<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Supply Chain Security on Jorge Laurel</title><link>https://jorgelaurel.com/topics/supply-chain-security/</link><description>Recent content in Supply Chain Security on Jorge Laurel</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 05 Aug 2026 18:54:26 +0000</lastBuildDate><atom:link href="https://jorgelaurel.com/topics/supply-chain-security/index.xml" rel="self" type="application/rss+xml"/><item><title>The Agent Went Off Script And A Human Reviewer Stopped It.</title><link>https://jorgelaurel.com/writing/the-agent-went-off-script-and-a-human-reviewer-stopped-it/</link><pubDate>Wed, 05 Aug 2026 18:54:26 +0000</pubDate><guid>https://jorgelaurel.com/writing/the-agent-went-off-script-and-a-human-reviewer-stopped-it/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/writing/41c6b23ea896074e.png" alt="The Agent Went Off Script And A Human Reviewer Stopped It."&gt;&lt;/p&gt;
&lt;p&gt;On 28 July 2026, the UK AI Security Institute saw data leaving one of its research systems over Tor. Within an hour, every related evaluation was terminated, the machines were isolated, and a security incident was declared. The investigation that followed did not find a sandbox escape. It found something less familiar: AI agents under test taking sustained, unsanctioned action against real people and real organizations on the live internet.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 3 April 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-119/</link><pubDate>Fri, 03 Apr 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-119/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;This week in cybersecurity was a masterclass in how fast things can go sideways. 🔐&lt;/p&gt;
&lt;p&gt;Ransomware operators are now completing full attacks in under an hour. AI platforms you use every day shipped critical vulnerabilities. A supply chain attack hit a JavaScript library with 100M+ weekly downloads. And someone accidentally leaked 512,000 lines of AI source code — which attackers immediately weaponized into a malware campaign on GitHub.&lt;/p&gt;
&lt;p&gt;If your patch queue looks overwhelming right now, you’re not alone. Chrome, Cisco, F5, Fortinet, and more all dropped critical fixes this week — many already under active exploitation before patches shipped.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 20 March 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-117/</link><pubDate>Fri, 20 Mar 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-117/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It’s Friday, which means the threat actors didn’t take the week off — and neither did we. 🛡️&lt;/p&gt;
&lt;p&gt;This week’s Friday Wrap Up covers ransomware gangs weaponizing zero-days, nation-state actors wiping devices at scale, supply-chain attacks hitting developer toolchains, AI platforms becoming the new attack surface, and a botnet that clearly skipped leg day because it never stops running. Whether you’re patching, detecting, or just trying to make it to 5pm, there’s something in this week’s roundup that probably affects your org.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 6 February 2026</title><link>https://jorgelaurel.com/archive/fwu/fwu-111/</link><pubDate>Fri, 06 Feb 2026 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-111/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another supply chain nightmare. 🎢&lt;/p&gt;
&lt;p&gt;This week’s cybersecurity roundup features everything from compromised software updates (yes, even Notepad++) to record-breaking DDoS attacks that would make your infrastructure cry. We’ve got nation-state actors playing Olympics spoiler, fintech firms losing millions of records, and AI agents getting their own social network (because apparently they need friends too).&lt;/p&gt;
&lt;p&gt;Whether you’re defending against WinRAR exploits or wondering if your antivirus just became your biggest threat, this week had something for everyone.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 28 November 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-106/</link><pubDate>Fri, 28 Nov 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-106/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;This week’s cybersecurity landscape? Let’s just say the supply chain attacks are getting creative, the credential leaks are getting embarrassing, and emergency alert systems proved they’re not immune to ransomware.&lt;/p&gt;
&lt;p&gt;From worms named after sci-fi sandworms to threat groups with identity crises, we’ve got breaches affecting everything from real estate finance to your favorite analytics platforms.&lt;/p&gt;
&lt;p&gt;Oh, and reminder: those “helpful” code formatting websites? They’ve been collecting your credentials like Pokémon cards. Click through for the full roundup of this week’s digital chaos.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 31 October 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-102/</link><pubDate>Fri, 31 Oct 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-102/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Happy Halloween! 🎃&lt;/p&gt;
&lt;p&gt;This week’s cyber threats are scarier than any haunted house. We’ve got banking trojans that disguise themselves as humans, nation-state ghosts haunting European diplomats, and AI tools conjuring up security nightmares that would make Frankenstein nervous.&lt;/p&gt;
&lt;p&gt;Ransomware ghouls are back with new tricks, supply chain vampires are draining developer credentials, and Microsoft’s DNS went dark like a haunted mansion.&lt;/p&gt;
&lt;p&gt;Whether you’re more afraid of deepfakes, zero-days, or your cloud services vanishing into thin air, this week’s wrap-up has something to give every security professional the chills.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 26 September 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-097/</link><pubDate>Fri, 26 Sep 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-097/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another batch of creative ways cybercriminals are keeping us security folks caffeinated! ☕&lt;/p&gt;
&lt;p&gt;From airports getting grounded by ransomware to AI agents accidentally becoming the world’s most helpful data thieves, this week’s threat landscape had more plot twists than a Netflix series. We saw record-breaking DDoS attacks that made previous “massive” attacks look like gentle nudges, supply chain compromises that spread faster than office gossip, and enough zero-days to make patch Tuesday feel like patch decade.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 12 September 2025</title><link>https://jorgelaurel.com/archive/fwu/fwu-095/</link><pubDate>Fri, 12 Sep 2025 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-095/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;💥 This week in cyber was one for the history books.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;📦 The world’s largest supply chain attack hit npm, with billions of downloads tainted.&lt;br&gt;
⚡ Nation-state espionage escalated as China-linked groups ramped up campaigns tied to trade negotiations.&lt;br&gt;
💻 Ransomware evolved yet again, with &lt;strong&gt;HybridPetya&lt;/strong&gt; breaking UEFI Secure Boot and Akira exploiting SonicWall appliances.&lt;br&gt;
📱 Meanwhile, Samsung scrambled to patch a WhatsApp-linked zero-day, and Apple unveiled a five-year project to shut down spyware developers.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 13 December 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-054/</link><pubDate>Fri, 13 Dec 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-054/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="category-critical-infrastructure-and-software-risks"&gt;Category: &lt;strong&gt;Critical Infrastructure and Software Risks&lt;/strong&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;⚠️ 90% of software in U.S. critical infrastructure contains code developed in China, posing systemic risks. (Published on 12/9/2024, Dark Reading). &lt;a href="https://www.darkreading.com/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🛠️ Forrester panel explores software supply chain vulnerabilities and global IT security challenges. (Published on 12/10/2024, InformationWeek). &lt;a href="https://www.informationweek.com/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 18 October 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-048/</link><pubDate>Fri, 18 Oct 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-048/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="cybersecurity-updates"&gt;Cybersecurity Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🔐 Supply chain attacks exploit entry points in open-source ecosystems like Python and npm, posing a widespread risk. (Published on 10/14/2024, The Hacker News). &lt;a href="https://thehackernews.com/2024/10/supply-chain-attacks-exploit-entry.html"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🖥️ Iranian cyberspies are exploiting a recent Windows kernel vulnerability, targeting Gulf region organizations. (Published on 10/14/2024, SecurityWeek). &lt;a href="https://www.securityweek.com/iranian-cyberspies-exploiting-recent-windows-kernel-vulnerability/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 28 June 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-030/</link><pubDate>Fri, 28 Jun 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-030/</guid><description>&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/strong&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🚀 Google is testing &amp;ldquo;Digital Credential API&amp;rdquo; for Chrome on Android to enhance secure ID verification via mobile wallets. (Published on 6/24/2024, IoT and Edge). &lt;a href="https://www.bleepingcomputer.com/news/google/chrome-for-android-tests-feature-that-securely-verifies-your-id-with-sites/"&gt;Read More&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;⚠️ The &amp;lsquo;GrimResource&amp;rsquo; attack exploits MSC files and an unpatched Windows XSS flaw for network breaches. Stay alert! (Published on 6/24/2024, BleepingComputer). &lt;a href="https://www.bleepingcomputer.com/news/security/new-grimresource-attack-uses-msc-files-and-windows-xss-flaw-to-breach-networks/"&gt;Read More&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 9 May 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-019/</link><pubDate>Thu, 09 May 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-019/</guid><description>&lt;p&gt;&lt;img src="https://jorgelaurel.com/images/fwu/fcf96d25ef594efb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Another week, another thrilling episode of &lt;em&gt;As The Cyber World Burns&lt;/em&gt; 🔥&lt;/p&gt;
&lt;p&gt;From ransomware groups getting hacked (yes, really) to backdoored npm packages, fake installers, Pegasus penalties, and one too many Mirai botnets—I’ve highlighted the news story. Even a Signal clone used by a politician decided to just&amp;hellip; stop existing.&lt;/p&gt;
&lt;p&gt;If you’re into CIO existential crises, DDoS takedowns, or wondering what “Bring Your Own Installer” could possibly mean (spoiler: nothing good), I’ve highlighted it in this week’s &lt;strong&gt;Friday Wrap Up&lt;/strong&gt;. Because in cybersecurity, the only constant is, well&amp;hellip; incident response.&lt;/p&gt;</description></item><item><title>Friday Wrap Up: 29 March 2024</title><link>https://jorgelaurel.com/archive/fwu/fwu-013/</link><pubDate>Fri, 29 Mar 2024 00:00:00 +0000</pubDate><guid>https://jorgelaurel.com/archive/fwu/fwu-013/</guid><description>&lt;hr&gt;
&lt;p&gt;It&amp;rsquo;s been a busy week in cybersecurity and time for a Friday Wrap Up. Here are some of the interesting stories from this past week.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;🔑 &lt;strong&gt;New MFA-Bypassing Phishing Kit Targets Microsoft 365, Gmail&lt;/strong&gt; - Cybercriminals exploit &amp;lsquo;Tycoon 2FA&amp;rsquo; to bypass 2FA on major email platforms. (3/25/2024, BleepingComputer) &lt;a href="https://www.bleepingcomputer.com/news/security/new-mfa-bypassing-phishing-kit-targets-microsoft-365-gmail-accounts/"&gt;Read more&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;🍏 &lt;strong&gt;iOS 17.4.1 and macOS 14.4.1 Update for Security Fixes&lt;/strong&gt; - Apple rolls out crucial security updates without much detail. (3/25/2024, 9to5 Mac) &lt;a href="https://9to5mac.com/2024/03/25/ios-17-4-1-these-2-security-fixes/"&gt;Read more&lt;/a&gt;&lt;/p&gt;</description></item></channel></rss>