<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Nation-State &amp; APT Activity on Jorge Laurel</title><link>https://jorgelaurel.com/topics/nation-state--apt-activity/</link><description>Recent content in Nation-State &amp; APT Activity on Jorge Laurel</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 27 Mar 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://jorgelaurel.com/topics/nation-state--apt-activity/index.xml" rel="self" type="application/rss+xml"/><item><title>Friday Wrap Up: 27 March 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-118/</link><pubDate>Fri, 27 Mar 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-118/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;This week: a pro-Iranian group hacked the FBI Director&amp;rsquo;s personal email. North Korean hackers got hired for remote IT jobs. TeamPCP backdoored yet another PyPI package. And an iPhone exploit kit has evolved directly from the zero-click campaign that hit Russian targets back in 2023.&lt;br&gt;
&lt;br&gt;
In the &amp;ldquo;things we didn&amp;rsquo;t need&amp;rdquo; column: GlassWorm now uses the Solana blockchain to route its malware payloads, a new infostealer bypasses Chrome&amp;rsquo;s Application-Bound Encryption, and a QR code phishing campaign somehow slipped past SPF, DKIM, AND DMARC at scale — 1.6 million emails delivered, no alarm raised.&lt;br&gt;
&lt;br&gt;
It&amp;rsquo;s a lot. Click through for 34 stories across 6 categories, and maybe patch your NetScaler while you&amp;rsquo;re at it.&lt;br&gt;
&lt;br&gt;
#FWU #fridaywrapup #SupplyChainSecurity #NationStateHackers #PatchNow #Malware #DataBreach #Ransomware&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 20 March 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-117/</link><pubDate>Fri, 20 Mar 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-117/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It’s Friday, which means the threat actors didn’t take the week off — and neither did we. 🛡️&lt;/p&gt;
&lt;p&gt;This week’s Friday Wrap Up covers ransomware gangs weaponizing zero-days, nation-state actors wiping devices at scale, supply-chain attacks hitting developer toolchains, AI platforms becoming the new attack surface, and a botnet that clearly skipped leg day because it never stops running. Whether you’re patching, detecting, or just trying to make it to 5pm, there’s something in this week’s roundup that probably affects your org.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 13 March 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-116/</link><pubDate>Fri, 13 Mar 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-116/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Happy Friday the 13th! 🔪 In the spirit of the day, threat actors did NOT hold back this week.&lt;/p&gt;
&lt;p&gt;We’ve got Chrome extensions that turned evil after changing hands, an AI agent that decided to mine crypto on its own (nobody asked, buddy 🤖⛏️), a medtech giant hit by Iranian hackers claiming to have wiped 200,000 devices, and a 1 petabyte data theft claim that made storage admins everywhere break into a cold sweat.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 6 March 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-115/</link><pubDate>Fri, 06 Mar 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-115/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Happy Friday, security professionals! 🔐&lt;/p&gt;
&lt;p&gt;This week in cybersecurity served up everything from drone strikes on cloud data centers (yes, physical ones) to hackers tapping FBI wiretap systems, AI assistants getting hijacked, and your car’s tire sensors moonlighting as surveillance tools.&lt;/p&gt;
&lt;p&gt;Nation-state actors from China, North Korea, and Iran were all running active campaigns. Critical vulnerabilities hit Android, Cisco firewalls, and iOS — while global law enforcement struck back, dismantling Tycoon 2FA, seizing LeakBase, and arresting a $46M crypto thief in Saint Martin (the vacation vibes did not help).&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 27 February 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-114/</link><pubDate>Fri, 27 Feb 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-114/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another Friday, another reason to question whether your apps, APIs, and Zoom calls are working for you — or someone else. 🛡️&lt;/p&gt;
&lt;p&gt;This week’s Friday Wrap Up covers ransomware hitting chip makers and medical device companies, China-linked spies repurposing Google Sheets as a command center (productivity hack of the year, unfortunately), North Korea expanding into healthcare ransomware, and a fake Zoom meeting that installs surveillance software before you finish your first sip of coffee.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 6 February 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-111/</link><pubDate>Fri, 06 Feb 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-111/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another supply chain nightmare. 🎢&lt;/p&gt;
&lt;p&gt;This week’s cybersecurity roundup features everything from compromised software updates (yes, even Notepad++) to record-breaking DDoS attacks that would make your infrastructure cry. We’ve got nation-state actors playing Olympics spoiler, fintech firms losing millions of records, and AI agents getting their own social network (because apparently they need friends too).&lt;/p&gt;
&lt;p&gt;Whether you’re defending against WinRAR exploits or wondering if your antivirus just became your biggest threat, this week had something for everyone.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 9 January 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-110/</link><pubDate>Fri, 09 Jan 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-110/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another wave of vulnerabilities keeping us on our toes!&lt;/p&gt;
&lt;p&gt;From nation-state hackers conducting global credential harvesting campaigns to fake AI Chrome extensions stealing nearly a million users’ data, this week proved cybersecurity professionals earn every bit of their coffee budget. Critical n8n vulnerabilities reached CVSS scores that made even hardened defenders nervous, while Chinese Salt Typhoon intrusions keep expanding in scope. Meanwhile, Disney learned that YouTube privacy violations cost $10M—turns out COPPA compliance isn’t optional.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 5 December 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-107/</link><pubDate>Fri, 05 Dec 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-107/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another reminder that cybercriminals are getting creative while defenders scramble to keep up! From malware disguising itself as helpful browser extensions to hackers learning poetry (yes, really) to break AI systems, this week had it all.&lt;/p&gt;
&lt;p&gt;We’re talking massive DDoS attacks breaking records, nation-states playing the long game with backdoors, and even an Aussie getting jail time for fake airport Wi-Fi. Plus, the eternal struggle continues: zero trust is still more “aspirational framework” than “accomplished mission” for most organizations.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 7 November 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-103/</link><pubDate>Fri, 07 Nov 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-103/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another wild week in cybersecurity where insider threats meet nation-state attacks, AI-powered malware rewrites itself hourly, and even our security pros are allegedly moonlighting with ransomware gangs. 🤦‍♂️&lt;/p&gt;
&lt;p&gt;From YouTube ghost networks spreading infostealers through fake videos to logic bombs hiding in code packages set to detonate in 2027 (mark your calendars!), the threat landscape keeps getting more creative—and concerning 😳 .&lt;/p&gt;
&lt;p&gt;The Congressional Budget Office got breached, Samsung phones were compromised via malicious images, and ChatGPT vulnerabilities could leak your AI conversations. Meanwhile, the cybercrime equivalent of a corporate merger just happened with three major gangs joining forces 💸 .&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 17 October 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-100/</link><pubDate>Fri, 17 Oct 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-100/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another wild week in cybersecurity! From nation-state actors breaching major tech companies to botnets going global, hackers weren’t taking any days off.&lt;/p&gt;
&lt;p&gt;We’ve got everything from AI guardrails getting schooled by basic prompt injection to a vulnerability so severe Microsoft had to break out their highest-ever severity score. Oh, and YouTube decided to take a little nap this week too.&lt;/p&gt;
&lt;p&gt;Cybersecurity stories covering everything from malware hiding in GitHub images to North Korean job scams that would make your HR department cry. Check out the full roundup to see what kept security teams caffeinated this week.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 10 October 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-099/</link><pubDate>Fri, 10 Oct 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-099/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another ransomware alliance, and somehow your mouse might be eavesdropping on you now. 🖱️👂&lt;/p&gt;
&lt;p&gt;From fake Discord alerts stealing vault credentials to North Korean hackers pocketing $2B in crypto, this week proves that cybercriminals are nothing if not creative (and disturbingly well-funded). Meanwhile, the FBI took down BreachForums and Google’s AI is learning to patch code before attackers can exploit it.&lt;/p&gt;
&lt;p&gt;The cybersecurity world never sleeps, and honestly, neither should your security team after reading this. Click through for the full rundown of breaches, malware, and the latest “why-is-that-even-possible” attack vectors.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 12 September 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-095/</link><pubDate>Fri, 12 Sep 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-095/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;💥 This week in cyber was one for the history books.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;📦 The world’s largest supply chain attack hit npm, with billions of downloads tainted.&lt;br&gt;
⚡ Nation-state espionage escalated as China-linked groups ramped up campaigns tied to trade negotiations.&lt;br&gt;
💻 Ransomware evolved yet again, with &lt;strong&gt;HybridPetya&lt;/strong&gt; breaking UEFI Secure Boot and Akira exploiting SonicWall appliances.&lt;br&gt;
📱 Meanwhile, Samsung scrambled to patch a WhatsApp-linked zero-day, and Apple unveiled a five-year project to shut down spyware developers.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 22 August 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-092/</link><pubDate>Fri, 22 Aug 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-092/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;🚨 Major Cyberattacks &amp;amp; Data Breaches&lt;/strong&gt; This week saw breaches across industries — from HR platforms to healthcare — showing how attackers continue to exploit trusted systems.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;👔 Workday discloses data breach linked to Salesforce attacks (Published on 8/18/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/hr-giant-workday-discloses-data-breach-amid-salesforce-attacks/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🍔 Hacker finds flaws in McDonald’s staff &amp;amp; partner hubs, exposing APIs and sensitive documents (Published on 8/20/2025, Dark Reading). &lt;a href="https://www.darkreading.com/cybersecurity-operations/hacker-finds-flaws-mcdonalds-staff-partner-hubs"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 15 Aug 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-091/</link><pubDate>Fri, 15 Aug 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-091/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚨 Friday Wrap Up highlights this week&lt;/p&gt;
&lt;p&gt;From cars remotely unlocked to state-backed hacks — attackers didn’t take a summer break.&lt;/p&gt;
&lt;p&gt;🚗 Car dealership portal flaw let anyone unlock vehicles remotely.&lt;/p&gt;
&lt;p&gt;🏛 Russian hackers breached U.S. federal court filing system.&lt;/p&gt;
&lt;p&gt;🛠 Microsoft patched Kerberos zero-day; Cisco fixed CVSS 10 flaw.&lt;/p&gt;
&lt;p&gt;🕵️ Crypto24 ransomware using custom EDR evasion tools.&lt;/p&gt;
&lt;p&gt;📻 TETRA radio encryption flaws exposed law enforcement comms.&lt;/p&gt;
&lt;p&gt;💾 Hackers leaked 9GB from alleged North Korean hacker’s PC.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 27 June 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-084/</link><pubDate>Fri, 27 Jun 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-084/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cyber-threats--state-linked-activity"&gt;🛡️ Cyber Threats &amp;amp; State-Linked Activity&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🕵️ Salt Typhoon hacks a Canadian telecom using Cisco flaws, confirming China-linked espionage. (Published on 6/23/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/canada-says-salt-typhoon-hacked-telecom-firm-via-cisco-flaw/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🚨 Salt Typhoon exploits router flaws to spy on global telecoms, FBI and Canada warn. (Published on 6/23/2025, Hackread). &lt;a href="https://hackread.com/salt-typhoon-targets-telecoms-router-flaws-fbi-canada/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🐺 Chinese group Silver Fox uses fake websites to spread Sainbox RAT and hidden rootkit. (Published on 6/27/2025, The Hacker News). &lt;a href="https://thehackernews.com/2025/06/chinese-group-silver-fox-uses-fake.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 13 June 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-082/</link><pubDate>Fri, 13 Jun 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-082/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;This week’s Friday Wrap-Up brings a dense mix of cyber drama and tech evolution: from state-sponsored exploits and zero-click spyware to novel threats using smartwatches.&lt;/p&gt;
&lt;p&gt;Big tech players like Meta and Google are making AI splashes, while law enforcement cracks down on massive malware networks. Catch the highlights, breaches, patches, and pivots in one place—because your inbox deserves clarity. Click through for the full update!&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cyber-espionage--nation-state-activity"&gt;&lt;strong&gt;Cyber Espionage &amp;amp; Nation-State Activity&lt;/strong&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🚫 OpenAI bans ChatGPT accounts tied to nation-state actors using AI for espionage and fraud (Published on 6/9/2025, Dark Reading). &lt;a href="https://www.darkreading.com/threat-intelligence/openai-bans-chatgpt-accounts-nation-state-threat-actors"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 30 May 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-080/</link><pubDate>Fri, 30 May 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-080/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;This week’s cyber headlines are packed with breaches, bots, BitM attacks, and even a courtroom confession. Dive into the Friday Wrap-Up to stay ahead—and maybe even stay safe. 🧠🛡️&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-threats--malware-attacks"&gt;&lt;strong&gt;Cybersecurity Threats &amp;amp; Malware Attacks&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;This week brought an array of fresh threats and major disclosures:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;⚠️ Over 70 malicious npm and VS Code packages steal user data and crypto via Discord endpoints. (Published on 5/26/2025, The Hacker News). &lt;strong&gt;&lt;a href="https://thehackernews.com/2025/05/over-70-malicious-npm-and-vs-code.html"&gt;Read More&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 18 April 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-075/</link><pubDate>Fri, 18 Apr 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-075/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;From rogue restarts in Windows Server 2025 to ransomware giving dialysis clinics a real headache, this week was anything but quiet.&lt;/p&gt;
&lt;p&gt;State-backed hackers were busy playing malware bingo, Fortinet and Cisco had some uninvited guests, and 4chan may have just been out-trolled by a rival forum (yes, really).&lt;/p&gt;
&lt;p&gt;Meanwhile, AI continues its sneaky takeover—half of your coworkers are probably using unapproved tools, and Google’s swatting down billions of bad ads like it’s a high-stakes arcade game.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 28 March 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-072/</link><pubDate>Fri, 28 Mar 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-072/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;🛡️ Cyberattack Campaigns &amp;amp; Threat Actor Activity&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;A surge in advanced persistent threats and ransomware highlights the evolving cybercrime landscape.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🐜 Chinese Weaver Ant hackers infiltrated a telecom network for over 4 years using compromised Zyxel routers. (Published on 3/24/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/chinese-weaver-ant-hackers-spied-on-telco-network-for-4-years/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🧬 Medusa ransomware disables EDR tools using stolen certificates for stealthy system takeovers. (Published on 3/25/2025, Hackread). &lt;a href="https://hackread.com/medusa-ransomware-anti-malware-tools-stolen-certificates/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 14 March 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-070/</link><pubDate>Fri, 14 Mar 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-070/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-threats--incidents-"&gt;&lt;strong&gt;Cybersecurity Threats &amp;amp; Incidents&lt;/strong&gt; 🔥&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🚨 &lt;strong&gt;Americans lost a record $12.5 billion to fraud in 2024&lt;/strong&gt;, marking a 25% increase from the previous year. (Published on 3/10/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/us-govt-says-americans-lost-record-125-billion-to-fraud-in-2024/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🏴‍☠️ A &lt;strong&gt;former employee was found guilty of a revenge kill-switch scheme&lt;/strong&gt;, locking out users if their account was disabled. (Published on 3/10/2025, Dark Reading). &lt;a href="https://www.darkreading.com/cyberattacks-data-breaches/ex-employee-guilty-revenge-kill-switch-scheme"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 28 February 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-068/</link><pubDate>Fri, 28 Feb 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-068/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cybersecurity-threats--attacks"&gt;🚨 Cybersecurity Threats &amp;amp; Attacks&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🎭 Hackers exploit Google Docs and Steam to spread ACRStealer, a new infostealer malware targeting users via trusted platforms. (Published on 2/24/2025, Hackread). &lt;a href="https://hackread.com/hackers-google-docs-steam-drop-acrstealer-infostealer/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🔍 OpenAI bans ChatGPT accounts linked to Chinese threat actors who allegedly used the AI model for espionage tool development. (Published on 2/24/2025, SecurityWeek). &lt;a href="https://www.securityweek.com/openai-bans-chatgpt-accounts-used-by-chinese-group-for-spy-tools/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 21 February 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-067/</link><pubDate>Fri, 21 Feb 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-067/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cybersecurity-threats--exploits"&gt;🛡️ Cybersecurity Threats &amp;amp; Exploits&lt;/h3&gt;
&lt;p&gt;Cyberattacks are evolving, with new malware, vulnerabilities, and nation-state threats emerging. Stay informed and vigilant!&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🛑 &lt;strong&gt;Microsoft detects a new XCSSET macOS malware variant&lt;/strong&gt; targeting sensitive user data, including crypto wallets and Notes app content. (Published on 2/17/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/microsoft-spots-xcsset-macos-malware-variant-used-for-crypto-theft/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 14 February 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-066/</link><pubDate>Fri, 14 Feb 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-066/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;💘 &lt;strong&gt;Roses are red, violets are blue, cyber threats don’t care… and they’re coming for you!&lt;/strong&gt; 💘&lt;/p&gt;
&lt;p&gt;This Valentine’s Day, while some are finding love, others are finding &lt;strong&gt;zero-days, ransomware, and nation-state hackers&lt;/strong&gt;. Here’s a &lt;strong&gt;cybersecurity love stories&lt;/strong&gt; you don’t want to be part of:&lt;/p&gt;
&lt;h3 id="latest-cybersecurity-threats-and-vulnerabilities"&gt;🔥 Latest Cybersecurity Threats and Vulnerabilities&lt;/h3&gt;
&lt;p&gt;From zero-days to AI exploits, attackers are finding new ways to break into systems. Stay updated on the latest security risks.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 10 January 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-058/</link><pubDate>Fri, 10 Jan 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-058/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-threats-and-attacks"&gt;&lt;strong&gt;Cybersecurity Threats and Attacks&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;These stories highlight the latest cybersecurity threats, including malware, nation-state hacks, and unconventional attack methods.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🛡️ FireScam malware disguises itself as &amp;ldquo;Telegram Premium&amp;rdquo; to steal data and maintain remote control of Android devices. Stay vigilant! (Published on 1/6/2025, The Hacker News). &lt;a href="https://thehackernews.com/2025/01/firescam-android-malware-poses-as.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 3 January 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-057/</link><pubDate>Fri, 03 Jan 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-057/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-breaches-and-incidents"&gt;Cybersecurity Breaches and Incidents&lt;/h3&gt;
&lt;p&gt;🔒 &lt;strong&gt;Chinese state-sponsored hackers breached the U.S. Treasury Department&lt;/strong&gt; via a remote support platform. (Published on 12/30/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/us-treasury-department-breached-through-remote-support-platform/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🚘 &lt;strong&gt;Volkswagen, Audi, and Skoda EV owners affected by a major data breach&lt;/strong&gt; tracking over 800,000 vehicles. (Published on 12/30/2024, Hackread). &lt;a href="https://hackread.com/exposed-cloud-server-tracks-volkswagen-audi-skoda-evs/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 27 December 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-056/</link><pubDate>Fri, 27 Dec 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-056/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h4 id="threat-actors-and-malware"&gt;&lt;strong&gt;Threat Actors and Malware&lt;/strong&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🎯 Lazarus Group targets the nuclear industry using CookiePlus malware. Critical threat intelligence updates shared by Kaspersky. (Published on 12/23/2024, Hackread). &lt;a href="https://hackread.com/lazarus-group-nuclear-industry-cookieplus-malware/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🐱 Iran’s Charming Kitten deploys BellaCPP, a C++ variant of the BellaCiao malware, increasing its attack sophistication. (Published on 12/25/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/12/irans-charming-kitten-deploys-bellacpp.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 29 November 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-053/</link><pubDate>Fri, 29 Nov 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-053/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-threats-and-exploits"&gt;Cybersecurity Threats and Exploits&lt;/h3&gt;
&lt;p&gt;Key updates on critical vulnerabilities and sophisticated hacking campaigns targeting diverse platforms worldwide.&lt;/p&gt;
&lt;p&gt;🔓 mySCADA patches critical vulnerabilities in myPRO systems, which allowed remote unauthenticated system takeovers. (Published on 11/25/2024, SecurityWeek). &lt;a href="https://www.securityweek.com/vulnerabilities-expose-myscada-mypro-systems-to-remote-hacking/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🛡 Malware leveraging BYOVD techniques uses Avast’s anti-rootkit driver to disable antivirus protections. (Published on 11/25/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/11/researchers-uncover-malware-using-byovd.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 15 November 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-051/</link><pubDate>Fri, 15 Nov 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-051/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-threats-and-exploits"&gt;Cybersecurity Threats and Exploits&lt;/h3&gt;
&lt;p&gt;Emerging cyber threats and vulnerabilities that highlight the evolving tactics of attackers targeting various platforms and industries.&lt;/p&gt;
&lt;p&gt;🛠 Revamped Remcos RAT targets Microsoft Windows users, exploiting known RCE vulnerabilities in Microsoft Office and WordPad. (Published on 11/11/2024, Dark Reading). &lt;a href="https://www.darkreading.com/application-security/revamped-remcos-rat-microsoft-windows-users"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 18 October 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-048/</link><pubDate>Fri, 18 Oct 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-048/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="cybersecurity-updates"&gt;Cybersecurity Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🔐 Supply chain attacks exploit entry points in open-source ecosystems like Python and npm, posing a widespread risk. (Published on 10/14/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/10/supply-chain-attacks-exploit-entry.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🖥️ Iranian cyberspies are exploiting a recent Windows kernel vulnerability, targeting Gulf region organizations. (Published on 10/14/2024, SecurityWeek). &lt;a href="https://www.securityweek.com/iranian-cyberspies-exploiting-recent-windows-kernel-vulnerability/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 11 October 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-047/</link><pubDate>Fri, 11 Oct 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-047/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-breaches"&gt;Cybersecurity Breaches&lt;/h3&gt;
&lt;p&gt;🚨 ADT discloses a second breach within two months, with attackers gaining access using stolen credentials to exfiltrate employee account data. (Published on 10/7/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/adt-discloses-second-breach-in-2-months-hacked-via-stolen-credentials/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🚨 LEGO’s website was hacked by cryptocurrency scammers promoting a fake Lego token that could be purchased with Ethereum. (Published on 10/7/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/legos-website-hacked-to-push-cryptocurrency-scam/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 30 August 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-041/</link><pubDate>Fri, 30 Aug 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-041/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="cybersecurity-incidents-and-alerts"&gt;Cybersecurity Incidents and Alerts:&lt;/h2&gt;
&lt;p&gt;🚨 &lt;strong&gt;Seattle-Tacoma Airport cyberattack&lt;/strong&gt; disrupts IT systems, causing flight delays and reservation check-in issues. (Published on 8/26/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/seattle-tacoma-airport-it-systems-down-due-to-a-cyberattack/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;👥 &lt;strong&gt;750M fake Microsoft accounts created&lt;/strong&gt; as cybercriminals exploit Greasy Opal to bypass security measures. (Published on 8/26/2024, Dark Reading). &lt;a href="https://www.darkreading.com/cyberattacks-data-breaches/cybercriminals-tap-greasy-opal-to-create-750m-fake-microsoft-accounts"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔒 &lt;strong&gt;Patelco Credit Union data breach&lt;/strong&gt; impacts 726,000 customers due to a ransomware attack. (Published on 8/26/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/patelco-notifies-726-000-customers-of-ransomware-data-breach/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 22 August 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-039/</link><pubDate>Thu, 22 Aug 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-039/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Cars weren’t the only things being unlocked — patient records, HR data, and even McDonald’s portals were on the menu.&lt;/p&gt;
&lt;p&gt;Meanwhile, governments went after ransomware wallets, AI browsers went shopping on their own, and TikTok replaced moderators with algorithms.&lt;/p&gt;
&lt;p&gt;🔍 From zero-days to fake Europol rewards, this week proves one thing: cyber never sleeps (but maybe TikTok’s moderators finally will).&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;🚨 Major Cyberattacks &amp;amp; Data Breaches&lt;/strong&gt; This week saw breaches across industries — from HR platforms to healthcare — showing how attackers continue to exploit trusted systems.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 12 July 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-033/</link><pubDate>Fri, 12 Jul 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-033/</guid><description>&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/strong&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚨 A remote code execution bug in Ghostscript is being actively exploited on Linux systems. Stay alert! (Published on 7/8/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/rce-bug-in-widely-used-ghostscript-library-now-exploited-in-attacks/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;💻 Emerging RaaS operation &amp;lsquo;Eldorado&amp;rsquo; targets both Windows and Linux systems with encryption locker variants. (Published on 7/8/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/07/new-ransomware-as-service-eldorado.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔍 The &amp;lsquo;CloudSorcerer&amp;rsquo; APT leverages cloud services in a sophisticated cyber-espionage campaign. (Published on 7/8/2024, Dark Reading). &lt;a href="https://www.darkreading.com/cloud-security/cloudsorceror-public-cloud-cyberespionage-campaign"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 4 July 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-031/</link><pubDate>Thu, 04 Jul 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-031/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="-happy-4th-of-july-"&gt;🎇 Happy 4th of July! 🇺🇸&lt;/h2&gt;
&lt;p&gt;While you’re watching fireworks, the cybersecurity world isn’t taking a holiday. From Iranian cyber threats and a Norwegian dam hack to Google’s $314M data verdict, Chrome zero-days, and Microsoft layoffs despite record profits, it’s a busy Independence Week in tech.&lt;/p&gt;
&lt;p&gt;Stay sharp, stay patched, and don’t let your systems party too hard without monitoring. 🚀&lt;/p&gt;
&lt;p&gt;Catch all these stories and more in our Friday Wrap-Up below to stay informed without burning out.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 27 June 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-029/</link><pubDate>Thu, 27 Jun 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-029/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another buffet of breaches, botnets, and bureaucratic advisories! 🍽️&lt;/p&gt;
&lt;p&gt;The FBI unmasked IntelBroker using email trails, crypto wallets, and YouTube activity, reminding us that your “anonymous” OPSEC is only as good as your weakest Like button 👍.&lt;/p&gt;
&lt;p&gt;If you’re feeling overwhelmed, you’re not alone. The pace of attacks continues to remind us that no matter how strong your defenses, there’s always a misconfigured Docker API somewhere ready to turn into a crypto-mining hotspot. 🐈‍⬛💻&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 21 June 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-028/</link><pubDate>Fri, 21 Jun 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-028/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚨 Hackers use F5 BIG-IP malware to stealthily steal data for years. Stay alert! (Published on 6/17/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/hackers-use-f5-big-ip-malware-to-stealthily-steal-data-for-years/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;⚖️ Empire Market owners charged for enabling $430M in dark web transactions. Legal repercussions ahead! (Published on 6/17/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/legal/empire-market-owners-charged-for-enabling-430m-in-dark-web-transactions/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔧 ASUS patches critical authentication bypass flaw in multiple router models. Update your devices! (Published on 6/17/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/06/asus-patches-critical-authentication.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Saturday Wrap Up: 11 May 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-020/</link><pubDate>Sat, 11 May 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-020/</guid><description>&lt;hr&gt;
&lt;p&gt;This week&amp;rsquo;s Friday Wrap Up is going to be &lt;strong&gt;Saturday&lt;/strong&gt; Wrap Up. I spent the week at RSA and arrived back on the east coast yesterday evening and decided to relax after the coast to coast flight. If you were at RSA all week, you know what I&amp;rsquo;m talking about!&lt;/p&gt;
&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/44553eb2e3034052.png" alt=""&gt;&lt;/p&gt;
&lt;p&gt;A real working Enigma that was on display at the NSA booth in the South Hall. Thank you to National Cryptologic Museum for having it on display and having a museum curator on hand to give a history of the Enigma to anyone that asked.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 26 April 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-017/</link><pubDate>Fri, 26 Apr 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-017/</guid><description>&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/strong&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🌐 MITRE, renowned for its cybersecurity frameworks, was compromised using MITRE techniques and Ivanti bugs (Published on 4/22/2024, Dark Reading). &lt;a href="https://www.darkreading.com/endpoint-security/mitre-attacked-infosecs-most-trusted-name-falls-to-ivanti-bugs"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🖨️ Russia&amp;rsquo;s APT28 targeted Windows Print Spooler to introduce &amp;lsquo;GooseEgg&amp;rsquo; malware, unknown until now (Published on 4/22/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/04/russias-apt28-exploited-windows-print.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🕵️♂️ ToddyCat hackers exploit advanced tools to steal data from governments on an industrial scale (Published on 4/22/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/04/russian-hacker-group-toddycat-uses.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 28 March 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-012/</link><pubDate>Thu, 28 Mar 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-012/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another batch of cyber drama that makes you question every login form you&amp;rsquo;ve ever seen.&lt;/p&gt;
&lt;p&gt;Chinese threat actors camped out in a telco network for four years like it was their personal Airbnb, while a critical Next.js vulnerability quietly said, “Authorization? Never heard of her.”&lt;/p&gt;
&lt;p&gt;Meanwhile, ransomware crews are out here disabling anti-malware tools with stolen certs—because apparently, &lt;em&gt;revoked&lt;/em&gt; doesn&amp;rsquo;t mean &lt;em&gt;useless&lt;/em&gt;. And Kubernetes? Let’s just say 40% of clusters are living dangerously, thanks to the aptly named “IngressNightmare.”&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 22 March 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-011/</link><pubDate>Fri, 22 Mar 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-011/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Saturday aka Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🔐 Microsoft steps up security, deprecating 1024-bit RSA keys in Windows TLS. A significant move! (3/18/2024, BleepingComputer) &lt;a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-announces-deprecation-of-1024-bit-rsa-keys-in-windows/"&gt;Read more&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🌏 Chinese &amp;lsquo;Earth Krahang&amp;rsquo; hackers breach 70 orgs in a global campaign. (3/18/2024, BleepingComputer) &lt;a href="https://www.bleepingcomputer.com/news/security/chinese-earth-krahang-hackers-breach-70-orgs-in-23-countries/"&gt;Read more&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;💻 Malware distributed via fake Google Sites using HTML smuggling technique. Beware! (3/18/2024, The Hacker News) &lt;a href="https://thehackernews.com/2024/03/hackers-using-sneaky-html-smuggling-to.html"&gt;Read more&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up for 1 March 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-008/</link><pubDate>Fri, 01 Mar 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-008/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;p&gt;🚨 LockBitSupp talks to law enforcement post-ransomware takedown. (2/25/2024, The Hacker News, &lt;a href="https://thehackernews.com/2024/02/authorities-claim-lockbit-admin.html"&gt;https://thehackernews.com/2024/02/authorities-claim-lockbit-admin.html&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;👶 Florida&amp;rsquo;s new bill against youth on social media. 2/25/2024, NY Times, &lt;a href="https://www.nytimes.com/2024/02/23/business/florida-social-media-youths.html"&gt;https://www.nytimes.com/2024/02/23/business/florida-social-media-youths.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;💸 Apple&amp;rsquo;s Vision Pro cost breakdown sparks returns. 2/25/2024, 9to5mac, &lt;a href="https://9to5mac.com/2024/02/25/heres-how-much-it-costs-apple-to-make-the-3500-vision-pro/"&gt;https://9to5mac.com/2024/02/25/heres-how-much-it-costs-apple-to-make-the-3500-vision-pro/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🌍 Five Eyes detail Russian cyberespionage in clouds. 2/26/2024, CyberScoop, &lt;a href="https://cyberscoop.com/five-eyes-nations-warn-of-evolving-russian-cyberespionage-practices-targeting-cloud-environments/"&gt;https://cyberscoop.com/five-eyes-nations-warn-of-evolving-russian-cyberespionage-practices-targeting-cloud-environments/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;📧 Massive email spam from SubdoMailing campaign. 2/26/2024, BleepingComputer, &lt;a href="https://www.bleepingcomputer.com/news/security/subdomailing-campaign-spams-5-million-emails-daily-via-8k-hijacked-domains/"&gt;https://www.bleepingcomputer.com/news/security/subdomailing-campaign-spams-5-million-emails-daily-via-8k-hijacked-domains/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 28 February 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-007/</link><pubDate>Wed, 28 Feb 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-007/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cybersecurity-threats--attacks"&gt;🚨 Cybersecurity Threats &amp;amp; Attacks&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🎭 Hackers exploit Google Docs and Steam to spread ACRStealer, a new infostealer malware targeting users via trusted platforms. (Published on 2/24/2025, Hackread). &lt;a href="https://hackread.com/hackers-google-docs-steam-drop-acrstealer-infostealer/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🔍 OpenAI bans ChatGPT accounts linked to Chinese threat actors who allegedly used the AI model for espionage tool development. (Published on 2/24/2025, SecurityWeek). &lt;a href="https://www.securityweek.com/openai-bans-chatgpt-accounts-used-by-chinese-group-for-spy-tools/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 21 February 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-006/</link><pubDate>Wed, 21 Feb 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-006/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cybersecurity-threats--exploits"&gt;🛡️ &lt;strong&gt;Cybersecurity Threats &amp;amp; Exploits&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Cyberattacks are evolving, with new malware, vulnerabilities, and nation-state threats emerging. Stay informed and vigilant!&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🛑 &lt;strong&gt;Microsoft detects a new XCSSET macOS malware variant&lt;/strong&gt; targeting sensitive user data, including crypto wallets and Notes app content. (Published on 2/17/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/microsoft-spots-xcsset-macos-malware-variant-used-for-crypto-theft/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 14 February 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-005/</link><pubDate>Wed, 14 Feb 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-005/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;💘 &lt;strong&gt;Roses are red, violets are blue, cyber threats don’t care… and they’re coming for you!&lt;/strong&gt; 💘&lt;/p&gt;
&lt;p&gt;This Valentine’s Day, while some are finding love, others are finding &lt;strong&gt;zero-days, ransomware, and nation-state hackers&lt;/strong&gt;. Here’s a &lt;strong&gt;cybersecurity love stories&lt;/strong&gt; you don’t want to be part of:&lt;/p&gt;
&lt;h3 id="-latest-cybersecurity-threats-and-vulnerabilities"&gt;🔥 Latest Cybersecurity Threats and Vulnerabilities&lt;/h3&gt;
&lt;p&gt;From zero-days to AI exploits, attackers are finding new ways to break into systems. Stay updated on the latest security risks.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 7 February 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-004/</link><pubDate>Wed, 07 Feb 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-004/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cybersecurity-news--threats"&gt;🔥 &lt;strong&gt;Cybersecurity News &amp;amp; Threats&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;From AI impersonation to major vulnerabilities, here’s what’s shaping cybersecurity this week.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🎭 DeepSeek AI tools are being impersonated on PyPI by infostealer malware targeting developers. (Published on 2/3/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/deepseek-ai-tools-impersonated-by-infostealer-malware-on-pypi/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🏦 The Coyote banking trojan expands its reach, now targeting 1,030 sites and 73 financial institutions. (Published on 2/3/2025, The Hacker News). &lt;a href="https://thehackernews.com/2025/02/coyote-malware-expands-reach-now.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item></channel></rss>