&gt;Supply chain risks&lt;/strong&gt; with firmware bugs and Linux cryptominers that just won’t quit&lt;br&gt;
• &lt;strong&gt;Ransomware&lt;/strong&gt; hitting both companies &lt;em&gt;and&lt;/em&gt; their liquor cabinets&lt;br&gt;
• &lt;strong&gt;Long-standing vulnerabilities&lt;/strong&gt; (turns out, some train hacks just need a couple of decades to get noticed)&lt;br&gt;
• &lt;strong&gt;Cloudflare blocking a tidal wave of DDoS&lt;/strong&gt;—and accidentally blocking itself, but hey, no hackers there&lt;br&gt;
• And for good measure, a dose of AI panic&amp;hellip;with experts saying we can keep our robot uprising memes on standby (for now)&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 5 July 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-032/</link><pubDate>Fri, 05 Jul 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-032/</guid><description>&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/strong&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚨 An Australian man charged for conducting an ‘evil twin’ WiFi attack on domestic flights, stealing credentials. (Published on 7/1/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/australian-charged-for-evil-twin-wifi-attack-on-plane/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔒 HubSpot is actively blocking attempts to hack customer accounts amidst ongoing cyberattacks. (Published on 7/1/2024, SecurityWeek). &lt;a href="https://www.securityweek.com/hubspot-warns-of-ongoing-cyberattacks-targeting-customer-accounts/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🛡️ Landmark Admin discloses a data breach compromising personal and medical information from May. (Published on 7/1/2024, SecurityWeek). &lt;a href="https://www.securityweek.com/landmark-admin-discloses-data-breach-impacting-personal-medical-information/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 27 June 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-029/</link><pubDate>Thu, 27 Jun 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-029/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another buffet of breaches, botnets, and bureaucratic advisories! 🍽️&lt;/p&gt;
&lt;p&gt;The FBI unmasked IntelBroker using email trails, crypto wallets, and YouTube activity, reminding us that your “anonymous” OPSEC is only as good as your weakest Like button 👍.&lt;/p&gt;
&lt;p&gt;If you’re feeling overwhelmed, you’re not alone. The pace of attacks continues to remind us that no matter how strong your defenses, there’s always a misconfigured Docker API somewhere ready to turn into a crypto-mining hotspot. 🐈‍⬛💻&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 21 June 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-028/</link><pubDate>Fri, 21 Jun 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-028/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚨 Hackers use F5 BIG-IP malware to stealthily steal data for years. Stay alert! (Published on 6/17/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/hackers-use-f5-big-ip-malware-to-stealthily-steal-data-for-years/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;⚖️ Empire Market owners charged for enabling $430M in dark web transactions. Legal repercussions ahead! (Published on 6/17/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/legal/empire-market-owners-charged-for-enabling-430m-in-dark-web-transactions/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔧 ASUS patches critical authentication bypass flaw in multiple router models. Update your devices! (Published on 6/17/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/06/asus-patches-critical-authentication.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 7 June 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-025/</link><pubDate>Fri, 07 Jun 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-025/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚨 A massive trove of 361 million stolen accounts has been added to Have I Been Pwned. Check if your accounts are compromised! (Published on 6/3/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/361-million-stolen-accounts-leaked-on-telegram-added-to-hibp/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔒 Security researchers discovered a high-severity vulnerability in Azure Service Tags, but Microsoft disagrees. (Published on 6/3/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/microsoft/azure-service-tags-tagged-as-security-risk-microsoft-disagrees/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 24 May 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-023/</link><pubDate>Fri, 24 May 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-023/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚨 Microsoft introduces &amp;lsquo;Recall&amp;rsquo; for Windows 11, an AI feature that records your activities for easy search. (Published on 5/20/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/microsoft/windows-11-recall-ai-feature-will-record-everything-you-do-on-your-pc/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🛡️ The latest BiBi Wiper malware version now deletes the disk partition table, complicating data recovery. (Published on 5/20/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/new-bibi-wiper-version-also-destroys-the-disk-partition-table/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔒 American Radio Relay League (ARRL) suffers a cyberattack, causing disruptions and potential data breach. (Published on 5/20/2024, SecurityWeek). &lt;a href="https://www.securityweek.com/american-radio-relay-league-hit-by-cyberattack/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 9 May 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-019/</link><pubDate>Thu, 09 May 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-019/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another thrilling episode of &lt;em&gt;As The Cyber World Burns&lt;/em&gt; 🔥&lt;/p&gt;
&lt;p&gt;From ransomware groups getting hacked (yes, really) to backdoored npm packages, fake installers, Pegasus penalties, and one too many Mirai botnets—I’ve highlighted the news story. Even a Signal clone used by a politician decided to just&amp;hellip; stop existing.&lt;/p&gt;
&lt;p&gt;If you’re into CIO existential crises, DDoS takedowns, or wondering what “Bring Your Own Installer” could possibly mean (spoiler: nothing good), I’ve highlighted it in this week’s &lt;strong&gt;Friday Wrap Up&lt;/strong&gt;. Because in cybersecurity, the only constant is, well&amp;hellip; incident response.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 26 April 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-017/</link><pubDate>Fri, 26 Apr 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-017/</guid><description>&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/strong&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🌐 MITRE, renowned for its cybersecurity frameworks, was compromised using MITRE techniques and Ivanti bugs (Published on 4/22/2024, Dark Reading). &lt;a href="https://www.darkreading.com/endpoint-security/mitre-attacked-infosecs-most-trusted-name-falls-to-ivanti-bugs"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🖨️ Russia&amp;rsquo;s APT28 targeted Windows Print Spooler to introduce &amp;lsquo;GooseEgg&amp;rsquo; malware, unknown until now (Published on 4/22/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/04/russias-apt28-exploited-windows-print.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🕵️♂️ ToddyCat hackers exploit advanced tools to steal data from governments on an industrial scale (Published on 4/22/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/04/russian-hacker-group-toddycat-uses.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 5 April 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-014/</link><pubDate>Fri, 05 Apr 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-014/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🛒 &lt;strong&gt;Shopping Platform PandaBuy Data Leak Impacts 1.3 Million Users&lt;/strong&gt; - Over 1.3 million PandaBuy users&amp;rsquo; data leaked. (4/1/2024, BleepingComputer) &lt;a href="https://www.bleepingcomputer.com/news/security/shopping-platform-pandabuy-data-leak-impacts-13-million-users/"&gt;Read more&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;📱 &lt;strong&gt;AT&amp;amp;T Confirms 73M Customers Affected in Data Leak&lt;/strong&gt; - AT&amp;amp;T admits data on 73M customers leaked on Dark Web. (4/1/2024, Dark Reading) &lt;a href="https://www.darkreading.com/remote-workforce/att-confirms-73m-customers-affected-data-leak"&gt;Read more&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 29 March 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-013/</link><pubDate>Fri, 29 Mar 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-013/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🔑 &lt;strong&gt;New MFA-Bypassing Phishing Kit Targets Microsoft 365, Gmail&lt;/strong&gt; - Cybercriminals exploit &amp;lsquo;Tycoon 2FA&amp;rsquo; to bypass 2FA on major email platforms. (3/25/2024, BleepingComputer) &lt;a href="https://www.bleepingcomputer.com/news/security/new-mfa-bypassing-phishing-kit-targets-microsoft-365-gmail-accounts/"&gt;Read more&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🍏 &lt;strong&gt;iOS 17.4.1 and macOS 14.4.1 Update for Security Fixes&lt;/strong&gt; - Apple rolls out crucial security updates without much detail. (3/25/2024, 9to5 Mac) &lt;a href="https://9to5mac.com/2024/03/25/ios-17-4-1-these-2-security-fixes/"&gt;Read more&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 15 March 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-010/</link><pubDate>Fri, 15 Mar 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-010/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🛡️ &amp;ldquo;Knowledge base for Microsoft SCCM attack techniques exposed&amp;rdquo; - 3/11/2024, BleepingComputer &lt;a href="https://www.bleepingcomputer.com/news/security/researchers-expose-microsoft-sccm-misconfigs-usable-in-cyberattacks/"&gt;Read more&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🚨 &amp;ldquo;CISA offline after Ivanti breach, details scarce&amp;rdquo; - 3/11/2024, Dark Reading &lt;a href="https://www.darkreading.com/cyberattacks-data-breaches/ivanti-breach-cisa-systems-offline"&gt;Read more&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;⌨️ &amp;ldquo;Typosquatting attacks continue to thrive&amp;rdquo; - 3/11/2024, Dark Reading &lt;a href="https://www.darkreading.com/threat-intelligence/typosquatting-wave-shows-no-signs-of-abating"&gt;Read more&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;📸 &amp;ldquo;Midjourney bans Stability AI for image-scraping&amp;rdquo; - 3/11/2024, Ars Technica &lt;a href="https://arstechnica.com/information-technology/2024/03/in-ironic-twist-midjourney-bans-rival-ai-firm-employees-for-scraping-its-image-data/"&gt;Read more&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 8 March 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-009/</link><pubDate>Fri, 08 Mar 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-009/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;💳 American Express warns of a third-party breach exposing credit cards. (3/4/2024, BleepingComputer) &lt;a href="https://www.bleepingcomputer.com/news/security/american-express-credit-cards-exposed-in-vendor-data-breach/"&gt;Read more&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🎣 Hackers use phishing to steal Windows NTLM hashes. (3/4/2024, BleepingComputer) &lt;a href="https://www.bleepingcomputer.com/news/security/hackers-steal-windows-ntlm-authentication-hashes-in-phishing-attacks/"&gt;Read more&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔒 GitHub battles millions of malicious repos. (3/4/2024, Dark Reading) &lt;a href="https://www.darkreading.com/application-security/millions-of-malicious-repositories-flood-github"&gt;Read more&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🛑 Meta faces massive outage across top social apps. (3/5/2024, TechCrunch) &lt;a href="https://techcrunch.com/2024/03/05/facebook-instagram-and-threads-are-all-down-in-massive-meta-outage-on-super-tuesday/"&gt;Read more&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 28 February 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-007/</link><pubDate>Wed, 28 Feb 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-007/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cybersecurity-threats--attacks"&gt;🚨 Cybersecurity Threats &amp;amp; Attacks&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🎭 Hackers exploit Google Docs and Steam to spread ACRStealer, a new infostealer malware targeting users via trusted platforms. (Published on 2/24/2025, Hackread). &lt;a href="https://hackread.com/hackers-google-docs-steam-drop-acrstealer-infostealer/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🔍 OpenAI bans ChatGPT accounts linked to Chinese threat actors who allegedly used the AI model for espionage tool development. (Published on 2/24/2025, SecurityWeek). &lt;a href="https://www.securityweek.com/openai-bans-chatgpt-accounts-used-by-chinese-group-for-spy-tools/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 21 February 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-006/</link><pubDate>Wed, 21 Feb 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-006/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cybersecurity-threats--exploits"&gt;🛡️ &lt;strong&gt;Cybersecurity Threats &amp;amp; Exploits&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Cyberattacks are evolving, with new malware, vulnerabilities, and nation-state threats emerging. Stay informed and vigilant!&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🛑 &lt;strong&gt;Microsoft detects a new XCSSET macOS malware variant&lt;/strong&gt; targeting sensitive user data, including crypto wallets and Notes app content. (Published on 2/17/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/microsoft-spots-xcsset-macos-malware-variant-used-for-crypto-theft/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 7 February 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-004/</link><pubDate>Wed, 07 Feb 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-004/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cybersecurity-news--threats"&gt;🔥 &lt;strong&gt;Cybersecurity News &amp;amp; Threats&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;From AI impersonation to major vulnerabilities, here’s what’s shaping cybersecurity this week.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🎭 DeepSeek AI tools are being impersonated on PyPI by infostealer malware targeting developers. (Published on 2/3/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/deepseek-ai-tools-impersonated-by-infostealer-malware-on-pypi/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🏦 The Coyote banking trojan expands its reach, now targeting 1,030 sites and 73 financial institutions. (Published on 2/3/2025, The Hacker News). &lt;a href="https://thehackernews.com/2025/02/coyote-malware-expands-reach-now.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 31 January 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-003/</link><pubDate>Wed, 31 Jan 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-003/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cybersecurity-news--emerging-threats"&gt;🔥 &lt;strong&gt;Cybersecurity News &amp;amp; Emerging Threats&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;From zero-day exploits to ransomware attacks, here’s what’s making waves in cybersecurity this week.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🍏 Apple patches the first actively exploited zero-day of 2025, targeting iPhone users. (Published on 1/27/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/apple-fixes-this-years-first-actively-exploited-zero-day-bug/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🚨 DeepSeek AI halts new user registrations after a large-scale cyberattack disrupts operations. (Published on 1/27/2025, Hackread). &lt;a href="https://hackread.com/deepseek-large-scale-cyberattack-halts-user-registrations/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 24 January 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-002/</link><pubDate>Wed, 24 Jan 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-002/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cybersecurity-breaches--attacks"&gt;🚨 Cybersecurity Breaches &amp;amp; Attacks&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🛠️ &lt;strong&gt;HPE investigates breach&lt;/strong&gt; as a hacker claims to have stolen sensitive documents from its developer environments. (Published on 1/20/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/hewlett-packard-enterprise-investigates-new-breach-claims/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🔓 &lt;strong&gt;PowerSchool data breach&lt;/strong&gt; exposes students’ and educators’ personal information in a December 2024 cyberattack. (Published on 1/21/2025, SecurityWeek). &lt;a href="https://www.securityweek.com/students-educators-impacted-by-powerschool-data-breach/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item></channel></rss>