<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ransomware &amp; Extortion on Jorge Laurel</title><link>https://jorgelaurel.com/topics/ransomware--extortion/</link><description>Recent content in Ransomware &amp; Extortion on Jorge Laurel</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 03 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://jorgelaurel.com/topics/ransomware--extortion/index.xml" rel="self" type="application/rss+xml"/><item><title>Friday Wrap Up: 3 April 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-119/</link><pubDate>Fri, 03 Apr 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-119/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;This week in cybersecurity was a masterclass in how fast things can go sideways. 🔐&lt;/p&gt;
&lt;p&gt;Ransomware operators are now completing full attacks in under an hour. AI platforms you use every day shipped critical vulnerabilities. A supply chain attack hit a JavaScript library with 100M+ weekly downloads. And someone accidentally leaked 512,000 lines of AI source code — which attackers immediately weaponized into a malware campaign on GitHub.&lt;/p&gt;
&lt;p&gt;If your patch queue looks overwhelming right now, you’re not alone. Chrome, Cisco, F5, Fortinet, and more all dropped critical fixes this week — many already under active exploitation before patches shipped.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 20 March 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-117/</link><pubDate>Fri, 20 Mar 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-117/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It’s Friday, which means the threat actors didn’t take the week off — and neither did we. 🛡️&lt;/p&gt;
&lt;p&gt;This week’s Friday Wrap Up covers ransomware gangs weaponizing zero-days, nation-state actors wiping devices at scale, supply-chain attacks hitting developer toolchains, AI platforms becoming the new attack surface, and a botnet that clearly skipped leg day because it never stops running. Whether you’re patching, detecting, or just trying to make it to 5pm, there’s something in this week’s roundup that probably affects your org.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 27 February 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-114/</link><pubDate>Fri, 27 Feb 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-114/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another Friday, another reason to question whether your apps, APIs, and Zoom calls are working for you — or someone else. 🛡️&lt;/p&gt;
&lt;p&gt;This week’s Friday Wrap Up covers ransomware hitting chip makers and medical device companies, China-linked spies repurposing Google Sheets as a command center (productivity hack of the year, unfortunately), North Korea expanding into healthcare ransomware, and a fake Zoom meeting that installs surveillance software before you finish your first sip of coffee.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 13 February 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-112/</link><pubDate>Fri, 13 Feb 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-112/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another collection of reasons why your security team hasn’t slept properly since 2019. This week’s FWU brings you everything from ransomware gangs cosplaying as employee monitoring software to North Korean job applicants who are definitely not who they claim to be on LinkedIn (looking at you, “Senior DevOps Engineer”).&lt;/p&gt;
&lt;p&gt;We’ve got cloud infrastructure being turned into crime bots, Olympic ice dancers accidentally committing AI plagiarism, and the eternal question: “Is that zero-day actively exploited?” (Spoiler: yes, probably within 24 hours of the PoC dropping).&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 12 December 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-108/</link><pubDate>Fri, 12 Dec 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-108/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another avalanche of zero-days, ransomware victims, and creative attack techniques that make you wonder if threat actors ever sleep (spoiler: they don’t).&lt;/p&gt;
&lt;p&gt;From Chrome getting exploited in the wild to malware hiding in VS Code extensions—because apparently, even our dev tools need therapy now—this week had it all. We’ve got nation-state shenanigans, AI security guardrails, and someone at Accenture allegedly fudging DoD compliance (yikes).&lt;/p&gt;
&lt;p&gt;Click through for the full breakdown before your CISO asks if you’ve seen the latest Chrome patch.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 14 November 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-104/</link><pubDate>Fri, 14 Nov 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-104/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another wild week in cybersecurity! From PhaaS platforms targeting M365 to ransomware groups naming victims, Russian IABs pleading guilty, and a chipmaker publishing 60+ vuln patches—it’s been eventful.&lt;/p&gt;
&lt;p&gt;We’ve got nation-state espionage campaigns, supply chain nightmares, fake travel sites stealing payment data, and even Android photo frames shipping with malware. Plus, the passwordless dream keeps hitting reality checks while Microsoft rushes fixes for Windows 10 stragglers.&lt;/p&gt;
&lt;p&gt;Check out this week’s Friday Wrap Up for the full breakdown!&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 7 November 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-103/</link><pubDate>Fri, 07 Nov 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-103/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another wild week in cybersecurity where insider threats meet nation-state attacks, AI-powered malware rewrites itself hourly, and even our security pros are allegedly moonlighting with ransomware gangs. 🤦‍♂️&lt;/p&gt;
&lt;p&gt;From YouTube ghost networks spreading infostealers through fake videos to logic bombs hiding in code packages set to detonate in 2027 (mark your calendars!), the threat landscape keeps getting more creative—and concerning 😳 .&lt;/p&gt;
&lt;p&gt;The Congressional Budget Office got breached, Samsung phones were compromised via malicious images, and ChatGPT vulnerabilities could leak your AI conversations. Meanwhile, the cybercrime equivalent of a corporate merger just happened with three major gangs joining forces 💸 .&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 31 October 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-102/</link><pubDate>Fri, 31 Oct 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-102/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Happy Halloween! 🎃&lt;/p&gt;
&lt;p&gt;This week’s cyber threats are scarier than any haunted house. We’ve got banking trojans that disguise themselves as humans, nation-state ghosts haunting European diplomats, and AI tools conjuring up security nightmares that would make Frankenstein nervous.&lt;/p&gt;
&lt;p&gt;Ransomware ghouls are back with new tricks, supply chain vampires are draining developer credentials, and Microsoft’s DNS went dark like a haunted mansion.&lt;/p&gt;
&lt;p&gt;Whether you’re more afraid of deepfakes, zero-days, or your cloud services vanishing into thin air, this week’s wrap-up has something to give every security professional the chills.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 24 October 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-101/</link><pubDate>Fri, 24 Oct 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-101/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another reminder that cybersecurity never takes a coffee break! ☕&lt;/p&gt;
&lt;p&gt;From botnet malware targeting your router to smart beds that won’t lie flat during cloud outages (yes, really), this week had everything. We’re talking billion-dollar breaches, quantum leaps, AI agents surfing the web, and Microsoft patches that caused more problems than they solved. Plus, ransomware victims learning the hard way that paying up doesn’t guarantee getting your data back.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 10 October 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-099/</link><pubDate>Fri, 10 Oct 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-099/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another ransomware alliance, and somehow your mouse might be eavesdropping on you now. 🖱️👂&lt;/p&gt;
&lt;p&gt;From fake Discord alerts stealing vault credentials to North Korean hackers pocketing $2B in crypto, this week proves that cybercriminals are nothing if not creative (and disturbingly well-funded). Meanwhile, the FBI took down BreachForums and Google’s AI is learning to patch code before attackers can exploit it.&lt;/p&gt;
&lt;p&gt;The cybersecurity world never sleeps, and honestly, neither should your security team after reading this. Click through for the full rundown of breaches, malware, and the latest “why-is-that-even-possible” attack vectors.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 03 October 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-098/</link><pubDate>Fri, 03 Oct 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-098/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another parade of cyber shenanigans that make you wonder if the internet needs a timeout. From ransomware gangs sliding into BBC reporters’ DMs with job offers (seriously), to AI tools making phishing easier than ordering takeout, it’s been quite the ride.&lt;/p&gt;
&lt;p&gt;We’ve got everything from government shutdowns creating security gaps you could drive a truck through, to hackers apologizing for posting kids’ photos (because even cybercriminals have PR nightmares). Plus, Meta wants to monetize your AI chats, because why not add targeted ads to your robot conversations?&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 26 September 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-097/</link><pubDate>Fri, 26 Sep 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-097/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another batch of creative ways cybercriminals are keeping us security folks caffeinated! ☕&lt;/p&gt;
&lt;p&gt;From airports getting grounded by ransomware to AI agents accidentally becoming the world’s most helpful data thieves, this week’s threat landscape had more plot twists than a Netflix series. We saw record-breaking DDoS attacks that made previous “massive” attacks look like gentle nudges, supply chain compromises that spread faster than office gossip, and enough zero-days to make patch Tuesday feel like patch decade.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 29 August 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-093/</link><pubDate>Fri, 29 Aug 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-093/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Salesforce attacks rippled into insurers and healthcare, AI-powered ransomware went live, Nevada shut down state offices, and hackers weaponized AI in the first supply chain breach.&lt;/p&gt;
&lt;p&gt;Meanwhile, $47M in scam crypto was seized, fake ID markets were dismantled, and Linux blew out 34 candles 🎂.&lt;/p&gt;
&lt;p&gt;🔍 From data theft to AI threats, the line between “attack” and “experiment” is vanishing fast.&lt;/p&gt;
&lt;p&gt;⚡ &lt;em&gt;Recaps + sources in this week’s Friday Wrap Up&lt;/em&gt; — because in cyber, “too long; didn’t read” can turn into “too late; data’s ripped.”&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 15 Aug 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-091/</link><pubDate>Fri, 15 Aug 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-091/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚨 Friday Wrap Up highlights this week&lt;/p&gt;
&lt;p&gt;From cars remotely unlocked to state-backed hacks — attackers didn’t take a summer break.&lt;/p&gt;
&lt;p&gt;🚗 Car dealership portal flaw let anyone unlock vehicles remotely.&lt;/p&gt;
&lt;p&gt;🏛 Russian hackers breached U.S. federal court filing system.&lt;/p&gt;
&lt;p&gt;🛠 Microsoft patched Kerberos zero-day; Cisco fixed CVSS 10 flaw.&lt;/p&gt;
&lt;p&gt;🕵️ Crypto24 ransomware using custom EDR evasion tools.&lt;/p&gt;
&lt;p&gt;📻 TETRA radio encryption flaws exposed law enforcement comms.&lt;/p&gt;
&lt;p&gt;💾 Hackers leaked 9GB from alleged North Korean hacker’s PC.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 8 Aug 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-090/</link><pubDate>Fri, 08 Aug 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-090/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚨 Zero-days, crypto-stealing extensions, and AI-weaponized attacks—it&amp;rsquo;s been a week full of cybersecurity “achievements.” Also: Perplexity&amp;rsquo;s scraping scandal, scammy snail mail, and AI that might be a little too curious. Full roundup below!&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="malware--vulnerabilities"&gt;&lt;strong&gt;Malware &amp;amp; Vulnerabilities&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;From zero-days in security appliances to flaws in Exchange, Axis, and IP cameras—this week was a buffet of critical bugs waiting to be exploited.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🛡️ SonicWall probing potential zero-day in SSL VPN after 20+ targeted attacks (Published on 8/4/2025, The Hacker News). &lt;a href="https://thehackernews.com/2025/08/sonicwall-investigating-potential-ssl.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 01 August 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-089/</link><pubDate>Fri, 01 Aug 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-089/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🔐 From AI-fueled deepfake threats to prompt injection vulnerabilities in cutting-edge tools, the cybersecurity battlefield keeps getting messier.&lt;/p&gt;
&lt;p&gt;Ransomware crews, phishing scams, and espionage actors all made headlines this week.&lt;/p&gt;
&lt;p&gt;Click through for a concise digest of what’s hot (and hacked) in cyber. 💥&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;Malware &amp;amp; Vulnerabilities&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;From AI-generated threats to prompt injection and phishing tricks, attackers are exploiting everything from popular dev tools to critical infrastructure.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🧪 AI-generated malicious npm package drained Solana wallets from over 1,500 users before takedown (Published on 8/1/2025, The Hacker News). &lt;a href="https://thehackernews.com/2025/08/ai-generated-malicious-npm-package.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 11 July 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-086/</link><pubDate>Fri, 11 Jul 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-086/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another busy week in cybersecurity and tech.&lt;/p&gt;
&lt;p&gt;🛡️ Ransomware groups are shutting down while pivoting to data extortion, as millions of records continue leaking from major brands.&lt;/p&gt;
&lt;p&gt;🕸️ Malicious Chrome extensions, SEO poisoning attacks disguised as AI tools, and critical zero-days highlight persistent threats across the supply chain and user environments.&lt;/p&gt;
&lt;p&gt;🤖 As organizations rush to adopt agentic AI, understanding dark market dynamics, patching critical vulnerabilities, and ensuring cyber-insurance coverage remain vital for resilience.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 4 July 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-085/</link><pubDate>Fri, 04 Jul 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-085/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-security--cyber-threats"&gt;🚨 Security &amp;amp; Cyber Threats&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🇨🇦 Hikvision Canada shut down over national security concerns. (Published on 6/30/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/hikvision-canada-ordered-to-cease-operations-over-security-risks/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🛡️ U.S. warns of rising Iranian cyberattacks on critical infrastructure. (Published on 6/30/2025, The Hacker News). &lt;a href="https://thehackernews.com/2025/06/us-agencies-warn-of-rising-iranian.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;💧 Hackers opened a Norwegian dam valve for hours using a weak password. (Published on 6/30/2025, Hackread). &lt;a href="https://hackread.com/norwegian-dam-valve-forced-open-hours-in-cyberattack/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 20 June 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-083/</link><pubDate>Fri, 20 Jun 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-083/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="ransomware--backup-threats"&gt;Ransomware &amp;amp; Backup Threats&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;💀 New Anubis ransomware encrypts and permanently wipes files—recovery impossible even after payment. (Published on 6/16/2025, The Hacker News). &lt;a href="https://thehackernews.com/2025/06/anubis-ransomware-encrypts-and-wipes.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🔄 Ransomware gangs now target backup infrastructures first to cripple recovery options. (Published on 6/17/2025, The Hacker News). &lt;a href="https://thehackernews.com/2025/06/how-to-protect-your-backups-from-ransomware-attacks.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;💾 Chain IQ and UBS data stolen in a ransomware attack claiming millions of files exfiltrated. (Published on 6/19/2025, SecurityWeek). &lt;a href="https://www.securityweek.com/chain-iq-ubs-data-stolen-in-ransomware-attack/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 6 June 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-081/</link><pubDate>Fri, 06 Jun 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-081/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Ever feel like your network is safer when it’s unplugged and buried in a lead box? Same.&lt;/p&gt;
&lt;p&gt;This week in the Friday Wrap Up: ransomware operators got unmasked, GPU bugs need urgent hugs (a.k.a. patches), and fake CAPTCHAs are convincing users to hack themselves. From hospital breaches to solar device hijacks, the digital drama never disappoints.&lt;/p&gt;
&lt;p&gt;If you like your cyber news fresh, punchy, and slightly panic-inducing (with a side of professionalism), check out this week’s Friday Wrap-Up. You bring the coffee, we’ll bring the chaos.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 23 May 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-079/</link><pubDate>Fri, 23 May 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-079/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🎉 Back from vacation and fully recharged—sunburned but secure! ☀️🔐 Missed a week, but fear not: your favorite Friday Wrap Up is back and packed tighter than a phishing kit on a USB stick.&lt;/p&gt;
&lt;p&gt;This week’s headlines are a buffet of cyber-chaos: ransomware gangs get sneakier, Chrome plays password nanny, and someone gave 40,000 iOS apps a little too much freedom. Also, Microsoft’s playing sheriff, Signal&amp;rsquo;s playing defense, and a student hacker’s playing guilty.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 9 May 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-078/</link><pubDate>Fri, 09 May 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-078/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;🔐 Cyber Threats &amp;amp; Malware Surge&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Cybercriminals continue to evolve tactics—from exploiting zero-days to using supply-chain attacks and AI developer tools. Here’s what’s making headlines:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🛑 Signal clone used by Trump official ceases operations after reported hack. (Published on 5/5/2025, Ars Technica). &lt;a href="https://arstechnica.com/security/2025/05/signal-clone-used-by-trump-official-stops-operations-after-report-it-was-hacked/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🚨 New ransomware attack uses &amp;ldquo;Bring Your Own Installer&amp;rdquo; to bypass EDR protections. (Published on 5/5/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/new-bring-your-own-installer-edr-bypass-used-in-ransomware-attack/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 2 May 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-077/</link><pubDate>Fri, 02 May 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-077/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;From phishing rings to AI-written code, it&amp;rsquo;s been another week in cybersecurity where the only constant is everything’s on fire 🔥.&lt;/p&gt;
&lt;p&gt;This week’s Friday Wrap Up features:&lt;/p&gt;
&lt;p&gt;- Cybercriminals getting busted (some, not all—let&amp;rsquo;s not get crazy),&lt;/p&gt;
&lt;p&gt;- Zero-days popping like popcorn 🍿,&lt;/p&gt;
&lt;p&gt;- Space hacking (yes, literally),&lt;/p&gt;
&lt;p&gt;- AI quietly taking over dev jobs,&lt;/p&gt;
&lt;p&gt;- And government agencies asking, &amp;ldquo;Secure by Design—was that just a phase?&amp;rdquo;&lt;/p&gt;
&lt;p&gt;If your cloud is leaking secrets, your CMS is under siege, or you&amp;rsquo;re wondering how ransomware gangs pivot after a breakup&amp;hellip; we’ve got you covered.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 25 April 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-076/</link><pubDate>Fri, 25 Apr 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-076/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🎉 This Week in Cyber: From AI Phishing to ATM Hacking – We’ve Seen It All&lt;/p&gt;
&lt;p&gt;If you thought cybercriminals might slow down in April… plot twist! 😅&lt;/p&gt;
&lt;p&gt;This week’s headlines brought:&lt;/p&gt;
&lt;p&gt;- AI-powered phishing toolkits that scale scams faster than startups scale servers 🤖💸&lt;/p&gt;
&lt;p&gt;- Ransomware attacks hitting hospitals, cities, and schools — because clearly nothing is sacred anymore 🏥🏛️&lt;/p&gt;
&lt;p&gt;- Spoofed emails that even Google thought were legit 🫣&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 18 April 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-075/</link><pubDate>Fri, 18 Apr 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-075/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;From rogue restarts in Windows Server 2025 to ransomware giving dialysis clinics a real headache, this week was anything but quiet.&lt;/p&gt;
&lt;p&gt;State-backed hackers were busy playing malware bingo, Fortinet and Cisco had some uninvited guests, and 4chan may have just been out-trolled by a rival forum (yes, really).&lt;/p&gt;
&lt;p&gt;Meanwhile, AI continues its sneaky takeover—half of your coworkers are probably using unapproved tools, and Google’s swatting down billions of bad ads like it’s a high-stakes arcade game.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 11 April 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-074/</link><pubDate>Fri, 11 Apr 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-074/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚨 This week in cybersecurity: breakfast got breached, NASCAR took a pit stop for ransomware, and a new AI hacking assistant named Xanthorox hit the dark web like it’s applying for a job at Anonymous HQ.&lt;/p&gt;
&lt;p&gt;Meanwhile, “Lovable” AI turns out to be &lt;em&gt;a little too&lt;/em&gt; lovable to cybercriminals, WhatsApp had a Windows-flavored vulnerability, and someone really should check on those 4 million Chrome users installing sketchy extensions with “Featured” badges.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 28 March 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-072/</link><pubDate>Fri, 28 Mar 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-072/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;🛡️ Cyberattack Campaigns &amp;amp; Threat Actor Activity&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;A surge in advanced persistent threats and ransomware highlights the evolving cybercrime landscape.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🐜 Chinese Weaver Ant hackers infiltrated a telecom network for over 4 years using compromised Zyxel routers. (Published on 3/24/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/chinese-weaver-ant-hackers-spied-on-telco-network-for-4-years/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🧬 Medusa ransomware disables EDR tools using stolen certificates for stealthy system takeovers. (Published on 3/25/2025, Hackread). &lt;a href="https://hackread.com/medusa-ransomware-anti-malware-tools-stolen-certificates/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 7 March 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-069/</link><pubDate>Fri, 07 Mar 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-069/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="-cybersecurity-incidents--threats"&gt;🔥 Cybersecurity Incidents &amp;amp; Threats&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🔑 &lt;strong&gt;Rubrik rotates authentication keys after log server breach&lt;/strong&gt; – A breach in Rubrik’s log server led to the rotation of potentially leaked authentication keys. (Published on 3/3/2025, Bleeping Computer). &lt;a href="https://www.bleepingcomputer.com/news/security/rubrik-rotates-authentication-keys-after-log-server-breach/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🎭 &lt;strong&gt;North Korean fake IT workers pose as blockchain developers&lt;/strong&gt; – Fraudulent personas on GitHub are helping North Korean operatives secure blockchain development jobs in the U.S. and Japan. (Published on 3/5/2025, SecurityWeek). &lt;a href="https://www.securityweek.com/north-korean-fake-it-workers-pose-as-blockchain-developers-on-github/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 14 February 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-066/</link><pubDate>Fri, 14 Feb 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-066/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;💘 &lt;strong&gt;Roses are red, violets are blue, cyber threats don’t care… and they’re coming for you!&lt;/strong&gt; 💘&lt;/p&gt;
&lt;p&gt;This Valentine’s Day, while some are finding love, others are finding &lt;strong&gt;zero-days, ransomware, and nation-state hackers&lt;/strong&gt;. Here’s a &lt;strong&gt;cybersecurity love stories&lt;/strong&gt; you don’t want to be part of:&lt;/p&gt;
&lt;h3 id="latest-cybersecurity-threats-and-vulnerabilities"&gt;🔥 Latest Cybersecurity Threats and Vulnerabilities&lt;/h3&gt;
&lt;p&gt;From zero-days to AI exploits, attackers are finding new ways to break into systems. Stay updated on the latest security risks.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 23 January 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-061/</link><pubDate>Thu, 23 Jan 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-061/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another mountain of security incidents to digest. From Fortinet’s double-feature vulnerability showcase to AI systems getting tricked into leaking your calendar (thanks, Gemini!), the headlines remind us that “fully patched” is more of a suggestion than a guarantee.&lt;/p&gt;
&lt;p&gt;Highlights? Tesla got pwned for half a million dollars, Microsoft blamed a “coding error” for Outlook crashes (aren’t they all?), and Curl is officially done with AI-generated bug bounty spam. Somewhere, a developer shed a single tear.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 3 January 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-057/</link><pubDate>Fri, 03 Jan 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-057/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-breaches-and-incidents"&gt;Cybersecurity Breaches and Incidents&lt;/h3&gt;
&lt;p&gt;🔒 &lt;strong&gt;Chinese state-sponsored hackers breached the U.S. Treasury Department&lt;/strong&gt; via a remote support platform. (Published on 12/30/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/us-treasury-department-breached-through-remote-support-platform/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🚘 &lt;strong&gt;Volkswagen, Audi, and Skoda EV owners affected by a major data breach&lt;/strong&gt; tracking over 800,000 vehicles. (Published on 12/30/2024, Hackread). &lt;a href="https://hackread.com/exposed-cloud-server-tracks-volkswagen-audi-skoda-evs/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 20 December 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-055/</link><pubDate>Fri, 20 Dec 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-055/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-threats-and-attacks"&gt;Cybersecurity Threats and Attacks&lt;/h3&gt;
&lt;p&gt;Staying informed about the latest cybersecurity threats and data breaches is essential for businesses and individuals alike.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🛑 Malicious ads spread Lumma Stealer via fake CAPTCHA pages, tricking users into running PowerShell commands. (Published on 12/16/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/malicious-ads-push-lumma-infostealer-via-fake-captcha-pages/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🐘 Glutton malware exploits popular PHP frameworks like Laravel and ThinkPHP, targeting multiple countries. (Published on 12/16/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/12/new-glutton-malware-exploits-popular.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 13 September 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-043/</link><pubDate>Fri, 13 Sep 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-043/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/c58afca7b6e9f5e6.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="cybersecurity-incidents-"&gt;Cybersecurity Incidents 🛡️&lt;/h3&gt;
&lt;p&gt;🚨 Highline Public Schools shuts down following a cyberattack, causing school closures and activity cancellations. (Published on 9/9/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/highline-public-schools-closes-schools-following-cyberattack/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🚨 Avis Car Rental data breach affects 300,000 customers, exposing personal information in August 2024. (Published on 9/9/2024, SecurityWeek). &lt;a href="https://www.securityweek.com/300000-impacted-by-data-breach-at-car-rental-firm-avis/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🚨 Fortinet confirms a data breach after a hacker claims to have stolen 440GB of files from their Microsoft SharePoint server. (Published on 9/12/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/fortinet-confirms-data-breach-after-hacker-claims-to-steal-440gb-of-files/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 6 September 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-042/</link><pubDate>Fri, 06 Sep 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-042/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="data-breaches--security-failures"&gt;Data Breaches &amp;amp; Security Failures&lt;/h3&gt;
&lt;p&gt;🔓 &lt;strong&gt;Verkada&lt;/strong&gt; will pay $2.95M after security lapses allowed hackers to access live feeds from 150,000 cameras. (Published on 9/2/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/verkada-to-pay-295m-for-security-failures-leading-to-breaches/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔐 &lt;strong&gt;CBIZ&lt;/strong&gt; disclosed a data breach involving unauthorized access to client information stored in specific databases. (Published on 9/2/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/business-services-giant-cbiz-discloses-customer-data-breach/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 30 August 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-041/</link><pubDate>Fri, 30 Aug 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-041/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="cybersecurity-incidents-and-alerts"&gt;Cybersecurity Incidents and Alerts:&lt;/h2&gt;
&lt;p&gt;🚨 &lt;strong&gt;Seattle-Tacoma Airport cyberattack&lt;/strong&gt; disrupts IT systems, causing flight delays and reservation check-in issues. (Published on 8/26/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/seattle-tacoma-airport-it-systems-down-due-to-a-cyberattack/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;👥 &lt;strong&gt;750M fake Microsoft accounts created&lt;/strong&gt; as cybercriminals exploit Greasy Opal to bypass security measures. (Published on 8/26/2024, Dark Reading). &lt;a href="https://www.darkreading.com/cyberattacks-data-breaches/cybercriminals-tap-greasy-opal-to-create-750m-fake-microsoft-accounts"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔒 &lt;strong&gt;Patelco Credit Union data breach&lt;/strong&gt; impacts 726,000 customers due to a ransomware attack. (Published on 8/26/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/patelco-notifies-726-000-customers-of-ransomware-data-breach/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 16 Aug 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-038/</link><pubDate>Fri, 16 Aug 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-038/</guid><description>&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/strong&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚨 The FBI has successfully disrupted the Dispossessor ransomware operation, seizing servers after a global investigation. (Published on 8/12/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/fbi-disrupts-the-dispossessor-ransomware-operation-seizes-servers/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🤝 CrowdStrike addresses concerns at Black Hat and DEF CON, engaging directly with cybersecurity professionals. (Published on 8/12/2024, Dark Reading). &lt;a href="https://www.darkreading.com/cybersecurity-operations/crowdstrike-tries-patch-things-up-cybersecurity-industry"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;⚠️ Multiple vulnerabilities found in Google’s Quick Share, potentially allowing remote code execution on Windows systems. (Published on 8/12/2024, SecurityWeek). &lt;a href="https://www.securityweek.com/several-vulnerabilities-found-in-googles-quick-share-data-transfer-utility/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 9 August 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-037/</link><pubDate>Fri, 09 Aug 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-037/</guid><description>&lt;hr&gt;
&lt;h3 id="its-been-a-busy-week-in-cybersecurity-and-time-for-a-friday-wrap-up-here-are-some-of-the-interesting-stories-from-this-past-week"&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/h3&gt;
&lt;hr&gt;
&lt;p&gt;🚨 The Hunters International ransomware group is using the new SharpRhino malware to target IT workers and breach corporate networks. (Published on 8/5/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/hunters-international-ransomware-gang-targets-it-workers-with-new-sharprhino-malware/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔍 One in five enterprise IT admins report state-sponsored attacks aiming to infiltrate their supply chains. (Published on 8/5/2024, Malware Analysis). &lt;a href="https://malware.news/t/1-in-5-companies-say-state-sponsored-attacks-try-to-penetrate-supply-chain/84883"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 2 August 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-036/</link><pubDate>Fri, 02 Aug 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-036/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🔒 Microsoft reports ransomware gangs exploiting VMware ESXi authentication bypass vulnerability. Stay alert! (Published on 7/29/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-ransomware-gangs-exploit-vmware-esxi-auth-bypass-in-attacks/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;⚠️ Stargazer Goblin creates 3,000 fake GitHub accounts to spread malware, earning $100,000 in illicit profits. (Published on 7/29/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/07/stargazer-goblin-creates-3000-fake.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🛡️ A critical security flaw in Acronis Cyber Infrastructure exploited in the wild; now patched. (Published on 7/29/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/07/critical-flaw-in-acronis-cyber.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 19 July 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-035/</link><pubDate>Fri, 19 Jul 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-035/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚨 Cybercriminals use Facebook ads to spread info-stealing malware via fake Windows themes. Stay alert! (Published on 7/15/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/facebook-ads-for-windows-themes-push-sys01-info-stealing-malware/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🚫 Kaspersky Lab announces the shutdown of its U.S. operations starting July 20. (Published on 7/15/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/kaspersky-is-shutting-down-its-business-in-the-united-states/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🛡️ Rite Aid suffers a data breach affecting older customer purchases, becoming RansomHub&amp;rsquo;s latest victim. (Published on 7/15/2024, Dark Reading). &lt;a href="https://www.darkreading.com/cyberattacks-data-breaches/rite-aid-ransomhub-victim-data-breach"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 18 July 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-034/</link><pubDate>Thu, 18 Jul 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-034/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another wild week in cybersecurity! From hackers giving Elmo a social media crisis and ransomware taking a shot at Russian vodka, to DDoS attacks making 2024 look like a warm-up act—there’s plenty to keep security pros and IT teams busy (and probably a little stressed).&lt;/p&gt;
&lt;p&gt;We’ve got everything:&lt;br&gt;
• &lt;strong&gt;Stealthy new hacking tools&lt;/strong&gt; targeting Azure, Okta, and more&lt;br&gt;
• &lt;strong&gt;Major malware campaigns&lt;/strong&gt; sneaking through npm and even Microsoft Teams&lt;br&gt;
• &lt;strong&gt;Supply chain risks&lt;/strong&gt; with firmware bugs and Linux cryptominers that just won’t quit&lt;br&gt;
• &lt;strong&gt;Ransomware&lt;/strong&gt; hitting both companies &lt;em&gt;and&lt;/em&gt; their liquor cabinets&lt;br&gt;
• &lt;strong&gt;Long-standing vulnerabilities&lt;/strong&gt; (turns out, some train hacks just need a couple of decades to get noticed)&lt;br&gt;
• &lt;strong&gt;Cloudflare blocking a tidal wave of DDoS&lt;/strong&gt;—and accidentally blocking itself, but hey, no hackers there&lt;br&gt;
• And for good measure, a dose of AI panic&amp;hellip;with experts saying we can keep our robot uprising memes on standby (for now)&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 12 July 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-033/</link><pubDate>Fri, 12 Jul 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-033/</guid><description>&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/strong&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚨 A remote code execution bug in Ghostscript is being actively exploited on Linux systems. Stay alert! (Published on 7/8/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/rce-bug-in-widely-used-ghostscript-library-now-exploited-in-attacks/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;💻 Emerging RaaS operation &amp;lsquo;Eldorado&amp;rsquo; targets both Windows and Linux systems with encryption locker variants. (Published on 7/8/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/07/new-ransomware-as-service-eldorado.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔍 The &amp;lsquo;CloudSorcerer&amp;rsquo; APT leverages cloud services in a sophisticated cyber-espionage campaign. (Published on 7/8/2024, Dark Reading). &lt;a href="https://www.darkreading.com/cloud-security/cloudsorceror-public-cloud-cyberespionage-campaign"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 20 June 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-027/</link><pubDate>Thu, 20 Jun 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-027/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;This week’s cyber headlines reveal a multifaceted onslaught: ransomware that wipes backups before you can recover, AI tooling and Linux distros under active exploit, and social-engineering campaigns ranging from deepfake Zoom scams to MFA bypass ruses. Malware hides in images and sandboxed apps, while defenses scramble to shore up industrial controls and repel a 7.3 Tbps DDoS wave.&lt;/p&gt;
&lt;p&gt;Even “new” credential leaks turn out to be dust from old breaches. Stay sharp and dive into the links below for the full stories!&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 17 May 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-022/</link><pubDate>Fri, 17 May 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-022/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🔍 DNS tunneling is increasingly exploited by hackers to track phishing victims and scan networks for weaknesses (Published on 5/13/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/hackers-use-dns-tunneling-for-network-scanning-tracking-victims/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;📦 A deceptive PyPi package targets Macs using Sliver pen-testing, mimicking the &amp;lsquo;requests&amp;rsquo; library (Published on 5/13/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/pypi-package-backdoors-macs-using-the-sliver-pen-testing-suite/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;📞 Black Basta ransomware innovates with a new vishing strategy after impacting 500 victims (Published on 5/13/2024, Dark Reading). &lt;a href="https://www.darkreading.com/cyberattacks-data-breaches/500-victims-later-black-basta-reinvents-novel-vishing-strategy"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Saturday Wrap Up: 11 May 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-020/</link><pubDate>Sat, 11 May 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-020/</guid><description>&lt;hr&gt;
&lt;p&gt;This week&amp;rsquo;s Friday Wrap Up is going to be &lt;strong&gt;Saturday&lt;/strong&gt; Wrap Up. I spent the week at RSA and arrived back on the east coast yesterday evening and decided to relax after the coast to coast flight. If you were at RSA all week, you know what I&amp;rsquo;m talking about!&lt;/p&gt;
&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/44553eb2e3034052.png" alt=""&gt;&lt;/p&gt;
&lt;p&gt;A real working Enigma that was on display at the NSA booth in the South Hall. Thank you to National Cryptologic Museum for having it on display and having a museum curator on hand to give a history of the Enigma to anyone that asked.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 9 May 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-019/</link><pubDate>Thu, 09 May 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-019/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another thrilling episode of &lt;em&gt;As The Cyber World Burns&lt;/em&gt; 🔥&lt;/p&gt;
&lt;p&gt;From ransomware groups getting hacked (yes, really) to backdoored npm packages, fake installers, Pegasus penalties, and one too many Mirai botnets—I’ve highlighted the news story. Even a Signal clone used by a politician decided to just&amp;hellip; stop existing.&lt;/p&gt;
&lt;p&gt;If you’re into CIO existential crises, DDoS takedowns, or wondering what “Bring Your Own Installer” could possibly mean (spoiler: nothing good), I’ve highlighted it in this week’s &lt;strong&gt;Friday Wrap Up&lt;/strong&gt;. Because in cybersecurity, the only constant is, well&amp;hellip; incident response.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 12 April 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-015/</link><pubDate>Fri, 12 Apr 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-015/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚨 Greylock McKinnon Associates reports a major data breach, exposing over 340,000 Social Security numbers. Stay vigilant! (Published on 4/8/2024, TechCrunch). &lt;a href="https://techcrunch.com/2024/04/08/hackers-stole-340000-social-security-numbers-from-government-consulting-firm/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🔓 D-Link NAS devices with critical vulnerabilities won&amp;rsquo;t receive patches, putting 92,000 devices at risk. (Published on 4/8/2024, Ars Technica). &lt;a href="https://arstechnica.com/security/2024/04/hackers-actively-exploit-critical-remote-takeover-vulnerabilities-in-d-link-devices/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;💸 Nearly 2,000 WordPress sites have been compromised to trick visitors with fake NFT pop-ups and crypto drainers. Be cautious! (Published on 4/8/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/hackers-deploy-crypto-drainers-on-thousands-of-wordpress-sites/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 28 March 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-012/</link><pubDate>Thu, 28 Mar 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-012/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another batch of cyber drama that makes you question every login form you&amp;rsquo;ve ever seen.&lt;/p&gt;
&lt;p&gt;Chinese threat actors camped out in a telco network for four years like it was their personal Airbnb, while a critical Next.js vulnerability quietly said, “Authorization? Never heard of her.”&lt;/p&gt;
&lt;p&gt;Meanwhile, ransomware crews are out here disabling anti-malware tools with stolen certs—because apparently, &lt;em&gt;revoked&lt;/em&gt; doesn&amp;rsquo;t mean &lt;em&gt;useless&lt;/em&gt;. And Kubernetes? Let’s just say 40% of clusters are living dangerously, thanks to the aptly named “IngressNightmare.”&lt;/p&gt;</description></item><item><title>Friday Wrap Up for 1 March 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-008/</link><pubDate>Fri, 01 Mar 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-008/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;p&gt;🚨 LockBitSupp talks to law enforcement post-ransomware takedown. (2/25/2024, The Hacker News, &lt;a href="https://thehackernews.com/2024/02/authorities-claim-lockbit-admin.html"&gt;https://thehackernews.com/2024/02/authorities-claim-lockbit-admin.html&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;👶 Florida&amp;rsquo;s new bill against youth on social media. 2/25/2024, NY Times, &lt;a href="https://www.nytimes.com/2024/02/23/business/florida-social-media-youths.html"&gt;https://www.nytimes.com/2024/02/23/business/florida-social-media-youths.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;💸 Apple&amp;rsquo;s Vision Pro cost breakdown sparks returns. 2/25/2024, 9to5mac, &lt;a href="https://9to5mac.com/2024/02/25/heres-how-much-it-costs-apple-to-make-the-3500-vision-pro/"&gt;https://9to5mac.com/2024/02/25/heres-how-much-it-costs-apple-to-make-the-3500-vision-pro/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🌍 Five Eyes detail Russian cyberespionage in clouds. 2/26/2024, CyberScoop, &lt;a href="https://cyberscoop.com/five-eyes-nations-warn-of-evolving-russian-cyberespionage-practices-targeting-cloud-environments/"&gt;https://cyberscoop.com/five-eyes-nations-warn-of-evolving-russian-cyberespionage-practices-targeting-cloud-environments/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;📧 Massive email spam from SubdoMailing campaign. 2/26/2024, BleepingComputer, &lt;a href="https://www.bleepingcomputer.com/news/security/subdomailing-campaign-spams-5-million-emails-daily-via-8k-hijacked-domains/"&gt;https://www.bleepingcomputer.com/news/security/subdomailing-campaign-spams-5-million-emails-daily-via-8k-hijacked-domains/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 14 February 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-005/</link><pubDate>Wed, 14 Feb 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-005/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;💘 &lt;strong&gt;Roses are red, violets are blue, cyber threats don’t care… and they’re coming for you!&lt;/strong&gt; 💘&lt;/p&gt;
&lt;p&gt;This Valentine’s Day, while some are finding love, others are finding &lt;strong&gt;zero-days, ransomware, and nation-state hackers&lt;/strong&gt;. Here’s a &lt;strong&gt;cybersecurity love stories&lt;/strong&gt; you don’t want to be part of:&lt;/p&gt;
&lt;h3 id="-latest-cybersecurity-threats-and-vulnerabilities"&gt;🔥 Latest Cybersecurity Threats and Vulnerabilities&lt;/h3&gt;
&lt;p&gt;From zero-days to AI exploits, attackers are finding new ways to break into systems. Stay updated on the latest security risks.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 31 January 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-003/</link><pubDate>Wed, 31 Jan 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-003/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="-cybersecurity-news--emerging-threats"&gt;🔥 &lt;strong&gt;Cybersecurity News &amp;amp; Emerging Threats&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;From zero-day exploits to ransomware attacks, here’s what’s making waves in cybersecurity this week.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🍏 Apple patches the first actively exploited zero-day of 2025, targeting iPhone users. (Published on 1/27/2025, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/apple-fixes-this-years-first-actively-exploited-zero-day-bug/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🚨 DeepSeek AI halts new user registrations after a large-scale cyberattack disrupts operations. (Published on 1/27/2025, Hackread). &lt;a href="https://hackread.com/deepseek-large-scale-cyberattack-halts-user-registrations/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item></channel></rss>