<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Phishing &amp; Social Engineering on Jorge Laurel</title><link>https://jorgelaurel.com/topics/phishing--social-engineering/</link><description>Recent content in Phishing &amp; Social Engineering on Jorge Laurel</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 05 Aug 2026 18:54:26 +0000</lastBuildDate><atom:link href="https://jorgelaurel.com/topics/phishing--social-engineering/index.xml" rel="self" type="application/rss+xml"/><item><title>The Agent Went Off Script And A Human Reviewer Stopped It.</title><link>https://jorgelaurel.com/writing/the-agent-went-off-script-and-a-human-reviewer-stopped-it/</link><pubDate>Wed, 05 Aug 2026 18:54:26 +0000</pubDate><guid>https://jorgelaurel.com/writing/the-agent-went-off-script-and-a-human-reviewer-stopped-it/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/writing/41c6b23ea896074e.png" alt="The Agent Went Off Script And A Human Reviewer Stopped It."&gt;&lt;/p&gt;
&lt;p&gt;On 28 July 2026, the UK AI Security Institute saw data leaving one of its research systems over Tor. Within an hour, every related evaluation was terminated, the machines were isolated, and a security incident was declared. The investigation that followed did not find a sandbox escape. It found something less familiar: AI agents under test taking sustained, unsanctioned action against real people and real organizations on the live internet.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 20 February 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-113/</link><pubDate>Fri, 20 Feb 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-113/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another reminder that the internet is basically a haunted house and someone keeps adding new rooms. 🏚️&lt;/p&gt;
&lt;p&gt;This week’s Friday Wrap Up covers data breaches hitting your wallet and your wardrobe, Android malware clever enough to use Google’s own AI against you, Chrome zero-days being actively exploited, fake AI tools fooling a quarter million users, and OAuth phishing attacks that let hackers waltz through MFA like they own the place.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 19 December 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-109/</link><pubDate>Fri, 19 Dec 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-109/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;The Friday Wrap Up is taking a holiday break 🎄&lt;/p&gt;
&lt;p&gt;After 50 weeks of doom-scrolling through CVEs, data breaches, and supply chain incidents, the FWU is officially logging off until 2026.&lt;/p&gt;
&lt;p&gt;Yes, 2026. The FWU will be back with more threat intelligence, more zero-days, and probably another ransomware group with a questionable naming convention.&lt;/p&gt;
&lt;p&gt;What to expect during the FWU break:&lt;/p&gt;
&lt;p&gt;• Threat actors will continue working (they don’t believe in work-life balance)&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 14 November 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-104/</link><pubDate>Fri, 14 Nov 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-104/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another wild week in cybersecurity! From PhaaS platforms targeting M365 to ransomware groups naming victims, Russian IABs pleading guilty, and a chipmaker publishing 60+ vuln patches—it’s been eventful.&lt;/p&gt;
&lt;p&gt;We’ve got nation-state espionage campaigns, supply chain nightmares, fake travel sites stealing payment data, and even Android photo frames shipping with malware. Plus, the passwordless dream keeps hitting reality checks while Microsoft rushes fixes for Windows 10 stragglers.&lt;/p&gt;
&lt;p&gt;Check out this week’s Friday Wrap Up for the full breakdown!&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 03 October 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-098/</link><pubDate>Fri, 03 Oct 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-098/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another parade of cyber shenanigans that make you wonder if the internet needs a timeout. From ransomware gangs sliding into BBC reporters’ DMs with job offers (seriously), to AI tools making phishing easier than ordering takeout, it’s been quite the ride.&lt;/p&gt;
&lt;p&gt;We’ve got everything from government shutdowns creating security gaps you could drive a truck through, to hackers apologizing for posting kids’ photos (because even cybercriminals have PR nightmares). Plus, Meta wants to monetize your AI chats, because why not add targeted ads to your robot conversations?&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 19 September 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-096/</link><pubDate>Fri, 19 Sep 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-096/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another collection of cyber chaos! From luxury fashion brands getting their digital wardrobes raided to AI tools that apparently graduated from &amp;ldquo;Hacking 101&amp;rdquo; with honors, the threat landscape continues its creative evolution.&lt;/p&gt;
&lt;p&gt;This week&amp;rsquo;s highlights include some particularly audacious impersonation schemes (fake FBI portals, anyone?), memory attacks that work faster than your morning coffee kicks in, and evidence that retirement announcements from cybercriminals should be taken with the same grain of salt as your uncle&amp;rsquo;s fishing stories.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 25 July 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-088/</link><pubDate>Fri, 25 Jul 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-088/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;This week, it’s cyber whack-a-mole: one forum admin down, another mirror site up. Meanwhile, malware gets cuddly (hi, pandas 🐼), and brands like Microsoft remain prime phishing bait.&lt;/p&gt;
&lt;p&gt;A dash of espionage, a pinch of legal drama, and a travel scam twist—because hackers need vacations too.&lt;/p&gt;
&lt;p&gt;👇 Dive in for the full roundup before your inbox gets spoofed.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="major-cyberattacks--incidents"&gt;&lt;strong&gt;Major Cyberattacks &amp;amp; Incidents&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Breaches, takedowns, and court battles highlight the ever-evolving cyber threat landscape.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 20 June 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-083/</link><pubDate>Fri, 20 Jun 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-083/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="ransomware--backup-threats"&gt;Ransomware &amp;amp; Backup Threats&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;💀 New Anubis ransomware encrypts and permanently wipes files—recovery impossible even after payment. (Published on 6/16/2025, The Hacker News). &lt;a href="https://thehackernews.com/2025/06/anubis-ransomware-encrypts-and-wipes.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🔄 Ransomware gangs now target backup infrastructures first to cripple recovery options. (Published on 6/17/2025, The Hacker News). &lt;a href="https://thehackernews.com/2025/06/how-to-protect-your-backups-from-ransomware-attacks.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;💾 Chain IQ and UBS data stolen in a ransomware attack claiming millions of files exfiltrated. (Published on 6/19/2025, SecurityWeek). &lt;a href="https://www.securityweek.com/chain-iq-ubs-data-stolen-in-ransomware-attack/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 2 May 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-077/</link><pubDate>Fri, 02 May 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-077/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;From phishing rings to AI-written code, it&amp;rsquo;s been another week in cybersecurity where the only constant is everything’s on fire 🔥.&lt;/p&gt;
&lt;p&gt;This week’s Friday Wrap Up features:&lt;/p&gt;
&lt;p&gt;- Cybercriminals getting busted (some, not all—let&amp;rsquo;s not get crazy),&lt;/p&gt;
&lt;p&gt;- Zero-days popping like popcorn 🍿,&lt;/p&gt;
&lt;p&gt;- Space hacking (yes, literally),&lt;/p&gt;
&lt;p&gt;- AI quietly taking over dev jobs,&lt;/p&gt;
&lt;p&gt;- And government agencies asking, &amp;ldquo;Secure by Design—was that just a phase?&amp;rdquo;&lt;/p&gt;
&lt;p&gt;If your cloud is leaking secrets, your CMS is under siege, or you&amp;rsquo;re wondering how ransomware gangs pivot after a breakup&amp;hellip; we’ve got you covered.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 25 April 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-076/</link><pubDate>Fri, 25 Apr 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-076/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🎉 This Week in Cyber: From AI Phishing to ATM Hacking – We’ve Seen It All&lt;/p&gt;
&lt;p&gt;If you thought cybercriminals might slow down in April… plot twist! 😅&lt;/p&gt;
&lt;p&gt;This week’s headlines brought:&lt;/p&gt;
&lt;p&gt;- AI-powered phishing toolkits that scale scams faster than startups scale servers 🤖💸&lt;/p&gt;
&lt;p&gt;- Ransomware attacks hitting hospitals, cities, and schools — because clearly nothing is sacred anymore 🏥🏛️&lt;/p&gt;
&lt;p&gt;- Spoofed emails that even Google thought were legit 🫣&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 4 April 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-073/</link><pubDate>Fri, 04 Apr 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-073/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It’s been a busy week in cybersecurity — the kind that makes your firewall sweat and your SOC team rethink their life choices.&lt;/p&gt;
&lt;p&gt;From phishing-as-a-service platforms like Lucid going global with their spammy ambitions, to malware dressing up in stealth mode and pretending it’s just “advanced persistence,” attackers are working overtime.&lt;/p&gt;
&lt;p&gt;Meanwhile, vulnerabilities in everything from solar tech to AI platforms remind us that no codebase is safe from bugs (especially the kind that moonlight as backdoors).&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 7 March 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-069/</link><pubDate>Fri, 07 Mar 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-069/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="-cybersecurity-incidents--threats"&gt;🔥 Cybersecurity Incidents &amp;amp; Threats&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🔑 &lt;strong&gt;Rubrik rotates authentication keys after log server breach&lt;/strong&gt; – A breach in Rubrik’s log server led to the rotation of potentially leaked authentication keys. (Published on 3/3/2025, Bleeping Computer). &lt;a href="https://www.bleepingcomputer.com/news/security/rubrik-rotates-authentication-keys-after-log-server-breach/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🎭 &lt;strong&gt;North Korean fake IT workers pose as blockchain developers&lt;/strong&gt; – Fraudulent personas on GitHub are helping North Korean operatives secure blockchain development jobs in the U.S. and Japan. (Published on 3/5/2025, SecurityWeek). &lt;a href="https://www.securityweek.com/north-korean-fake-it-workers-pose-as-blockchain-developers-on-github/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 7 February 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-065/</link><pubDate>Fri, 07 Feb 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-065/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cybersecurity-news--threats"&gt;🔥 Cybersecurity News &amp;amp; Threats&lt;/h3&gt;
&lt;p&gt;From AI impersonation to major vulnerabilities, here are some stories that shaped cybersecurity this week.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🎭 DeepSeek AI tools are being impersonated on PyPI by infostealer malware targeting developers. (Published on 2/3/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/deepseek-ai-tools-impersonated-by-infostealer-malware-on-pypi/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🏦 The Coyote banking trojan expands its reach, now targeting 1,030 sites and 73 financial institutions. (Published on 2/3/2025, The Hacker News). &lt;a href="https://thehackernews.com/2025/02/coyote-malware-expands-reach-now.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 23 January 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-061/</link><pubDate>Thu, 23 Jan 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-061/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another mountain of security incidents to digest. From Fortinet’s double-feature vulnerability showcase to AI systems getting tricked into leaking your calendar (thanks, Gemini!), the headlines remind us that “fully patched” is more of a suggestion than a guarantee.&lt;/p&gt;
&lt;p&gt;Highlights? Tesla got pwned for half a million dollars, Microsoft blamed a “coding error” for Outlook crashes (aren’t they all?), and Curl is officially done with AI-generated bug bounty spam. Somewhere, a developer shed a single tear.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 16 January 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-059/</link><pubDate>Thu, 16 Jan 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-059/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🎢 This week’s cybersecurity rollercoaster: where Wi-Fi crashes with one packet, Chrome extensions cosplay as your HR portal, and ZIP files contain more layers than a lasagna made by someone with commitment issues.&lt;/p&gt;
&lt;p&gt;The big picture? Attackers are getting sophisticated (looking at you, Predator spyware that learns from failure), infrastructure is falling over (RIP Verizon, enjoy your $20), and apparently two missing characters almost took down AWS. Two. Characters.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 22 November 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-052/</link><pubDate>Fri, 22 Nov 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-052/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-threats-and-exploits"&gt;Cybersecurity Threats and Exploits&lt;/h3&gt;
&lt;p&gt;Newly discovered vulnerabilities and sophisticated hacking campaigns reveal the ongoing evolution of cyber threats across platforms and technologies.&lt;/p&gt;
&lt;p&gt;🔓 Chinese hackers exploit a Fortinet VPN zero-day vulnerability using the DeepData toolkit to steal credentials. (Published on 11/18/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-fortinet-vpn-zero-day-to-steal-credentials/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🎯 Fake discount sites mimic legitimate brands to exploit Black Friday shopping activity and steal customer information. (Published on 11/18/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/11/fake-discount-sites-exploit-black.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 8 November 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-050/</link><pubDate>Fri, 08 Nov 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-050/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-threats-and-exploits"&gt;Cybersecurity Threats and Exploits&lt;/h3&gt;
&lt;p&gt;A roundup of recent cybersecurity incidents and newly discovered vulnerabilities impacting various platforms and users worldwide.&lt;/p&gt;
&lt;p&gt;🚨 DocuSign’s Envelopes API is being exploited to send fake invoices, mimicking brands like Norton and PayPal. (Published on 11/4/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/docusigns-envelopes-api-abused-to-send-realistic-fake-invoices/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔍 Google’s AI tool, Big Sleep, uncovers a zero-day vulnerability in the SQLite database engine, marking a first in AI-assisted vulnerability discovery. (Published on 11/4/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/11/googles-ai-tool-big-sleep-finds-zero.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 2 August 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-036/</link><pubDate>Fri, 02 Aug 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-036/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🔒 Microsoft reports ransomware gangs exploiting VMware ESXi authentication bypass vulnerability. Stay alert! (Published on 7/29/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-ransomware-gangs-exploit-vmware-esxi-auth-bypass-in-attacks/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;⚠️ Stargazer Goblin creates 3,000 fake GitHub accounts to spread malware, earning $100,000 in illicit profits. (Published on 7/29/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/07/stargazer-goblin-creates-3000-fake.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🛡️ A critical security flaw in Acronis Cyber Infrastructure exploited in the wild; now patched. (Published on 7/29/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/07/critical-flaw-in-acronis-cyber.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 20 June 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-027/</link><pubDate>Thu, 20 Jun 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-027/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;This week’s cyber headlines reveal a multifaceted onslaught: ransomware that wipes backups before you can recover, AI tooling and Linux distros under active exploit, and social-engineering campaigns ranging from deepfake Zoom scams to MFA bypass ruses. Malware hides in images and sandboxed apps, while defenses scramble to shore up industrial controls and repel a 7.3 Tbps DDoS wave.&lt;/p&gt;
&lt;p&gt;Even “new” credential leaks turn out to be dust from old breaches. Stay sharp and dive into the links below for the full stories!&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 14 June 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-026/</link><pubDate>Fri, 14 Jun 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-026/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚨 Exploit for critical Veeam auth bypass flaw CVE-2024-29849 available. Admins urged to patch now. (Published on 6/10/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/exploit-for-critical-veeam-auth-bypass-available-patch-now/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;📱 Apple&amp;rsquo;s AI promise: &amp;ldquo;Your data is never stored or accessible to Apple.&amp;rdquo; Server code is publicly reviewable for verification. (Published on 6/10/2024, Ars Technica). &lt;a href="https://arstechnica.com/ai/2024/06/apples-ai-promise-your-data-is-never-stored-or-made-accessible-by-apple/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 31 May 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-024/</link><pubDate>Fri, 31 May 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-024/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚀 TP-Link fixes a critical RCE bug in its popular C5400X gaming router. Stay updated! (Published on 5/27/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/tp-link-fixes-critical-rce-bug-in-popular-c5400x-gaming-router/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔒 Hackers are targeting Check Point VPNs in a campaign to breach enterprise networks. Stay secure! (Published on 5/27/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/hackers-target-check-point-vpns-to-breach-enterprise-networks/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;💳 A Moroccan cybercrime group is stealing up to $100K daily through sophisticated gift card fraud. Be cautious! (Published on 5/27/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/05/moroccan-cybercrime-group-steals-up-to.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 17 May 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-022/</link><pubDate>Fri, 17 May 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-022/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🔍 DNS tunneling is increasingly exploited by hackers to track phishing victims and scan networks for weaknesses (Published on 5/13/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/hackers-use-dns-tunneling-for-network-scanning-tracking-victims/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;📦 A deceptive PyPi package targets Macs using Sliver pen-testing, mimicking the &amp;lsquo;requests&amp;rsquo; library (Published on 5/13/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/pypi-package-backdoors-macs-using-the-sliver-pen-testing-suite/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;📞 Black Basta ransomware innovates with a new vishing strategy after impacting 500 victims (Published on 5/13/2024, Dark Reading). &lt;a href="https://www.darkreading.com/cyberattacks-data-breaches/500-victims-later-black-basta-reinvents-novel-vishing-strategy"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 5 April 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-014/</link><pubDate>Fri, 05 Apr 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-014/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🛒 &lt;strong&gt;Shopping Platform PandaBuy Data Leak Impacts 1.3 Million Users&lt;/strong&gt; - Over 1.3 million PandaBuy users&amp;rsquo; data leaked. (4/1/2024, BleepingComputer) &lt;a href="https://www.bleepingcomputer.com/news/security/shopping-platform-pandabuy-data-leak-impacts-13-million-users/"&gt;Read more&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;📱 &lt;strong&gt;AT&amp;amp;T Confirms 73M Customers Affected in Data Leak&lt;/strong&gt; - AT&amp;amp;T admits data on 73M customers leaked on Dark Web. (4/1/2024, Dark Reading) &lt;a href="https://www.darkreading.com/remote-workforce/att-confirms-73m-customers-affected-data-leak"&gt;Read more&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 29 March 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-013/</link><pubDate>Fri, 29 Mar 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-013/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🔑 &lt;strong&gt;New MFA-Bypassing Phishing Kit Targets Microsoft 365, Gmail&lt;/strong&gt; - Cybercriminals exploit &amp;lsquo;Tycoon 2FA&amp;rsquo; to bypass 2FA on major email platforms. (3/25/2024, BleepingComputer) &lt;a href="https://www.bleepingcomputer.com/news/security/new-mfa-bypassing-phishing-kit-targets-microsoft-365-gmail-accounts/"&gt;Read more&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🍏 &lt;strong&gt;iOS 17.4.1 and macOS 14.4.1 Update for Security Fixes&lt;/strong&gt; - Apple rolls out crucial security updates without much detail. (3/25/2024, 9to5 Mac) &lt;a href="https://9to5mac.com/2024/03/25/ios-17-4-1-these-2-security-fixes/"&gt;Read more&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 8 March 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-009/</link><pubDate>Fri, 08 Mar 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-009/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;💳 American Express warns of a third-party breach exposing credit cards. (3/4/2024, BleepingComputer) &lt;a href="https://www.bleepingcomputer.com/news/security/american-express-credit-cards-exposed-in-vendor-data-breach/"&gt;Read more&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🎣 Hackers use phishing to steal Windows NTLM hashes. (3/4/2024, BleepingComputer) &lt;a href="https://www.bleepingcomputer.com/news/security/hackers-steal-windows-ntlm-authentication-hashes-in-phishing-attacks/"&gt;Read more&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔒 GitHub battles millions of malicious repos. (3/4/2024, Dark Reading) &lt;a href="https://www.darkreading.com/application-security/millions-of-malicious-repositories-flood-github"&gt;Read more&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🛑 Meta faces massive outage across top social apps. (3/5/2024, TechCrunch) &lt;a href="https://techcrunch.com/2024/03/05/facebook-instagram-and-threads-are-all-down-in-massive-meta-outage-on-super-tuesday/"&gt;Read more&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 7 February 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-004/</link><pubDate>Wed, 07 Feb 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-004/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cybersecurity-news--threats"&gt;🔥 &lt;strong&gt;Cybersecurity News &amp;amp; Threats&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;From AI impersonation to major vulnerabilities, here’s what’s shaping cybersecurity this week.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🎭 DeepSeek AI tools are being impersonated on PyPI by infostealer malware targeting developers. (Published on 2/3/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/deepseek-ai-tools-impersonated-by-infostealer-malware-on-pypi/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🏦 The Coyote banking trojan expands its reach, now targeting 1,030 sites and 73 financial institutions. (Published on 2/3/2025, The Hacker News). &lt;a href="https://thehackernews.com/2025/02/coyote-malware-expands-reach-now.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item></channel></rss>