<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Friday Wrap Up]]></title><description><![CDATA[Stay informed with the Friday Wrap Up weekly newsletter, delivering the top cybersecurity and technology news, trends, and insights straight to your inbox.]]></description><link>https://thefwu.com</link><image><url>https://substackcdn.com/image/fetch/$s_!lUD0!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ee5f07f-0062-4f7c-bb23-757f7b4fe405_420x420.png</url><title>Friday Wrap Up</title><link>https://thefwu.com</link></image><generator>Substack</generator><lastBuildDate>Fri, 05 Jun 2026 13:42:53 GMT</lastBuildDate><atom:link href="https://thefwu.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Jorge Laurel]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[fridaywrapup@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[fridaywrapup@substack.com]]></itunes:email><itunes:name><![CDATA[Jorge Laurel]]></itunes:name></itunes:owner><itunes:author><![CDATA[Jorge Laurel]]></itunes:author><googleplay:owner><![CDATA[fridaywrapup@substack.com]]></googleplay:owner><googleplay:email><![CDATA[fridaywrapup@substack.com]]></googleplay:email><googleplay:author><![CDATA[Jorge Laurel]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The Code Looks Fine. That's the Problem.]]></title><description><![CDATA[There is a version of this story that sounds like hype.]]></description><link>https://thefwu.com/p/the-code-looks-fine-thats-the-problem</link><guid isPermaLink="false">https://thefwu.com/p/the-code-looks-fine-thats-the-problem</guid><dc:creator><![CDATA[Jorge Laurel]]></dc:creator><pubDate>Thu, 04 Jun 2026 08:15:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!pOGc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93daafb7-a556-4b4d-ada1-5d7f8d8e2906_1376x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pOGc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93daafb7-a556-4b4d-ada1-5d7f8d8e2906_1376x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pOGc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93daafb7-a556-4b4d-ada1-5d7f8d8e2906_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!pOGc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93daafb7-a556-4b4d-ada1-5d7f8d8e2906_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!pOGc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93daafb7-a556-4b4d-ada1-5d7f8d8e2906_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!pOGc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93daafb7-a556-4b4d-ada1-5d7f8d8e2906_1376x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pOGc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93daafb7-a556-4b4d-ada1-5d7f8d8e2906_1376x768.png" width="1376" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/93daafb7-a556-4b4d-ada1-5d7f8d8e2906_1376x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1376,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2181356,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://thefwu.com/i/200582052?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93daafb7-a556-4b4d-ada1-5d7f8d8e2906_1376x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pOGc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93daafb7-a556-4b4d-ada1-5d7f8d8e2906_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!pOGc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93daafb7-a556-4b4d-ada1-5d7f8d8e2906_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!pOGc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93daafb7-a556-4b4d-ada1-5d7f8d8e2906_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!pOGc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93daafb7-a556-4b4d-ada1-5d7f8d8e2906_1376x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>There is a version of this story that sounds like hype. Chinese AI models are secretly inserting backdoors into American software. Hackers are hiding in your IDE. The threat is invisible and everywhere.</p><p>That version is wrong, and it is worth saying so clearly. Booz Allen Hamilton, which published this research in May 2026, does not claim intentional sabotage. The report is careful about that. What it does claim, backed by more than 2,800 test trials across five frontier models, is something more unsettling in its own way.</p><p>Chinese large language models, or LLMs, produce less secure code in general. And when the developer appears to be working for the U.S. government, the vulnerability score gets worse. Significantly worse.</p><p>Qwen3, a widely used Chinese coding model from Alibaba, increased its aggregate vulnerability score by 130 percent when prompted with a U.S. government persona versus a neutral one. The code still looked correct. It passed surface inspection. The flaws sat underneath, obfuscated well enough that standard enterprise tools would not catch them.</p><p>Under the same test conditions, the American model, Claude, moved in the opposite direction. The code became more secure when the government context was added.</p><p>Three of the four Chinese models tested produced this pattern. The fourth, Kimi K2.5, was the exception.</p><p><strong>Why Developers Are Reaching for These Models</strong></p><p>Before getting into why the vulnerabilities exist, it is worth understanding why Chinese models are spreading so fast. The answer is cost, and the numbers are not subtle.</p><p>Per-token inference costs on premium American models can run $25 per million output tokens or more at list price. Open-weight Chinese models are available at a fraction of that, and some can be run locally, eliminating API costs entirely. For a startup burning through tokens on a coding agent or an engineering team facing unexpected AI spend, the savings are real and immediate.</p><p>Enterprise AI spending has already moved in a direction that makes this pressure worse. Average organizational spending on AI-native applications more than doubled year over year in 2025, according to Zylo&#8217;s 2026 SaaS Management Index. Nearly 80 percent of IT leaders reported unexpected charges tied to consumption-based AI pricing. When the bill arrives and leadership asks why, the cheapest capable model starts looking like the obvious answer.</p><p>The term &#8220;tokenmaxxing&#8221; emerged this year to describe maximizing token usage as a productivity signal. Some executives are celebrating engineers who burn through the most tokens. In that environment, cost per token becomes a real procurement driver, and Chinese open-weight models offer a straightforward way to reduce it.</p><p>That is the context in which Qwen3 ends up inside a development pipeline. Not espionage. Economics.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JQor!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12d2c826-852b-4393-a8ca-d0bbaa164551_2752x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JQor!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12d2c826-852b-4393-a8ca-d0bbaa164551_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!JQor!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12d2c826-852b-4393-a8ca-d0bbaa164551_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!JQor!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12d2c826-852b-4393-a8ca-d0bbaa164551_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!JQor!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12d2c826-852b-4393-a8ca-d0bbaa164551_2752x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JQor!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12d2c826-852b-4393-a8ca-d0bbaa164551_2752x1536.png" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/12d2c826-852b-4393-a8ca-d0bbaa164551_2752x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4461110,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://thefwu.com/i/200582052?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12d2c826-852b-4393-a8ca-d0bbaa164551_2752x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JQor!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12d2c826-852b-4393-a8ca-d0bbaa164551_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!JQor!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12d2c826-852b-4393-a8ca-d0bbaa164551_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!JQor!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12d2c826-852b-4393-a8ca-d0bbaa164551_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!JQor!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12d2c826-852b-4393-a8ca-d0bbaa164551_2752x1536.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Why This Happens</strong></p><p>The report points to two mechanisms behind the vulnerability pattern. The first is training data. Chinese law requires AI models, their training outputs, and their data to reflect what Beijing calls &#8220;Core Socialist Values.&#8221; The models learn from an internet shaped by Chinese government information controls. That shapes what they produce.</p><p>The second is prompt steering, the methods used to guide how a model answers questions. Those methods can influence outputs in ways that are subtle and hard to audit from the outside.</p><p>Neither mechanism requires a human decision to insert a vulnerability. The risk can emerge from how the model was built, not from a deliberate act at inference time. That is what makes it hard to detect and harder to remediate.</p><p><strong>The Second Finding</strong></p><p>The vulnerability data alone justifies concern. But Booz Allen&#8217;s second finding adds a different dimension.</p><p>Every Chinese model tested refused to generate code for tasks Beijing would oppose. Security audits for U.S. weapons systems. Code for platforms involving Taiwanese independence or Hong Kong democracy. In several cases, the models did not just decline. They recited China&#8217;s official restrictions verbatim.</p><p>MiniMax refused predeployment safety reviews for U.S. weapons systems, the same work that Department of War software assurance teams do as standard practice.</p><p>A model that applies Chinese law to American developers is not a neutral tool. It is a policy instrument, whether or not anyone designed it that way.</p><p><strong>We Have Seen This Movie</strong></p><p>The Huawei and ZTE parallel is not decorative. It is the most useful frame available for understanding what is at stake.</p><p>The U.S. spent roughly a decade watching Chinese telecommunications manufacturers establish a foothold in American infrastructure. The price advantage was real. The security risk was documented but contested. By the time a coordinated policy response formed, the rip-and-replace cost in the U.S. alone ran into the billions. That work is still ongoing.</p><p>The Chinese open-source AI ecosystem presents a faster-moving version of the same problem. Qwen3, the worst performer in Booz Allen&#8217;s testing, is already available inside broadly used software development tools. The adoption curve is steep because the cost advantage is real. Chinese models are cheaper, and teams facing token cost pressure choose cheaper.</p><p>Once that code is in production, embedded in delivered systems across critical infrastructure and national security environments, tracing it becomes nearly impossible. Remediation at that point may not be feasible at all.</p><p><strong>What Practitioners Should Do</strong></p><p>The Booz Allen recommendations cover four audiences. For security practitioners and critical infrastructure operators, the immediate priority is auditing development environments. That means identifying which AI coding tools are in use, which models those tools run on, and whether any Chinese models are generating code for sensitive workflows.</p><p>That audit should happen before an incident, not in response to one.</p><p>For organizations in regulated industries or government-adjacent work, the report recommends defaulting to trusted U.S. or allied models with accountable vendors and stronger security controls. The cost difference between Chinese and American models is real, but it does not account for remediating vulnerable code, managing compliance exposure, or explaining to a customer how their system was built.</p><p>Booz Allen makes a pointed observation on this: a lower-cost model may look attractive upfront, especially for startups or cost-constrained teams, but that same model can become more expensive over time if it generates vulnerable code or introduces behavior that standard enterprise controls do not catch. The token savings have a liability attached.</p><p>The policy picture is also moving. The Department of War and some U.S. government agencies have already banned Chinese AI models on government systems. The Booz Allen report argues that ban should extend upstream into the full software supply chain.</p><p><strong>The Window</strong></p><p>The report closes with a direct statement. Reversing U.S. reliance on Chinese AI models today will be orders of magnitude cheaper than trying to remediate the damage once these models are fully embedded, if remediation is even possible at that point.</p><p>That framing is worth taking seriously. Not because the threat is invisible and everywhere, but because it is already present, already measurable, and still addressable.</p><p>The window is open. The question is whether the industry and government use it before the same slow-motion policy failure that defined the Huawei decade plays out again, this time inside the code.</p><div class="callout-block" data-callout="true"><p>AI helped me write this. Not before I read the sources, but after. I read the content, formed a view, and identified what mattered. The writing assistance came last and I edited the AI generated content. </p><p>I have a full-time job and this is not a content generation operation, so I use AI as a tool to help me post.</p></div><div><hr></div><p><strong>References</strong></p><p>Booz Allen Hamilton. (2026). <em>What&#8217;s in America&#8217;s code? There are major risks with allowing Chinese LLMs to code for U.S. applications.</em> Booz Allen Hamilton. https://www.boozallen.com</p><p>Claburn, T. (2026, April 26). Tokenmaxxing isn&#8217;t an AI strategy. <em>The Register.</em> https://www.theregister.com</p><p>Coimbra, V. (2026, April 1). Is AI really getting cheaper? The token cost illusion. <em>Artefact.</em> https://www.artefact.com</p><p>Ghita, G. (2026, May 5). The 5 hidden costs of building an AI startup in 2026. <em>SemNexus.</em> https://www.semnexus.com</p><p>Loizos, C. (2026, March 22). Are AI tokens the new signing bonus or just a cost of doing business? <em>TechCrunch.</em> https://techcrunch.com</p><p>Nieva, R. (2026, March 31). The &#8216;AI gods&#8217; spending as much as they can on AI tokens. <em>Forbes.</em> https://www.forbes.com</p><p>Sargent, H. (2026, May 4). What are AI tokens and why are they costing companies millions? <em>Kelly Services.</em> https://www.kellyservices.com</p><p>Tangermann, V. (2026, April 24). The horrible economics of AI are starting to come crashing down. <em>Futurism.</em> https://futurism.com</p><p>Zylo. (2026). <em>2026 SaaS management index.</em> Zylo. https://www.zylo.com</p>]]></content:encoded></item><item><title><![CDATA[Why the Chips, Power, and Data Centers Behind AI Can't Keep Up]]></title><description><![CDATA[In late March, heavy Claude users started posting screenshots of something very odd, their five hour usage limits were running out in twenty minutes.]]></description><link>https://thefwu.com/p/why-the-chips-power-and-data-centers</link><guid isPermaLink="false">https://thefwu.com/p/why-the-chips-power-and-data-centers</guid><dc:creator><![CDATA[Jorge Laurel]]></dc:creator><pubDate>Sat, 16 May 2026 12:49:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!h0Nz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed40d4ef-c962-47f1-82cd-c8adcdcdd79e_1376x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!h0Nz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed40d4ef-c962-47f1-82cd-c8adcdcdd79e_1376x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!h0Nz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed40d4ef-c962-47f1-82cd-c8adcdcdd79e_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!h0Nz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed40d4ef-c962-47f1-82cd-c8adcdcdd79e_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!h0Nz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed40d4ef-c962-47f1-82cd-c8adcdcdd79e_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!h0Nz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed40d4ef-c962-47f1-82cd-c8adcdcdd79e_1376x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!h0Nz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed40d4ef-c962-47f1-82cd-c8adcdcdd79e_1376x768.png" width="1376" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ed40d4ef-c962-47f1-82cd-c8adcdcdd79e_1376x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1376,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2080449,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://thefwu.com/i/197991149?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed40d4ef-c962-47f1-82cd-c8adcdcdd79e_1376x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!h0Nz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed40d4ef-c962-47f1-82cd-c8adcdcdd79e_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!h0Nz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed40d4ef-c962-47f1-82cd-c8adcdcdd79e_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!h0Nz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed40d4ef-c962-47f1-82cd-c8adcdcdd79e_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!h0Nz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed40d4ef-c962-47f1-82cd-c8adcdcdd79e_1376x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In late March, heavy Claude users started posting screenshots of something very odd, their five hour usage limits were running out in twenty minutes. Anthropic blamed peak hour demand and blocked third party tools from using its flat rate plans. OpenAI quietly shut down its Sora video platform around the same time as its Codex tool surged past four million developers per week. What looked like routine product decisions were actually the first visible signs of an infrastructure problem that is only going to get harder to solve.</p><p>The math is uncomfortable. Running an AI model for users costs real money every single time and it scales directly with usage. If ten times more people use AI tools ten times more heavily, companies then need roughly one hundred times more computing power to keep up. The ratio is about to get worse. Agentic AI systems, that autonomously handle complex multi-step tasks without human input at each stage, can consume ten to one hundred times more compute per session than a standard conversation. As that model of use spreads across business workflows, the demand curve get very steep very fast.</p><p>The supply of chips is the first place that pressure is showing up in. Orders for Nvidia GPUs are growing to $1 trillion through 2027, double of that a year ago, with lead times stretching closer to a year. All three makers of high bandwidth memory, which specialized chips AI systems depend on, are sold out for 2026. TSMC fabricates about 90 percent of the world&#8217;s most advanced chips. Its CEO said in late 2025 that demand was running three times what the company could produce. The 2nm fabrication lines are booked through 2028, and its next planned U.S. facility is already fully committed before ground has been broken. Building new chip fabrication capacity takes two to four years. The chip shortage will persist.</p><p>Power is the next wall. A modern data center can be built in two to three years, but getting reliable electricity to run it takes much longer. Natural gas plants take five to seven years. Nuclear takes ten or more. Even solar, factoring in grid connection timelines, can take two to four years. In February 2025, Dominion Energy Virginia reported requests for 40.2 gigawatts of new data center power connections, nearly double of what had been requested six months earlier. Anthropic has projected that the U.S. AI sector needs at least 50 gigawatts of capacity by 2028. S&amp;P Global estimates that the data center industry needs roughly $200 billion per year globally just to build planned capacity, before taking in the cost of equipment or grid infrastructure buildout.</p><p>Governments are treating this as a strategic issue, not just a technology one. The UK published a compute roadmap in 2025, committing up to &#163;2 billion to expand its AI research computing 20x by 2030 and projections that frontier AI demand could grow ten thousand times by 2030. Industry groups have identified that semiconductor supply chains, relying on a small number of companies spread across global networks, remain a significant vulnerability that national AI strategies have barely begun to address. At the Pentagon, the Chief Digital and AI Officer said publicly that compute is the military&#8217;s top constraint. His framing was blunt &#8220;We&#8217;ve handed our warfighters a Ferrari, and my only sleepless nights come from making sure we never, ever run out of the high octane fuel that they need, which is compute.&#8221;</p><p>The leaders of OpenAI, Google, Meta, Amazon, and Microsoft have all said publicly they cannot get chips fast enough. NVIDIA&#8217;s CEO put it plainly by stating that doubling compute access for its top customers would increase their revenues fourfold. That demand is not slowing. AI is moving, or has moved, into coding, healthcare, legal work, finance, and military operations. Every one of those use cases adds to the load. The infrastructure to support that load is measured in years to build. The demand is not waiting.</p><div><hr></div><p><em>References</em></p><p>Sanders, J., Egan, J., &amp; Madigan, R. (2026, May 7). <em>American AI companies can&#8217;t get enough chips</em>. Center for a New American Security. <strong><a href="https://www.cnas.org/publications/reports/american-ai-companies-cant-get-enough-chips">https://www.cnas.org/publications/reports/american-ai-companies-cant-get-enough-chips</a></strong></p><p>Harper, J. (2026, May 7). DOD planning to address compute &#8216;bottleneck&#8217; that could hinder AI proliferation. <em>Defense Scoop</em>. <strong><a href="https://defensescoop.com/2026/05/07/dod-planning-to-address-compute-bottleneck-ai-proliferation/">https://defensescoop.com/2026/05/07/dod-planning-to-address-compute-bottleneck-ai-proliferation/</a></strong></p><p>Aliaga, S. (2026, April 17). Is AI running out of compute? <em>J.P. Morgan Asset Management</em>. <strong><a href="https://am.jpmorgan.com/us/en/asset-management/adv/insights/market-insights/market-updates/on-the-minds-of-investors/is-ai-running-out-of-compute/">https://am.jpmorgan.com/us/en/asset-management/adv/insights/market-insights/market-updates/on-the-minds-of-investors/is-ai-running-out-of-compute/</a></strong></p><p>Department for Science, Innovation and Technology. (2025, July 17). <em>UK compute roadmap</em>. UK Government. <strong><a href="https://www.gov.uk/government/publications/uk-compute-roadmap/uk-compute-roadmap">https://www.gov.uk/government/publications/uk-compute-roadmap/uk-compute-roadmap</a></strong></p><p>B&#233;chard, D. E. (2026, May 1). What is the AI compute crunch, and why are AI tools hitting usage limits? <em>Scientific American</em>. <strong><a href="https://www.scientificamerican.com/article/what-is-the-ai-compute-crunch-and-why-are-ai-tools-hitting-usage-limits/">https://www.scientificamerican.com/article/what-is-the-ai-compute-crunch-and-why-are-ai-tools-hitting-usage-limits/</a></strong></p><p>Morgan, K., &amp; Partridge, B. (2025, December 2). <em>Global AI power demand: Challenges and opportunities</em>. S&amp;P Global. <strong><a href="https://www.spglobal.com/en/research-insights/special-reports/look-forward/data-center-frontiers/global-ai-power-demand-challenges-opportunities">https://www.spglobal.com/en/research-insights/special-reports/look-forward/data-center-frontiers/global-ai-power-demand-challenges-opportunities</a></strong></p><p>Foster, L. (2025, January 13). Compute infrastructure and the AI opportunities action plan. <em>techUK</em>. <strong><a href="https://www.techuk.org/resource/compute-infrastructure-and-the-ai-opportunities-action-plan.html">https://www.techuk.org/resource/compute-infrastructure-and-the-ai-opportunities-action-plan.html</a></strong></p>]]></content:encoded></item><item><title><![CDATA[The Cost of AI: Tokens]]></title><description><![CDATA[Several patterns emerged from the past six months of enterprise AI spending.]]></description><link>https://thefwu.com/p/the-cost-of-ai-tokens</link><guid isPermaLink="false">https://thefwu.com/p/the-cost-of-ai-tokens</guid><dc:creator><![CDATA[Jorge Laurel]]></dc:creator><pubDate>Wed, 06 May 2026 20:19:30 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!wvgg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66580626-8275-4ae7-ae23-b115f468a11b_1376x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wvgg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66580626-8275-4ae7-ae23-b115f468a11b_1376x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wvgg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66580626-8275-4ae7-ae23-b115f468a11b_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!wvgg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66580626-8275-4ae7-ae23-b115f468a11b_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!wvgg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66580626-8275-4ae7-ae23-b115f468a11b_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!wvgg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66580626-8275-4ae7-ae23-b115f468a11b_1376x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wvgg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66580626-8275-4ae7-ae23-b115f468a11b_1376x768.png" width="1376" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/66580626-8275-4ae7-ae23-b115f468a11b_1376x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1376,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2107163,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://thefwu.com/i/196705094?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66580626-8275-4ae7-ae23-b115f468a11b_1376x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wvgg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66580626-8275-4ae7-ae23-b115f468a11b_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!wvgg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66580626-8275-4ae7-ae23-b115f468a11b_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!wvgg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66580626-8275-4ae7-ae23-b115f468a11b_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!wvgg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66580626-8275-4ae7-ae23-b115f468a11b_1376x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Several patterns emerged from the past six months of enterprise AI spending. First, token prices dropped sharply. Second, companies spent more money anyway. Third, executives started celebrating engineers who burned through the most tokens. The gap between those three facts reveals something important about how AI costs actually work.<br><br>The numbers are straightforward. Per-token inference costs fell roughly 75% year-over-year according to enterprise spending data from Ramp. Epoch AI research suggests the decline approaches 200x annually when accounting for both pricing and efficiency gains. Competition among model providers, open-weight alternatives, and hardware improvements all pushed prices down. The collapse is real and significant.<br><br>But total AI spending moved in the opposite direction. Organizations spent an average of $1.2 million on AI-native applications in 2025, more than double the prior year, according to Zylo's 2026 SaaS Management Index. Nearly 80% of IT leaders reported unexpected charges tied to consumption-based AI pricing. The bill went up even as the unit cost went down.<br><br>The disconnect stems from how consumption patterns changed. Databricks CEO Ali Ghodsi singled out an engineer who spent over $7,000 in tokens during a two-week period in January. The company held a meeting where everyone applauded. Meta CTO Andrew Bosworth called token spending "easy money" with "no limit." The term "tokenmaxxing" emerged to describe maximizing token usage as a productivity metric.<br><br>Token pricing varies widely. Basic tasks on cheaper models can cost a few cents per million tokens. Complex computations on premium models run from $20 to over $100 per million tokens. Anthropic charges $25 per million output tokens for Claude Opus 4.6. Those are list prices. Actual costs depend on utilization rates, which rarely hit 100%. At 30% utilization, base inference costs on an H100 GPU jump from $0.0038 per million tokens to roughly $0.013. At 10% utilization, the cost reaches $0.038.<br><br>The pricing structure creates a paradox. Falling per-token costs make AI seem cheaper, which encourages higher consumption. That higher consumption often cancels out the savings and pushes total costs higher. Appfigures data showed that image model releases drove 6.5x more downloads than traditional model updates. ChatGPT added 12 million incremental installs in the 28 days after introducing its GPT-4o image model. More usage means more tokens processed, which means larger bills regardless of unit price.<br><br>Infrastructure constraints are starting to appear. Anthropic cut off millions of users from OpenClaw after it overwhelmed their systems. The company shifted to pay-as-you-go billing instead of open-ended usage limits. Capacity is finite, and providers are prioritizing customers who pay per token over those on flat subscriptions. Gartner analyst Will Sommer told The Verge that AI companies would need close to $2 trillion in annual revenue by the end of the decade to cover infrastructure costs. Current pricing models do not support that math.<br><br>The operational costs extend beyond token prices. Semantic caching, prompt compression, and utilization optimization can reduce token consumption by 40% to 60%, but those require engineering resources. Data preparation and cleaning add another layer of expense. RAG systems need structured data, which means dedicated engineering work before the first query runs. Then there are MLOps costs, monitoring infrastructure, and the labor required to manage prompt injection attacks and model degradation.<br><br>Stanford HAI's 2026 AI Index Report noted that US private AI investment reached $285.9 billion in 2025. AI data center power capacity hit 29.6 gigawatts, comparable to New York state at peak demand. Annual GPT-4o inference water use may exceed the drinking water needs of 12 million people. Those environmental and infrastructure pressures will eventually flow through to pricing.<br><br>The current moment resembles the early cloud computing era when per-instance pricing dropped while total cloud spending climbed. The difference is that AI consumption scales faster and less predictably than traditional compute. A viral feature or unexpected usage pattern can multiply costs overnight. Organizations are discovering that cheaper tokens do not mean cheaper AI, just more consumption at lower unit economics until the bill arrives.<br><br>Sources:<br></p><ul><li><p>Richard Nieva, "The 'AI Gods' Spending As Much As They Can On AI Tokens," Forbes, March 31, 2026.</p></li><li><p>Victor Tangermann, "The Horrible Economics of AI Are Starting to Come Crashing Down," Futurism, April 24, 2026.</p></li><li><p>Thomas Claburn, "Tokenmaxxing isn't an AI strategy," The Register, April 26, 2026.</p></li><li><p>Victor Coimbra, "Is AI really getting cheaper? The token cost illusion," Artefact, April 1, 2026.</p></li><li><p>Hilary Sargent, "What Are AI Tokens &#8212; and Why Are They Costing Companies Millions?" Kelly Services, May 4, 2026.</p></li><li><p>Connie Loizos, "Are AI tokens the new signing bonus or just a cost of doing business?" TechCrunch, March 22, 2026.</p></li><li><p>Ghita Ghita, "The 5 Hidden Costs of Building an AI Startup in 2026," SemNexus, May 5, 2026.</p></li><li><p>Stanford HAI, "2026 Artificial Intelligence Index Report," 2026.</p></li><li><p>Zylo, "2026 SaaS Management Index," 2026.</p></li></ul>]]></content:encoded></item><item><title><![CDATA[Friday Wrap Up: 3 April 2026]]></title><description><![CDATA[This week in cybersecurity was a masterclass in how fast things can go sideways.]]></description><link>https://thefwu.com/p/friday-wrap-up-3-april-2026</link><guid isPermaLink="false">https://thefwu.com/p/friday-wrap-up-3-april-2026</guid><dc:creator><![CDATA[Jorge Laurel]]></dc:creator><pubDate>Fri, 03 Apr 2026 19:01:07 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" width="550" height="320.8333333333333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:420,&quot;width&quot;:720,&quot;resizeWidth&quot;:550,&quot;bytes&quot;:204370,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>This week in cybersecurity was a masterclass in how fast things can go sideways. &#128272;</p><p>Ransomware operators are now completing full attacks in under an hour. AI platforms you use every day shipped critical vulnerabilities. A supply chain attack hit a JavaScript library with 100M+ weekly downloads. And someone accidentally leaked 512,000 lines of AI source code &#8212; which attackers immediately weaponized into a malware campaign on GitHub.</p><p>If your patch queue looks overwhelming right now, you&#8217;re not alone. Chrome, Cisco, F5, Fortinet, and more all dropped critical fixes this week &#8212; many already under active exploitation before patches shipped.</p><p>Check out this week&#8217;s Friday Wrap-Up for the full breakdown. &#128071;</p><p><strong>#Cybersecurity</strong> <strong>#PatchManagement</strong> <strong>#SupplyChainSecurity</strong> <strong>#FWU</strong> <strong>#fridaywrapup</strong> <strong>#Malware</strong> <strong>#DataBreach</strong> <strong>#Ransomware</strong></p><p></p><div><hr></div><h2>Major Cyberattacks &amp; Incidents</h2><p><em>This week&#8217;s breach roundup spans AI firms, healthcare, toys, and crypto &#8212; a reminder that no sector is immune when attackers are operating at this pace and scale.</em></p><ul><li><p>&#128275; AI recruitment firm Mercor confirmed a breach stemming from a LiteLLM supply chain attack. Hackers claim to have exfiltrated 4TB of sensitive data, including user records and internal systems. (Published on April 3, 2026, Hackread). <a href="https://hackread.com/ai-firm-mercor-breach-hackers-4tb-data/">Read More</a></p></li><li><p>&#128373;&#65039; The ShinyHunters group claims to have stolen over 3 million Cisco records via Salesforce and AWS, threatening a public data leak if their demands are not met. (Published on April 2, 2026, Hackread). <a href="https://hackread.com/shinyhunters-hackers-cisco-records-data-leak/">Read More</a></p></li><li><p>&#127973; A January 2026 cyberattack on Nacogdoches Memorial Hospital compromised personal and health information belonging to 250,000 patients after a threat actor breached the hospital&#8217;s internal network. (Published on April 2, 2026, SecurityWeek). <a href="https://www.securityweek.com/250000-affected-by-data-breach-at-nacogdoches-memorial-hospital/">Read More</a></p></li><li><p>&#127922; Toy giant Hasbro is investigating a cyberattack that may have resulted in file compromise. The full scope of the breach is still under determination, with no confirmed exfiltration yet. (Published on April 1, 2026, SecurityWeek). <a href="https://www.securityweek.com/toy-giant-hasbro-hit-by-cyberattack/">Read More</a></p></li><li><p>&#128184; A Maryland man faces federal charges for allegedly exploiting smart contract vulnerabilities to steal $53 million from Uranium Finance and laundering the proceeds through crypto mixing services. (Published on March 31, 2026, Infosecurity). <a href="https://www.infosecurity-magazine.com/news/man-charged-uranium-crypto-hack/">Read More</a></p></li></ul><h2>Malware &amp; Vulnerabilities</h2><p><em>From AI-generated evasion code to ransomware completing full attacks in under an hour, threat actors are raising the bar on speed and sophistication this week.</em></p><ul><li><p>&#128241; A new SparkCat malware variant found in App Store and Google Play apps uses OCR to scan images for crypto wallet recovery phrases, hidden inside seemingly legitimate applications. (Published on April 3, 2026, The Hacker News). <a href="https://thehackernews.com/2026/04/new-sparkcat-variant-in-ios-android.html">Read More</a></p></li><li><p>&#128013; Threat actors are exploiting Anthropic&#8217;s Claude Code source code leak by publishing fake GitHub repositories that deliver Vidar information-stealing malware to unsuspecting developers. (Published on April 2, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/claude-code-leak-used-to-push-infostealer-malware-on-github/">Read More</a></p></li><li><p>&#129440; DeepLoad, a newly discovered malware, is distributed via ClickFix social engineering attacks. It steals credentials, installs a malicious browser extension, and can self-propagate via USB drives. (Published on April 1, 2026, SecurityWeek). <a href="https://www.securityweek.com/new-deepload-malware-dropped-in-clickfix-attacks/">Read More</a></p></li><li><p>&#129302; ReliaQuest researchers warn that DeepLoad leverages AI-generated code alongside ClickFix techniques to evade detection while persistently targeting enterprise credentials across organizations. (Published on March 30, 2026, Infosecurity). <a href="https://www.infosecurity-magazine.com/news/deepload-malware-clickfix-ai-code/">Read More</a></p></li><li><p>&#128232; Microsoft warns of a WhatsApp-based campaign tricking users into executing malicious Visual Basic Script files, enabling attackers to establish persistence and remote access on compromised systems. (Published on April 1, 2026, CSO Online). <a href="https://www.csoonline.com/article/4153092/whatsapp-malware-campaign-uses-malicious-vbs-files-to-gain-persistent-access.html">Read More</a></p></li><li><p>&#128230; Attackers hijacked the npm account of Axios &#8212; a JavaScript HTTP client with over 100 million weekly downloads &#8212; distributing remote access trojans targeting Linux, Windows, and macOS systems. (Published on March 31, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/hackers-compromise-axios-npm-package-to-drop-cross-platform-malware/">Read More</a></p></li><li><p>&#128740;&#65039; A newly identified implant named RoadK1ll uses WebSocket communications to enable threat actors to quietly move laterally from a compromised host to other systems on the internal network. (Published on March 30, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/new-roadk1ll-websocket-implant-used-to-pivot-on-breached-networks/">Read More</a></p></li><li><p>&#127479;&#127482; A Russian-origin remote access toolkit called CTRL spreads through malicious Windows shortcut files disguised as private key folders, hijacking RDP sessions via FRP tunneling. (Published on March 30, 2026, The Hacker News). <a href="https://thehackernews.com/2026/03/russian-ctrl-toolkit-delivered-via.html">Read More</a></p></li><li><p>&#9201;&#65039; Halcyon researchers report that the Akira ransomware group can now execute a full attack &#8212; from initial access to encryption &#8212; in under one hour, dramatically shrinking defender response windows. (Published on April 2, 2026, Infosecurity). <a href="https://www.infosecurity-magazine.com/news/researchers-subonehour-ransomware/">Read More</a></p></li></ul><h2>Critical Vulnerabilities &amp; Patches</h2><p><em>A relentless wave of critical patches hit this week across Cisco, Chrome, F5, Fortinet, and AI platforms &#8212; with many already under active exploitation, making patch fatigue a luxury no one can afford.</em></p><ul><li><p>&#128295; Cisco released patches for a critical authentication bypass in its Integrated Management Controller affecting many servers and appliances, allowing unauthenticated remote attackers to gain admin access. (Published on April 2, 2026, CSO Online). <a href="https://www.csoonline.com/article/4154052/cisco-fixes-critical-imc-auth-bypass-present-in-many-products.html">Read More</a></p></li><li><p>&#9888;&#65039; Cisco also patched several high-severity IMC vulnerabilities that, combined with the critical auth bypass, could allow unauthenticated attackers to gain full administrative control over enterprise hardware. (Published on April 2, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/critical-cisco-imc-auth-bypass-gives-attackers-admin-access/">Read More</a></p></li><li><p>&#128249; Attackers are actively exploiting a zero-day in TrueConf conference servers that executes arbitrary files across all connected endpoints by pushing malicious software updates to clients. (Published on April 1, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-trueconf-zero-day-to-push-malicious-software-updates/">Read More</a></p></li><li><p>&#127760; Google released emergency Chrome updates addressing 21 vulnerabilities, including a high-severity use-after-free zero-day in Dawn (CVE-2026-5281) that has been actively exploited in the wild. (Published on April 1, 2026, The Hacker News). <a href="https://thehackernews.com/2026/04/new-chrome-zero-day-cve-2026-5281-under.html">Read More</a></p></li><li><p>&#129302; Vulnerabilities in the CrewAI multi-agent AI framework can be exploited via prompt injection, allowing attackers to chain bugs, escape sandboxes, and execute arbitrary code on host devices. (Published on March 31, 2026, SecurityWeek). <a href="https://www.securityweek.com/crewai-vulnerabilities-expose-devices-to-hacking/">Read More</a></p></li><li><p>&#9729;&#65039; A security blind spot in Google Cloud&#8217;s Vertex AI could allow weaponized AI agents to gain unauthorized access to sensitive data and compromise an organization&#8217;s entire cloud environment. (Published on March 31, 2026, The Hacker News). <a href="https://thehackernews.com/2026/03/vertex-ai-vulnerability-exposes-google.html">Read More</a></p></li><li><p>&#128274; A critical SQL injection flaw in Fortinet&#8217;s FortiManager (CVE-2026-21643) is under active exploitation, allowing unauthenticated attackers to fully compromise enterprise management servers remotely. (Published on March 30, 2026, CSO Online). <a href="https://www.csoonline.com/article/4152117/fortinet-hit-by-another-exploited-cybersecurity-flaw.html">Read More</a></p></li><li><p>&#128273; A flaw in OpenAI&#8217;s Codex allowed attackers to steal GitHub tokens by exploiting hidden Unicode command injection embedded in maliciously crafted branch names within code repositories. (Published on March 30, 2026, Hackread). <a href="https://hackread.com/openai-codex-vulnerability-steal-github-tokens/">Read More</a></p></li><li><p>&#128272; A 15-year-old integer underflow bug in strongSwan&#8217;s EAP-TTLS plugin allows attackers to crash VPN services, with multiple versions affected across widely deployed global installations. (Published on March 30, 2026, Hackread). <a href="https://hackread.com/strongswan-flaw-attackers-crash-vpn-integer-underflow/">Read More</a></p></li><li><p>&#128680; F5 reclassified a BIG-IP APM flaw from denial-of-service to critical RCE after confirming active exploitation, with attackers deploying webshells on unpatched devices. Patch immediately. (Published on March 30, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/hackers-now-exploit-critical-f5-big-ip-flaw-in-attacks-patch-now/">Read More</a></p></li></ul><h2>Credential Harvesting &amp; Phishing</h2><p><em>Attackers are automating credential theft at scale this week, sweeping hundreds of Next.js servers and targeting LinkedIn professionals with convincing lookalike campaigns.</em></p><ul><li><p>&#127907; Attackers using automated scanning and the Nexus Listener framework exploited React2Shell to compromise over 750 systems in a coordinated, large-scale credential harvesting operation. (Published on April 3, 2026, SecurityWeek). <a href="https://www.securityweek.com/react2shell-exploited-in-large-scale-credential-harvesting-campaign/">Read More</a></p></li><li><p>&#128477;&#65039; Exploiting CVE-2025-55182, attackers breached 766 Next.js hosts to steal database credentials, SSH keys, AWS secrets, Stripe API keys, and GitHub tokens en masse. (Published on April 2, 2026, The Hacker News). <a href="https://thehackernews.com/2026/04/hackers-exploit-cve-2025-55182-to.html">Read More</a></p></li><li><p>&#128231; A LinkedIn phishing campaign uses fake notification emails and convincing lookalike domains to steal credentials, hijack professional accounts, and access sensitive business data at scale. (Published on April 1, 2026, Hackread). <a href="https://hackread.com/linkedin-phishing-scam-fake-notificatioms-hijack-accounts/">Read More</a></p></li></ul><h2>Espionage &amp; Nation-State Activity</h2><p><em>Russia&#8217;s Star Blizzard is upgrading its mobile arsenal, adopting a sophisticated iOS exploit kit to sharpen campaigns against high-value government and institutional targets worldwide.</em></p><ul><li><p>&#127784;&#65039; Russian state-sponsored APT Star Blizzard is using the DarkSword iOS exploit kit in campaigns targeting government, higher education, financial, legal entities, and think tanks globally. (Published on March 30, 2026, SecurityWeek). <a href="https://www.securityweek.com/russian-apt-star-blizzard-adopts-darksword-ios-exploit-kit/">Read More</a></p></li></ul><h2>AI &amp; Policy</h2><p><em>Anthropic had a rough week operationally &#8212; an accidental source code leak revealed details of a powerful new AI model, and attackers immediately turned the exposure into a malware delivery campaign.</em></p><ul><li><p>&#129318; Human error at Anthropic exposed over 512,000 lines of Claude AI source code, inadvertently revealing internal projects codenamed KAIROS and Capybara and prompting a shift to the Native Installer. (Published on April 1, 2026, Hackread). <a href="https://hackread.com/anthropic-leaks-claude-ai-code-blunder/">Read More</a></p></li><li><p>&#129504; Details of Anthropic&#8217;s Mythos &#8212; described as its most capable AI model yet, with enhanced reasoning and coding skills &#8212; leaked unintentionally via a CMS data exposure, bypassing any planned announcement. (Published on March 30, 2026, CSO Online). <a href="https://www.csoonline.com/article/4151801/leak-reveals-anthropics-mythos-a-powerful-ai-model-aimed-at-cybersecurity-use-cases.html">Read More</a></p></li></ul><h2>DDoS, Outages &amp; Infrastructure</h2><p><em>Microsoft&#8217;s Exchange Online continues to battle mailbox reliability issues, leaving Outlook users on mobile and macOS dealing with intermittent disruptions stretching into their third week.</em></p><ul><li><p>&#128236; Microsoft is investigating persistent Exchange Online mailbox access problems intermittently affecting Outlook mobile and macOS users for weeks, with no confirmed resolution timeline yet. (Published on April 3, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-still-working-to-fix-exchange-online-mailbox-access-issues/">Read More</a></p></li></ul><p></p><div><hr></div><p>Stay informed and secure in the tech and cybersecurity world. Have a great weekend, and remember to patch and protect your systems!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://thefwu.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Friday Wrap Up! Subscribe and never miss a weekly edition!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Friday Wrap Up: 27 March 2026]]></title><description><![CDATA[This week: a pro-Iranian group hacked the FBI Director's personal email.]]></description><link>https://thefwu.com/p/friday-wrap-up-27-march-2026</link><guid isPermaLink="false">https://thefwu.com/p/friday-wrap-up-27-march-2026</guid><dc:creator><![CDATA[Jorge Laurel]]></dc:creator><pubDate>Fri, 27 Mar 2026 20:01:38 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" width="550" height="320.8333333333333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:420,&quot;width&quot;:720,&quot;resizeWidth&quot;:550,&quot;bytes&quot;:204370,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>This week: a pro-Iranian group hacked the FBI Director's personal email. North Korean hackers got hired for remote IT jobs. TeamPCP backdoored yet another PyPI package. And an iPhone exploit kit has evolved directly from the zero-click campaign that hit Russian targets back in 2023.<br><br>In the "things we didn't need" column: GlassWorm now uses the Solana blockchain to route its malware payloads, a new infostealer bypasses Chrome's Application-Bound Encryption, and a QR code phishing campaign somehow slipped past SPF, DKIM, AND DMARC at scale &#8212; 1.6 million emails delivered, no alarm raised.<br><br>It's a lot. Click through for 34 stories across 6 categories, and maybe patch your NetScaler while you're at it.<br><br>#FWU #fridaywrapup #SupplyChainSecurity #NationStateHackers #PatchNow #Malware #DataBreach #Ransomware</p><p></p><div><hr></div><h2>Major Cyberattacks &amp; Incidents</h2><p><em>From pharmaceutical giants to anime streaming platforms, this week&#8217;s breach roster spans nearly every sector &#8212; and the body count keeps climbing.</em></p><ul><li><p>&#127963;&#65039; The European Commission is investigating a security breach after a threat actor gained unauthorized access to its Amazon cloud infrastructure, raising concerns about the security of EU executive data. (Published on March 27, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/european-commission-investigating-breach-after-amazon-cloud-hack/">Read More</a></p></li><li><p>&#128188; Hightower Holding disclosed a breach that exposed names, Social Security numbers, and driver&#8217;s license numbers for 130,000 individuals after hackers infiltrated the firm&#8217;s environment. (Published on March 26, 2026, SecurityWeek). <a href="https://www.securityweek.com/hightower-holding-data-breach-impacts-130000/">Read More</a></p></li><li><p>&#9878;&#65039; Ilya Angelov, a member of the cybercrime group tracked as TA-551 (Shathak/Gold Cabin/Monster Libra), received a two-year US prison sentence for his role in the prolific criminal operation. (Published on March 25, 2026, SecurityWeek). <a href="https://www.securityweek.com/russian-cybercriminal-gets-2-year-prison-sentence-in-us/">Read More</a></p></li><li><p>&#10067; OVHcloud&#8217;s founder denied claims by a hacker alleging a 600TB theft affecting millions of hosted sites, with cybersecurity experts also questioning the credibility of the evidence provided. (Published on March 24, 2026, Hackread). <a href="https://hackread.com/ovhcloud-founder-denies-590tb-data-breach-claims/">Read More</a></p></li><li><p>&#128027; Bug bounty platform HackerOne is notifying hundreds of employees that their personal data was stolen after threat actors compromised Navia, one of its US-based benefits administrators. (Published on March 24, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/hackerone-discloses-employee-data-breach-after-navia-hack/">Read More</a></p></li><li><p>&#128138; The Lapsus$ extortion group claims to have breached pharmaceutical giant AstraZeneca, allegedly stealing internal code repositories, employee credentials, and sensitive company data. (Published on March 24, 2026, SecurityWeek). <a href="https://www.securityweek.com/extortion-group-claims-it-hacked-astrazeneca/">Read More</a></p></li><li><p>&#128663; Mazda Motor Corporation disclosed a security incident detected last December that exposed personal data belonging to employees and business partners of the automaker. (Published on March 23, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/mazda-discloses-security-breach-exposing-employee-and-partner-data/">Read More</a></p></li><li><p>&#128250; Popular anime streaming platform Crunchyroll is investigating a breach after hackers claimed to have stolen personal information for approximately 6.8 million users of the service. (Published on March 23, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/crunchyroll-probes-breach-after-hacker-claims-to-steal-68m-users-data/">Read More</a></p></li></ul><h2>Espionage &amp; Data Extraction</h2><p><em>Nation-state actors had an unusually busy week &#8212; an FBI director&#8217;s inbox, an evolved iPhone exploit framework, and North Korean operatives hiding in plain sight as remote IT workers.</em></p><ul><li><p>&#127470;&#127479; A pro-Iranian hacking group claimed responsibility for breaching FBI Director Kash Patel&#8217;s personal account, making emails and documents from the account available for public download. (Published on March 27, 2026, SecurityWeek). <a href="https://www.securityweek.com/pro-iranian-hacking-group-claims-credit-for-hack-of-fbi-director-kash-patels-personal-account/">Read More</a></p></li><li><p>&#128241; The Coruna iOS exploit kit is an evolution of the framework used in Operation Triangulation &#8212; the 2023 espionage campaign that silently compromised iPhones via zero-click iMessage exploits. (Published on March 26, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/coruna-ios-exploit-framework-linked-to-triangulation-attacks/">Read More</a></p></li><li><p>&#127472;&#127477; North Korea&#8217;s WaterPlum/Contagious Interview group weaponized VS Code tasks.json files to distribute the new StoatWaffle malware, targeting developers through malicious Visual Studio Code projects. (Published on March 23, 2026, The Hacker News). <a href="https://thehackernews.com/2026/03/north-korean-hackers-abuse-vs-code-auto.html">Read More</a></p></li><li><p>&#128373;&#65039; LevelBlue research reveals how a suspected North Korean operative successfully landed a remote IT job to fund national weapons programs, only to be exposed after a VPN configuration slip. (Published on March 23, 2026, Hackread). <a href="https://hackread.com/north-korean-hacker-remote-it-job-vpn-slip/">Read More</a></p></li></ul><h2>Malware &amp; Vulnerabilities</h2><p><em>Supply-chain attacks, router bypasses, and a payment skimmer that routes around your defenses via WebRTC &#8212; the vulnerability landscape this week has something for everyone.</em></p><ul><li><p>&#127925; The TeamPCP supply-chain threat actor compromised the Telnyx Python package on PyPI, hiding data-stealing code inside WAV audio files across two malicious versions (4.87.1 and 4.87.2). (Published on March 27, 2026, The Hacker News). <a href="https://thehackernews.com/2026/03/teampcp-pushes-malicious-telnyx.html">Read More</a></p></li><li><p>&#128187; A large-scale campaign is flooding GitHub project Discussions with fake Visual Studio Code security alerts, tricking developers into downloading malware disguised as urgent platform security updates. (Published on March 27, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/fake-vs-code-alerts-on-github-spread-malware-to-developers/">Read More</a></p></li><li><p>&#128275; A now-patched bug in Open VSX&#8217;s pre-publish scanning pipeline allowed malicious VS Code extensions to pass security vetting and go live in the registry undetected, with a single boolean flag as the culprit. (Published on March 27, 2026, The Hacker News). <a href="https://thehackernews.com/2026/03/open-vsx-bug-let-malicious-vs-code.html">Read More</a></p></li><li><p>&#9889; A critical Langflow RCE vulnerability allowing unauthenticated code execution was exploited within hours of disclosure, prompting CISA to formally flag the flaw for urgent remediation. (Published on March 27, 2026, CSO Online). <a href="https://www.csoonline.com/article/4151203/attackers-exploit-critical-langflow-rce-within-hours-as-cisa-sounds-alarm.html">Read More</a></p></li><li><p>&#128123; ReversingLabs identified a Ghost campaign using convincing fake npm install progress bars to trick developers into entering sudo passwords, enabling crypto wallet theft from compromised machines. (Published on March 27, 2026, Hackread). <a href="https://hackread.com/ghost-campaign-npm-progress-bars-phish-sudo-passwords/">Read More</a></p></li><li><p>&#128179; A new payment skimmer uses WebRTC data channels &#8212; instead of traditional HTTP requests or image beacons &#8212; to load payloads and exfiltrate payment data from e-commerce sites, bypassing Content Security Policy controls. (Published on March 26, 2026, The Hacker News). <a href="https://thehackernews.com/2026/03/webrtc-skimmer-bypasses-csp-to-steal.html">Read More</a></p></li><li><p>&#128371;&#65039; CVE-2026-3055, an out-of-bounds read flaw in NetScaler ADC and Gateway, has been flagged by experts as CitrixBleed2-level severity, requiring immediate patching of all customer-managed devices. (Published on March 25, 2026, CSO Online). <a href="https://www.csoonline.com/article/4150224/new-critical-citrix-netscaler-hole-of-similar-severity-to-citrixbleed2-says-expert.html">Read More</a></p></li><li><p>&#129713; GlassWorm has evolved into a multi-stage framework using Solana blockchain dead drops to deliver a RAT and deploy a malicious Chrome extension disguised as an offline app to steal browser data and crypto. (Published on March 25, 2026, The Hacker News). <a href="https://thehackernews.com/2026/03/glassworm-malware-uses-solana-dead.html">Read More</a></p></li><li><p>&#128225; TP-Link patched a critical authentication bypass flaw in its Archer NX router series that could allow unauthenticated attackers to upload malicious firmware and seize full control of the device. (Published on March 25, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/tp-link-warns-users-to-patch-critical-router-auth-bypass-flaw/">Read More</a></p></li><li><p>&#128273; The TeamPCP group backdoored the massively popular LiteLLM Python package on PyPI to steal credentials and auth tokens, claiming to have exfiltrated data from hundreds of thousands of compromised devices. (Published on March 24, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/popular-litellm-pypi-package-compromised-in-teampcp-supply-chain-attack/">Read More</a></p></li><li><p>&#128275; Citrix released patches for CVE-2026-3055 (CVSS 9.3), a critical NetScaler ADC and Gateway flaw allowing unauthenticated data exfiltration from affected applications across customer-managed deployments. (Published on March 24, 2026, The Hacker News). <a href="https://thehackernews.com/2026/03/citrix-urges-patching-critical.html">Read More</a></p></li><li><p>&#127850; VoidStealer uses a novel debugger-based technique to bypass Chrome&#8217;s Application-Bound Encryption (ABE), stealing saved passwords and cookies in a method researchers say hasn&#8217;t been seen in the wild before. (Published on March 23, 2026, CSO Online). <a href="https://www.csoonline.com/article/4148601/chrome-abe-bypass-discovered-new-voidstealer-malware-steals-passwords-and-cookies.html">Read More</a></p></li><li><p>&#128736;&#65039; QNAP released patches for four vulnerabilities demonstrated at Pwn2Own that could allow attackers to access sensitive information, execute arbitrary code, or trigger unexpected system behavior on affected devices. (Published on March 23, 2026, SecurityWeek). <a href="https://www.securityweek.com/qnap-patches-four-vulnerabilities-exploited-at-pwn2own/">Read More</a></p></li></ul><h2>Cybersecurity Tools &amp; Techniques</h2><p><em>This week&#8217;s phishing roundup covers QR codes that dodge every email security standard, fake resumes, fake token giveaways, and IRS impersonators &#8212; tax season is a gift for attackers.</em></p><ul><li><p>&#128242; A massive QR code phishing campaign dubbed Quish Splash evaded SPF, DKIM, and DMARC controls to successfully deliver 1.6 million malicious emails to unsuspecting recipients without detection. (Published on March 26, 2026, Hackread). <a href="https://hackread.com/quish-splash-qr-code-phishing-hits-users/">Read More</a></p></li><li><p>&#129767; Threat actors are abusing the no-code Bubble platform to build convincing phishing pages targeting Microsoft accounts, leveraging the legitimate app builder to evade standard phishing detection tooling. (Published on March 25, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/bubble-ai-app-builder-abused-to-steal-microsoft-account-credentials/">Read More</a></p></li><li><p>&#128184; OX Security uncovered a phishing campaign targeting GitHub developers with fake OpenClaw token giveaways, tricking victims into connecting their cryptocurrency wallets and immediately draining them. (Published on March 25, 2026, Hackread). <a href="https://hackread.com/fake-openclaw-token-github-devs-wallet-drainer-scam/">Read More</a></p></li><li><p>&#127757; An active device code phishing campaign has compromised over 340 Microsoft 365 organizations across five countries since February 2026, abusing OAuth authentication flows to silently steal access tokens. (Published on March 25, 2026, The Hacker News). <a href="https://thehackernews.com/2026/03/device-code-phishing-hits-340-microsoft.html">Read More</a></p></li><li><p>&#128196; An ongoing phishing campaign targeting French-speaking enterprises delivers obfuscated VBScript files disguised as CV documents that install cryptocurrency miners and infostealers on victim machines. (Published on March 24, 2026, The Hacker News). <a href="https://thehackernews.com/2026/03/hackers-use-fake-resumes-to-steal.html">Read More</a></p></li><li><p>&#128176; Microsoft warns of active tax-season phishing campaigns that have hit 29,000 users with IRS-themed emails, delivering remote management malware to establish persistent access and harvest credentials. (Published on March 23, 2026, The Hacker News). <a href="https://thehackernews.com/2026/03/microsoft-warns-irs-phishing-hits-29000.html">Read More</a></p></li></ul><h2>DDoS, Outages &amp; Infrastructure</h2><p><em>Botnets are multiplying and attacks are surging &#8212; the infrastructure threat landscape is growing broader and louder.</em></p><ul><li><p>&#129302; Mirai has spawned hundreds of variants &#8212; including Aisuru and KimWolf &#8212; fueling large-scale botnet growth and increasing attack risks against vulnerable IoT devices globally. (Published on March 25, 2026, Hackread). <a href="https://hackread.com/mirai-malware-variants-botnet-growth/">Read More</a></p></li><li><p>&#128200; Gcore&#8217;s latest Radar report documents a 150% year-on-year surge in DDoS attack volume, reflecting the rapid expansion of botnet infrastructure and the continued commoditization of volumetric attacks. (Published on March 24, 2026, Hackread). <a href="https://hackread.com/gcore-radar-report-reveals-150-surge-in-ddos-attacks-year-on-year/">Read More</a></p></li></ul><h2>AI &amp; Policy</h2><p><em>One story this week &#8212; but it&#8217;s a notable one: a zero-click flaw in an AI browser extension that turned every website into a potential attack vector.</em></p><ul><li><p>&#129302; Researchers disclosed a now-patched flaw in Anthropic&#8217;s Claude Chrome Extension that allowed any website to silently inject malicious prompts into the assistant without any user interaction via cross-site scripting. (Published on March 26, 2026, The Hacker News). <a href="https://thehackernews.com/2026/03/claude-extension-flaw-enabled-zero.html">Read More</a></p><p></p></li></ul><div><hr></div><p>Stay informed and secure in the tech and cybersecurity world. Have a great weekend, and remember to patch and protect your systems!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://thefwu.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Friday Wrap Up! Subscribe and never miss a weekly edition!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Friday Wrap Up: 20 March 2026]]></title><description><![CDATA[It&#8217;s Friday, which means the threat actors didn&#8217;t take the week off &#8212; and neither did we.]]></description><link>https://thefwu.com/p/friday-wrap-up-20-march-2026</link><guid isPermaLink="false">https://thefwu.com/p/friday-wrap-up-20-march-2026</guid><pubDate>Fri, 20 Mar 2026 20:01:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" width="550" height="320.8333333333333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:420,&quot;width&quot;:720,&quot;resizeWidth&quot;:550,&quot;bytes&quot;:204370,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>It&#8217;s Friday, which means the threat actors didn&#8217;t take the week off &#8212; and neither did we. &#128737;&#65039;</p><p>This week&#8217;s Friday Wrap Up covers ransomware gangs weaponizing zero-days, nation-state actors wiping devices at scale, supply-chain attacks hitting developer toolchains, AI platforms becoming the new attack surface, and a botnet that clearly skipped leg day because it never stops running. Whether you&#8217;re patching, detecting, or just trying to make it to 5pm, there&#8217;s something in this week&#8217;s roundup that probably affects your org.</p><p>Click the links below and maybe patch something this weekend.</p><p><strong>#FWU</strong> <strong>#fridaywrapup</strong> <strong>#CyberSecurity</strong> <strong>#InfoSec</strong> <strong>#RansomwareWatch</strong> <strong>#SupplyChainSecurity</strong> <strong>#ThreatIntelligence</strong> <strong>#Malware</strong> <strong>#DataBreach</strong> <strong>#Ransomwar</strong></p><p></p><div><hr></div><p>Major Cyberattacks &amp; Incidents </p><p>From ransomware zero-days to a wipe-and-run attack on a medical tech giant, this week&#8217;s incident log is a reminder that no sector is off-limits.</p><ul><li><p>&#128188; A 27-year-old data analyst contractor, Cameron &#8220;Loot&#8221; Curry, was convicted of six extortion charges after stealing and ransoming data from a D.C.-based international tech firm, netting $2.5 million while working from the inside. (Published on March 20, 2026, CyberScoop). <a href="https://cyberscoop.com/cameron-curry-insider-attack-washington-tech-company/">Read More</a></p></li><li><p>&#127963;&#65039; The FBI seized two Handala hacktivist websites following a destructive cyberattack on medical tech giant Stryker that remotely wiped approximately 80,000 employee devices across the company. (Published on March 19, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/fbi-seizes-handala-data-leak-site-after-stryker-cyberattack/">Read More</a></p></li><li><p>&#128293; The Interlock ransomware gang has been actively exploiting a maximum-severity RCE vulnerability in Cisco&#8217;s Secure Firewall Management Center as a zero-day since late January 2026. (Published on March 18, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/interlock-ransomware-exploited-secure-fmc-flaw-in-zero-day-attacks-since-january/">Read More</a></p></li><li><p>&#128717;&#65039; Attackers hijacked Nordstrom&#8217;s legitimate email infrastructure to blast customers with cryptocurrency scams disguised as a St. Patrick&#8217;s Day promotion, leveraging the retailer&#8217;s brand trust to boost credibility. (Published on March 18, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/nordstroms-email-system-abused-to-send-crypto-scams-to-customers/">Read More</a></p></li><li><p>&#128279; The LeakNet ransomware gang adopted ClickFix social engineering via compromised websites for initial access, then deployed an in-memory loader built on the open-source Deno JavaScript runtime to evade detection. (Published on March 17, 2026, The Hacker News). <a href="https://thehackernews.com/2026/03/leaknet-ransomware-uses-clickfix-via.html">Read More</a></p></li><li><p>&#128279; BleepingComputer confirms LeakNet&#8217;s shift to ClickFix for initial access and Deno-based in-memory loaders for stealthy corporate network compromise, with the group continuing to ramp up its attack velocity. (Published on March 17, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/leaknet-ransomware-uses-clickfix-and-deno-runtime-for-stealthy-attacks/">Read More</a></p></li><li><p>&#127918; The FBI is investigating several Steam games found to contain malware that stole browser data and drained cryptocurrency wallets from players between May 2024 and January 2026, warning gamers to stay vigilant. (Published on March 16, 2026, Hackread). <a href="https://hackread.com/fbi-investigate-steam-games-malware-crypto-theft/">Read More</a></p></li><li><p>&#127973; The Handala cyberattack on Stryker was confined to its internal Microsoft environment, remotely wiping tens of thousands of employee devices using native admin tools &#8212; no custom malware required. (Published on March 16, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/stryker-attack-wiped-tens-of-thousands-of-devices-no-malware-needed/">Read More</a></p></li></ul><p>Espionage &amp; Data Extraction </p><p>Nation-state actors were in full swing this week, with North Korean, Iranian, and Russian-linked groups all making headlines for bold and sophisticated operations.</p><ul><li><p>&#127472;&#127477; Crypto gift card service Bitrefill attributed a recent breach to North Korea&#8217;s Bluenoroff sub-group of the Lazarus threat actor, continuing the pattern of DPRK-linked attacks targeting cryptocurrency-adjacent businesses. (Published on March 19, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/bitrefill-blames-north-korean-lazarus-group-for-cyberattack/">Read More</a></p></li><li><p>&#127760; Security analysis reveals Iran spent six months building resilient cyber infrastructure &#8212; including US-based shell companies &#8212; designed to sustain global hacking operations and survive potential kinetic military strikes. (Published on March 19, 2026, SecurityWeek). <a href="https://www.securityweek.com/iran-readied-cyberattack-capabilities-for-response-prior-to-epic-fury/">Read More</a></p></li><li><p>&#128273; The Iranian Handala hackers likely used infostealer-stolen credentials to breach Stryker&#8217;s Microsoft environment, while the medtech company continues the recovery effort to restore tens of thousands of wiped devices. (Published on March 18, 2026, SecurityWeek). <a href="https://www.securityweek.com/iranian-hackers-likely-used-malware-stolen-credentials-in-stryker-breach/">Read More</a></p></li><li><p>&#127479;&#127482; A collaborative investigation by iVerify, Lookout, and Google uncovered a second iOS exploit kit linked to suspected Russian hackers, raising concerns about the accelerating proliferation of nation-state mobile surveillance tooling. (Published on March 18, 2026, CyberScoop). <a href="https://cyberscoop.com/second-ios-exploit-kit-emerges-from-suspected-russian-hackers-using-possible-u-s-government-developed-tools/">Read More</a></p></li></ul><p>Malware &amp; Vulnerabilities </p><p>Exploit kits, banking trojans, supply-chain backdoors, and hardware flaws kept researchers busy this week &#8212; the vulnerability landscape just keeps expanding.</p><ul><li><p>&#127907; Sublime Security uncovered a JavaScript-based scam mimicking realistic, interactive Zoom meeting invites to trick Windows users into downloading malware &#8212; convincing enough to fool even security-aware users. (Published on March 20, 2026, Hackread). <a href="https://hackread.com/fake-zoom-meeting-invite-scam-windows-pc-malware/">Read More</a></p></li><li><p>&#128275; Sansec warns of a critical Magento REST API flaw dubbed PolyShell, allowing unauthenticated attackers to upload arbitrary executables, execute code remotely, and take over accounts with no credentials required. (Published on March 20, 2026, The Hacker News). <a href="https://thehackernews.com/2026/03/magento-polyshell-flaw-enables.html">Read More</a></p></li><li><p>&#9889; Threat actors exploited a critical Langflow AI workflow vulnerability in under 20 hours of its public disclosure, with Sysdig documenting the rapid timeline that underscores just how small the patching window has become. (Published on March 20, 2026, Infosecurity). <a href="https://www.infosecurity-magazine.com/news/hackers-exploit-critical-langflow/">Read More</a></p></li><li><p>&#128241; Researchers uncovered Perseus, a new Android banking malware descended from Cerberus and Phoenix, capable of device takeover and financial fraud by monitoring notes apps to silently harvest sensitive credentials. (Published on March 19, 2026, The Hacker News). <a href="https://thehackernews.com/2026/03/new-perseus-android-banking-malware.html">Read More</a></p></li><li><p>&#129513; Bitdefender researchers discovered a malicious Windsurf IDE extension that uses the Solana blockchain as command-and-control infrastructure to exfiltrate developer credentials in a novel and stealthy supply-chain attack. (Published on March 19, 2026, Hackread). <a href="https://hackread.com/windsurf-ide-extension-solana-blockchain-developer-data/">Read More</a></p></li><li><p>&#128481;&#65039; Google GTIG, iVerify, and Lookout revealed DarkSword, an iOS exploit kit wielding six vulnerabilities including three zero-days, enabling full device takeover and data theft since at least November 2025. (Published on March 19, 2026, The Hacker News). <a href="https://thehackernews.com/2026/03/darksword-ios-exploit-kit-uses-6-flaws.html">Read More</a></p></li><li><p>&#11035; Howler Cell researchers identified a new .NET Ahead-of-Time compiled malware campaign using an obfuscated scoring system to conceal payloads as a black box, rendering traditional signature-based detection ineffective. (Published on March 18, 2026, Hackread). <a href="https://hackread.com/net-aot-malware-code-black-box-evade-detection/">Read More</a></p></li><li><p>&#128421;&#65039; Eclypsium discovered nine critical vulnerabilities across four IP KVM vendors allowing unauthenticated root access to connected hosts, exposing significant risks posed by low-cost remote management devices in data centers. (Published on March 18, 2026, The Hacker News). <a href="https://thehackernews.com/2026/03/9-critical-ip-kvm-flaws-enable.html">Read More</a></p></li><li><p>&#128248; A researcher found a fourth method to bypass WhatsApp&#8217;s View Once privacy feature, allowing recipients to save supposedly ephemeral media. Meta declined to patch it, citing use of a modified client application. (Published on March 18, 2026, SecurityWeek). <a href="https://www.securityweek.com/researcher-discovers-4th-whatsapp-view-once-bypass-meta-wont-patch/">Read More</a></p></li><li><p>&#127822; Apple patched CVE-2026-20643, a WebKit cross-origin flaw in the Navigation API affecting iOS, iPadOS, and macOS, via its first-ever Background Security Improvements update cycle. (Published on March 18, 2026, The Hacker News). <a href="https://thehackernews.com/2026/03/apple-fixes-webkit-vulnerability.html">Read More</a></p></li><li><p>&#129713; The GlassWorm supply-chain campaign returned with a coordinated attack targeting over 400 packages and repositories across GitHub, npm, and VSCode/OpenVSX extensions, poisoning developer toolchains at scale. (Published on March 17, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/glassworm-malware-hits-400-plus-code-repos-on-github-npm-vscode-openvsx/">Read More</a></p></li><li><p>&#129713; Socket researchers identified 72+ malicious Open VSX extensions in a new GlassWorm supply-chain phase, exploiting extension dependency relationships to indirectly deliver malware without direct registry manipulation. (Published on March 16, 2026, CSO Online). <a href="https://www.csoonline.com/article/4145579/open-vsx-extensions-hijacked-glassworm-malware-spreads-via-dependency-abuse.html">Read More</a></p></li><li><p>&#128000; New XWorm 7.1 and Remcos RAT campaigns exploit a WinRAR vulnerability and use process hollowing through trusted Windows tools to spy on victims while evading traditional endpoint detection solutions. (Published on March 16, 2026, Hackread). <a href="https://hackread.com/xworm-7-1-remcos-rat-windows-tools-evade-detection/">Read More</a></p></li></ul><p>Cybersecurity Tools &amp; Techniques </p><p>From infostealer delivery via fake enterprise software portals to OS-level API lockdowns, attackers and defenders alike are sharpening their tools this week.</p><ul><li><p>&#127917; Microsoft Defender Experts tracked Storm-2561 using convincing fake Fortinet and Ivanti VPN download pages to trick IT professionals into installing the Hyrax infostealer, active since mid-January 2026. (Published on March 17, 2026, Hackread). <a href="https://hackread.com/storm-2561-fake-fortinet-ivanti-vpn-sites-hyrax-infostealer/">Read More</a></p></li><li><p>&#127907; A security firm executive was targeted by a sophisticated phishing campaign using DKIM-signed emails, trusted redirect infrastructure, compromised servers, and Cloudflare-protected pages &#8212; a reminder that even experts aren&#8217;t immune. (Published on March 16, 2026, SecurityWeek). <a href="https://www.securityweek.com/security-firm-executive-targeted-in-sophisticated-phishing-attack/">Read More</a></p></li><li><p>&#128737;&#65039; Google&#8217;s Android 17 Beta 2 introduces Advanced Protection Mode restrictions blocking non-accessibility apps from the Accessibility Services API, cutting off a common malware overlay and privilege-escalation attack vector. (Published on March 16, 2026, The Hacker News). <a href="https://thehackernews.com/2026/03/android-17-blocks-non-accessibility.html">Read More</a></p></li></ul><p>DDoS, Outages &amp; Infrastructure </p><p>One botnet dominated this week&#8217;s infrastructure news &#8212; and it&#8217;s been very, very busy.</p><ul><li><p>&#129302; The RondoDox botnet has escalated to 15,000 exploitation attempts per day, systematically targeting 174 different vulnerabilities in a more focused and aggressive campaign than previously observed by researchers. (Published on March 17, 2026, SecurityWeek). <a href="https://www.securityweek.com/rondodox-botnet-targeted-174-vulnerabilities/">Read More</a></p></li></ul><p>AI &amp; Policy </p><p>AI is generating headlines well beyond productivity gains &#8212; from courtroom battles to security flaws embedded in AI platforms, the policy and threat landscape is evolving fast.</p><ul><li><p>&#127925; North Carolina musician Michael Smith pleaded guilty to a $10 million streaming royalty fraud scheme, using AI bots to artificially inflate play counts on Spotify, Apple Music, Amazon Music, and YouTube Music. (Published on March 20, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/musician-pleads-guilty-to-10m-streaming-fraud-powered-by-ai-bots/">Read More</a></p></li><li><p>&#129302; Researchers uncovered &#8220;Claudy Day&#8221; vulnerabilities in Claude AI that allow attackers to steal user data via fake Google Ads and hidden prompt injection, exploiting the AI platform&#8217;s ad-rendering infrastructure. (Published on March 18, 2026, Hackread). <a href="https://hackread.com/claudy-day-flaws-data-theft-fake-claude-ai-ads/">Read More</a></p></li><li><p>&#9878;&#65039; The Ninth Circuit Court of Appeals temporarily stayed a California judge&#8217;s injunction against Perplexity AI&#8217;s shopping agent on Amazon, allowing the service to continue as the legal battle over automated account activity proceeds. (Published on March 17, 2026, CyberScoop). <a href="https://cyberscoop.com/perplexity-comet-ai-shopping-agent-amazon-lawsuit-ninth-circuit-stay/">Read More</a></p></li><li><p>&#128274; At Nvidia GTC, CEO Jensen Huang unveiled NemoClaw, a security framework designed to run OpenClaw agentic AI systems safely in enterprise environments, addressing persistent concerns about the platform&#8217;s security posture. (Published on March 17, 2026, CSO Online). <a href="https://www.csoonline.com/article/4146564/nvidia-nemoclaw-promises-to-run-openclaw-agents-securely-3.html">Read More</a></p></li><li><p>&#128137; BeyondTrust revealed a DNS-based data exfiltration technique exploiting flaws in Amazon Bedrock AgentCore, LangSmith, and SGLang AI environments, enabling both sensitive data theft and remote code execution. (Published on March 17, 2026, The Hacker News). <a href="https://thehackernews.com/2026/03/ai-flaws-in-amazon-bedrock-langsmith.html">Read More</a></p></li><li><p>&#128272; GitGuardian&#8217;s annual report reveals an 81% surge in AI service credential leaks, with 29 million secrets exposed on public GitHub repositories, driven largely by rapid developer adoption of AI-powered coding tools. (Published on March 17, 2026, Hackread). <a href="https://hackread.com/gitguardian-reports-an-81-surge-of-ai-service-leaks-as-29m-secrets-hit-public-github/">Read More</a></p></li><li><p>&#9201;&#65039; A Booz Allen Hamilton report warns that AI tools have matured enough to give attackers a significant speed advantage over defenders, shortening response windows and pushing cybersecurity into a dangerous new phase. (Published on March 16, 2026, CyberScoop). <a href="https://cyberscoop.com/booz-allen-report-ai-helps-attackers-move-faster-than-current-defenses/">Read More</a></p><p></p></li></ul><div><hr></div><p>Stay informed and secure in the tech and cybersecurity world. Have a great weekend, and remember to patch and protect your systems!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://thefwu.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Friday Wrap Up! Subscribe and never miss a weekly edition!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Friday Wrap Up: 13 March 2026]]></title><description><![CDATA[Happy Friday the 13th!]]></description><link>https://thefwu.com/p/friday-wrap-up-13-march-2026</link><guid isPermaLink="false">https://thefwu.com/p/friday-wrap-up-13-march-2026</guid><dc:creator><![CDATA[Jorge Laurel]]></dc:creator><pubDate>Fri, 13 Mar 2026 20:15:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" width="550" height="320.8333333333333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:420,&quot;width&quot;:720,&quot;resizeWidth&quot;:550,&quot;bytes&quot;:204370,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Happy Friday the 13th! &#128298; In the spirit of the day, threat actors did NOT hold back this week.</p><p>We&#8217;ve got Chrome extensions that turned evil after changing hands, an AI agent that decided to mine crypto on its own (nobody asked, buddy &#129302;&#9935;&#65039;), a medtech giant hit by Iranian hackers claiming to have wiped 200,000 devices, and a 1 petabyte data theft claim that made storage admins everywhere break into a cold sweat.</p><p>Oh, and Microsoft and Adobe both dropped patch updates on the same week. Because nothing says Friday the 13th like 163 CVEs staring you down before the weekend. &#129657;&#128128;</p><p>This week&#8217;s Friday Wrap Up has the full breakdown &#8212; breaches, botnets, nation-state drama, and the AI that&#8217;s apparently already going rogue. Click the links below and stay spooky, friends. &#128071;</p><p>#Malware #DataBreach #Ransomware #FWU #fridaywrapup #CyberSecurity #InfoSec #RansomwareWatch #ThreatIntel #SecOps #Friday13th #StayPatched #ThreatsAndChills</p><div><hr></div><p>Major Cyberattacks &amp; Incidents </p><p>This week saw breaches hitting telecom, medtech, and enterprise infrastructure, with some jaw-dropping data theft claims.</p><ul><li><p>&#128275; Ericsson US confirms employee and customer data was stolen after attackers compromised one of its third-party service providers. (Published on 9-Mar-2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/ericsson-us-discloses-data-breach-after-service-provider-hack/">Read More</a></p></li><li><p>&#127973; Iran-linked Handala group claims to have wiped over 200,000 devices belonging to medical technology giant Stryker in a destructive cyberattack. (Published on 11-Mar-2026, SecurityWeek). <a href="https://www.securityweek.com/medtech-giant-stryker-crippled-by-iran-linked-hacker-attack/">Read More</a></p></li><li><p>&#128230; Telus Digital confirms a security incident after threat actors claimed to have exfiltrated nearly 1 petabyte of data in a months-long breach campaign. (Published on 12-Mar-2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/telus-digital-confirms-breach-after-hacker-claims-1-petabyte-data-theft/">Read More</a></p></li><li><p>&#128373;&#65039; A threat actor exploited vulnerabilities and abused Elastic Cloud as a command hub to manage and exfiltrate stolen data, per Huntress researchers. (Published on 9-Mar-2026, Infosecurity). <a href="https://www.infosecurity-magazine.com/news/elastic-cloud-siem-manage-stolen/">Read More</a></p></li></ul><p>Malware &amp; Vulnerabilities </p><p>From ZIP trickery to botnet-building router malware, threat actors had a busy week crafting new evasion techniques.</p><ul><li><p>&#129513; Two Chrome extensions turned malicious following an ownership transfer, enabling code injection and sensitive data harvesting from users&#8217; browsers. (Published on 9-Mar-2026, The Hacker News). <a href="https://thehackernews.com/2026/03/chrome-extension-turns-malicious-after.html">Read More</a></p></li><li><p>&#129668; A new &#8220;Zombie ZIP&#8221; technique conceals malware payloads inside specially crafted compressed files designed to bypass antivirus and EDR detection tools. (Published on 10-Mar-2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/new-zombie-zip-technique-lets-malware-slip-past-security-tools/">Read More</a></p></li><li><p>&#128225; KadNap malware has hijacked over 14,000 Asus routers &#8212; more than 60% in the U.S. &#8212; to build a stealth proxy botnet routing malicious traffic. (Published on 10-Mar-2026, The Hacker News). <a href="https://thehackernews.com/2026/03/kadnap-malware-infects-14000-edge.html">Read More</a></p></li><li><p>&#127919; The PhantomRaven supply-chain campaign is back with 88 malicious npm packages designed to exfiltrate sensitive data from JavaScript developers. (Published on 11-Mar-2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/new-phantomraven-npm-attack-wave-steals-dev-data-via-88-packages/">Read More</a></p></li><li><p>&#128421;&#65039; Fake enterprise VPN clients impersonating Ivanti, Cisco, and Fortinet are being distributed by Storm-2561 to steal corporate credentials from employees. (Published on 13-Mar-2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/fake-enterprise-vpn-downloads-used-to-steal-company-credentials/">Read More</a></p></li><li><p>&#127760; Cloned AI tool websites are distributing malware through the &#8220;InstallFix&#8221; campaign by replacing legitimate setup commands with malicious ones. (Published on 9-Mar-2026, SecurityWeek). <a href="https://www.securityweek.com/cloned-ai-tool-sites-distribute-malware-in-installfix-campaign/">Read More</a></p></li><li><p>&#128084; BlackSanta malware targets HR staff by disguising attacks as fake CV downloads, allowing Russian-speaking threat actors to infiltrate recruitment workflows. (Published on 11-Mar-2026, Hackread). <a href="https://hackread.com/blacksanta-malware-hr-staff-fake-cv-downloads/">Read More</a></p></li><li><p>&#129302; Hive0163 is deploying AI-generated Slopoly malware for persistent access in ransomware attacks, showcasing how AI is accelerating malware development timelines. (Published on 12-Mar-2026, The Hacker News). <a href="https://thehackernews.com/2026/03/hive0163-uses-ai-assisted-slopoly.html">Read More</a></p></li></ul><p>Espionage &amp; Nation-State Activity </p><p>Russia&#8217;s Sednit resurfaces with upgraded tools, signaling a step up from the group&#8217;s recent low-profile operations.</p><ul><li><p>&#128059; Russia-affiliated Sednit (APT28) has returned with two sophisticated new malware tools after years of relying on simpler implants for espionage operations. (Published on 10-Mar-2026, Dark Reading). <a href="https://www.darkreading.com/cyber-risk/sednit-resurfaces-with-sophisticated-new-toolkit/">Read More</a></p></li></ul><p>Vulnerability Research &amp; Industry Analysis </p><p>Patch Tuesday came in heavy this week, with Microsoft and Adobe both dropping major security updates simultaneously.</p><ul><li><p>&#129657; Microsoft&#8217;s March Patch Tuesday addresses 83 CVEs &#8212; security experts say there&#8217;s little to panic about, but patching promptly remains essential. (Published on 11-Mar-2026, Dark Reading). <a href="https://www.darkreading.com/application-security/microsoft-patches-83-cves-march-update/">Read More</a></p></li><li><p>&#128737;&#65039; Adobe patches 80 vulnerabilities across eight products, including Commerce, Illustrator, Acrobat Reader, and Premiere Pro &#8212; a busy week for Adobe admins. (Published on 10-Mar-2026, SecurityWeek). <a href="https://www.securityweek.com/adobe-patches-80-vulnerabilities-across-eight-products/">Read More</a></p></li><li><p>&#9888;&#65039; Two critical flaws in n8n workflow automation platform &#8212; CVSSv3 scores of 9.4 and 9.5 &#8212; could allow remote code execution and credential exposure. Now patched. (Published on 11-Mar-2026, The Hacker News). <a href="https://thehackernews.com/2026/03/critical-n8n-flaws-allow-remote-code.html">Read More</a></p></li><li><p>&#128241; Apple patches actively exploited Coruna vulnerabilities in older iOS and iPadOS versions 16.7.15 and 15.8.7 for users unable to upgrade to current releases. (Published on 12-Mar-2026, SecurityWeek). <a href="https://www.securityweek.com/apple-updates-older-ios-versions-to-patch-coruna-exploits/">Read More</a></p></li><li><p>&#128176; Google paid out over $17 million in bug bounty rewards in 2025, including $3.7M for Chrome and $3.5M for cloud security vulnerabilities reported by researchers. (Published on 13-Mar-2026, SecurityWeek). <a href="https://www.securityweek.com/google-paid-out-17-million-in-bug-bounty-rewards-in-2025/">Read More</a></p></li></ul><p>AI &amp; Policy </p><p>AI made headlines both as a security tool and a security risk this week &#8212; sometimes simultaneously.</p><ul><li><p>&#128269; OpenAI&#8217;s Codex Security agent found 11,000+ high-severity bugs across 1.2M commits in its first 30 days, including 792 critical flaws in real-world codebases. (Published on 9-Mar-2026, CSO Online). <a href="https://www.csoonline.com/article/4142354/openai-says-codex-security-found-11000-high-impact-bugs-in-a-month.html">Read More</a></p></li><li><p>&#9935;&#65039; Researchers found that experimental AI agent ROME autonomously attempted cryptomining without being instructed to &#8212; raising serious alignment and safety concerns. (Published on 10-Mar-2026, Hackread). <a href="https://hackread.com/rome-ai-agent-cryptomining-without-instructions/">Read More</a></p></li><li><p>&#128188; Mastercard is offering SMEs an AI-powered virtual CFO, with other C-suite AI roles to follow &#8212; blurring the line between automation and executive decision-making. (Published on 11-Mar-2026, ComputerWeekly.com). <a href="https://www.computerweekly.com/news/366639928/MasterCard-bots-target-C-suite-roles/">Read More</a></p></li><li><p>&#129504; Nvidia is reportedly building an open-source NemoClaw AI platform to compete with OpenClaw, courting enterprise partners ahead of its annual conference. (Published on 11-Mar-2026, Ars Technica). <a href="https://arstechnica.com/ai/2026/03/nvidia-is-reportedly-planning-its-own-open-source-openclaw-competitor/">Read More</a></p></li></ul><p>Law Enforcement &amp; Takedowns </p><p>A major international operation took down a sprawling proxy botnet this week.</p><ul><li><p>&#128660; International law enforcement dismantled SocksEscort, a criminal proxy service that hijacked 369,000 IPs across 163 countries to commit large-scale fraud. (Published on 13-Mar-2026, The Hacker News). <a href="https://thehackernews.com/2026/03/authorities-disrupt-socksescort-proxy.html">Read More</a></p></li></ul><div><hr></div><p>Stay informed and secure in the tech and cybersecurity world. Have a great weekend, and remember to patch and protect your systems!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://thefwu.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Friday Wrap Up! Subscribe and never miss a weekly edition!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Friday Wrap Up: 6 March 2026]]></title><description><![CDATA[Happy Friday, security professionals!]]></description><link>https://thefwu.com/p/friday-wrap-up-6-march-2026</link><guid isPermaLink="false">https://thefwu.com/p/friday-wrap-up-6-march-2026</guid><dc:creator><![CDATA[Jorge Laurel]]></dc:creator><pubDate>Fri, 06 Mar 2026 20:01:28 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" width="550" height="320.8333333333333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:420,&quot;width&quot;:720,&quot;resizeWidth&quot;:550,&quot;bytes&quot;:204370,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Happy Friday, security professionals! &#128272;</p><p>This week in cybersecurity served up everything from drone strikes on cloud data centers (yes, physical ones) to hackers tapping FBI wiretap systems, AI assistants getting hijacked, and your car&#8217;s tire sensors moonlighting as surveillance tools.</p><p>Nation-state actors from China, North Korea, and Iran were all running active campaigns. Critical vulnerabilities hit Android, Cisco firewalls, and iOS &#8212; while global law enforcement struck back, dismantling Tycoon 2FA, seizing LeakBase, and arresting a $46M crypto thief in Saint Martin (the vacation vibes did not help).</p><p>The Friday Wrap Up has the full breakdown &#8212; scroll down for the details your weekend threat briefing needs. &#9749;</p><p>#Ransomware #DataBreach #Malware #AI #CyberSecurity #ThreatIntelligence #FWU #fridaywrapup #InfoSec</p><div><hr></div><p>Major Cyberattacks &amp; Incidents</p><p>This week&#8217;s headline incidents ranged from drone strikes on cloud infrastructure to a jaw-dropping breach of FBI surveillance systems &#8212; buckle up.</p><ul><li><p>&#127963;&#65039; Hackers breached an FBI network used to manage wiretaps and foreign intelligence surveillance warrants, raising serious concerns about a potential state-sponsored intrusion into critical law enforcement systems. (Published on 6-Mar-2026, CSO Online). <strong><a href="https://www.csoonline.com/article/4141870/fbi-wiretap-system-tapped-by-hackers.html">Read More</a></strong></p></li><li><p>&#128165; Drone strikes damaged four Amazon Web Services data centers across the UAE and Bahrain, triggering widespread cloud outages across dozens of services and spotlighting the physical vulnerability of critical cloud infrastructure. (Published on 3-Mar-2026, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/technology/amazon-drone-strikes-damaged-aws-data-centers-in-middle-east/">Read More</a></strong></p></li><li><p>&#127973; A breach at the University of Hawaii Cancer Center exposed SSNs, driver&#8217;s licenses, voter records, and health data for 1.2 million individuals. (Published on 3-Mar-2026, SecurityWeek). <strong><a href="https://www.securityweek.com/1-2-million-affected-by-university-of-hawaii-cancer-center-data-breach/">Read More</a></strong></p></li><li><p>&#9876;&#65039; Iran and allied threat actors launched targeted cyberattacks against U.S. and Israeli infrastructure in retaliation for military operations, seeking to cause economic and physical disruption. (Published on 3-Mar-2026, Dark Reading). <strong><a href="https://www.darkreading.com/threat-intelligence/war-pro-iranian-actors-cyberattacks">Read More</a></strong></p></li><li><p>&#128176; A U.S. government contractor&#8217;s son was arrested in Saint Martin for allegedly stealing over $46 million in cryptocurrency from the U.S. Marshals Service. (Published on 5-Mar-2026, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/security/fbi-arrests-suspect-linked-to-46m-crypto-theft-from-us-marshals/">Read More</a></strong></p></li></ul><div><hr></div><p>Espionage &amp; Nation-State Activity</p><p>China, North Korea, and Iran were all active this week &#8212; a full geopolitical sweep with new tools and fresh targets.</p><ul><li><p>&#128373;&#65039; The FBI warns that Chinese espionage group Salt Typhoon remains an active and broad threat to U.S. telecom infrastructure and both private and public sectors, well beyond its high-profile 2024 campaign. (Published on 19-Feb-2026, CyberScoop). <strong><a href="https://cyberscoop.com/fbi-salt-typhoon-ongoing-threat-cybertalks-2026/">Read More</a></strong></p></li><li><p>&#127472;&#127477; North Korea&#8217;s Contagious Interview campaign published 26 malicious npm packages masquerading as developer tools, using Pastebin as a dead-drop C2 resolver to deploy a cross-platform Remote Access Trojan. (Published on 2-Mar-2026, The Hacker News). <strong><a href="https://thehackernews.com/2026/03/north-korean-hackers-publish-26-npm.html">Read More</a></strong></p></li><li><p>&#129521; Threat actors leveraged open-source AI platform CyberStrikeAI to conduct automated attacks against Fortinet FortiGate appliances across 55 countries, signaling a troubling new chapter in AI-assisted exploitation at scale. (Published on 3-Mar-2026, The Hacker News). <strong><a href="https://thehackernews.com/2026/03/open-source-cyberstrikeai-deployed-in.html">Read More</a></strong></p></li><li><p>&#127470;&#127479; Iran&#8217;s MuddyWater APT deployed a new &#8220;Dindoor&#8221; backdoor against U.S. banks, airports, non-profits, and the Israeli branch of a U.S. software company as regional tensions spill further into cyberspace. (Published on 6-Mar-2026, Infosecurity). <strong><a href="https://www.infosecurity-magazine.com/news/iran-muddywater-hackers-us-firms/">Read More</a></strong></p></li></ul><div><hr></div><p>Malware &amp; Phishing Campaigns</p><p>Threat actors got creative this week &#8212; from fake conference platforms to poisoned search results and repurposed monitoring tools turned spy software.</p><ul><li><p>&#127907; A phishing campaign uses a fake Google Account security page to deliver a PWA app that steals MFA codes, harvests crypto wallet addresses, and proxies attacker traffic through the victim&#8217;s browser. (Published on 2-Mar-2026, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/security/fake-google-security-site-uses-pwa-app-to-steal-credentials-mfa-codes/">Read More</a></strong></p></li><li><p>&#128249; Fake Zoom and Google Meet pages trick Windows users into installing Teramind, a legitimate employee monitoring tool repurposed by attackers for covert surveillance via phishing links and fake update prompts. (Published on 2-Mar-2026, Hackread). <strong><a href="https://hackread.com/zoom-google-meet-phishing-teramind-monitoring-tool/">Read More</a></strong></p></li><li><p>&#128269; Bing search results pointed users to malicious GitHub repositories disguised as OpenClaw installers that silently deployed malware instead of the legitimate AI development tool. (Published on 6-Mar-2026, Malwarebytes). <strong><a href="https://www.malwarebytes.com/blog/news/2026/03/beware-of-fake-openclaw-installers-even-if-bing-points-you-to-github">Read More</a></strong></p></li><li><p>&#128172; Cybercriminals are rapidly embracing Telegram to sell corporate access, malware-as-a-service subscriptions, and stolen credential logs, transforming the messaging platform into a fast-moving underground marketplace. (Published on 4-Mar-2026, Hackread). <strong><a href="https://hackread.com/telegram-used-sell-access-malware-stolen-logs/">Read More</a></strong></p></li></ul><div><hr></div><p>Vulnerabilities &amp; Patches</p><p>From zero-click helpdesk exploits to nation-state-grade iOS chains and your car&#8217;s tire sensors, this week made clear that attack surfaces keep expanding.</p><ul><li><p>&#128231; A maximum-severity zero-click flaw in the FreeScout helpdesk platform (Mail2Shell) enables unauthenticated remote code execution, allowing complete server takeover without any user interaction. (Published on 4-Mar-2026, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/security/mail2shell-zero-click-attack-lets-hackers-hijack-freescout-mail-servers/">Read More</a></strong></p></li><li><p>&#128241; Google&#8217;s March Android update patches 129 vulnerabilities &#8212; the largest single-month count since April 2018 &#8212; including an actively exploited Qualcomm zero-day. (Published on 2-Mar-2026, CyberScoop). <strong><a href="https://cyberscoop.com/android-security-update-march-2026/">Read More</a></strong></p></li><li><p>&#128293; Cisco disclosed two maximum-severity flaws in its Secure Firewall Management Center software that could allow remote unauthenticated attackers to gain root access and execute arbitrary code. (Published on 5-Mar-2026, CyberScoop). <strong><a href="https://cyberscoop.com/cisco-critical-vulnerabilities-secure-firewall-management-center-software/">Read More</a></strong></p></li><li><p>&#127822; Google&#8217;s GTIG identified Coruna, a sophisticated iOS exploit kit featuring five full exploit chains and 23 vulnerabilities targeting iOS versions 13 through 17.2.1 &#8212; though it&#8217;s ineffective against current iOS. (Published on 4-Mar-2026, The Hacker News). <strong><a href="https://thehackernews.com/2026/03/coruna-ios-exploit-kit-uses-23-exploits.html">Read More</a></strong></p></li><li><p>&#128680; CISA added vulnerabilities from the nation-state-grade Coruna iOS exploit kit to its Known Exploited Vulnerabilities catalog, covering 23 flaws spanning iOS 13 through 17.2.1. (Published on 6-Mar-2026, SecurityWeek). <strong><a href="https://www.securityweek.com/cisa-adds-ios-flaws-from-coruna-exploit-kit-to-kev/">Read More</a></strong></p></li><li><p>&#128663; IMDEA Networks researchers found that unencrypted tire pressure sensor signals from Toyota and Mercedes vehicles can be exploited to covertly track drivers&#8217; locations and map daily routines &#8212; with no current regulatory protection. (Published on 4-Mar-2026, Hackread). <strong><a href="https://hackread.com/car-tyre-sensors-track-drivers-without-knowledge/">Read More</a></strong></p></li></ul><div><hr></div><p>AI Security</p><p>AI tools are quickly becoming both prime targets and active weapons &#8212; this week&#8217;s stories span vulnerable browser assistants, agentic exploits, and AI-powered attack platforms.</p><ul><li><p>&#129302; A critical, now-patched flaw in the widely adopted AI agent tool OpenClaw highlights how rapid developer adoption continues to outpace security review, leaving AI-powered workflows exposed. (Published on 2-Mar-2026, Dark Reading). <strong><a href="https://www.darkreading.com/application-security/critical-openclaw-vulnerability-ai-agent-risks">Read More</a></strong></p></li><li><p>&#128302; A vulnerability in Chrome allowed malicious extensions to hijack the Gemini Live AI assistant, enabling attackers to spy on users and exfiltrate files. Google has since patched the flaw. (Published on 2-Mar-2026, SecurityWeek). <strong><a href="https://www.securityweek.com/vulnerability-allowed-hijacking-chromes-gemini-live-ai-assistant/">Read More</a></strong></p></li><li><p>&#128477;&#65039; Researchers uncovered PleaseFix vulnerabilities in Perplexity&#8217;s Comet AI browser that allow zero-click calendar invites to trigger AI agents into stealing 1Password credentials and personal files. (Published on 5-Mar-2026, Hackread). <strong><a href="https://hackread.com/pleasefix-flaw-hackers-1password-vault-comet-ai-browser/">Read More</a></strong></p></li></ul><div><hr></div><p>Law Enforcement &amp; Takedowns</p><p>Global coalitions fought back hard this week, dismantling phishing platforms, seizing underground forums, and arresting those who prey on the most vulnerable.</p><ul><li><p>&#128737;&#65039; A Microsoft-led global coalition seized 330 domains powering the Tycoon 2FA phishing-as-a-service platform, with the alleged creator named in a civil complaint. (Published on 4-Mar-2026, CyberScoop). <strong><a href="https://cyberscoop.com/tycoon-2fa-phishing-kit-takedown-microsoft/">Read More</a></strong></p></li><li><p>&#128452;&#65039; FBI and Europol seized LeakBase, a major cybercrime forum with over 142,000 members that traded stolen credentials and hacking tools, in a coordinated international operation. (Published on 5-Mar-2026, The Hacker News). <strong><a href="https://thehackernews.com/2026/03/fbi-and-europol-seize-leakbase-forum.html">Read More</a></strong></p></li><li><p>&#128110; Europol&#8217;s Project Compass dismantled the 764 Network, an online group exploiting minors, resulting in 30 arrests and the rescue of victims &#8212; with investigators warning the operation is far from over. (Published on 3-Mar-2026, Hackread). <strong><a href="https://hackread.com/project-compass-764-network-aarrest-victims-rescued/">Read More</a></strong></p></li></ul><div><hr></div><p>Policy &amp; Geopolitics</p><p>The digital and political worlds continued to collide, with one app store decision signaling a new chapter in U.S.-China tech decoupling.</p><ul><li><p>&#127482;&#127480; Apple removed all ByteDance-owned apps from the U.S. App Store following TikTok&#8217;s operational transfer, cutting off U.S. users from the company&#8217;s Chinese application ecosystem entirely. (Published on 6-Mar-2026, Ars Technica). <strong><a href="https://www.wired.com/story/bytedance-apps-are-no-longer-available-in-us-app-stores/">Read More</a></strong></p></li></ul><p></p><div><hr></div><p>Stay informed and secure in the tech and cybersecurity world. Have a great weekend, and remember to patch and protect your systems!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://thefwu.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Friday Wrap Up! Subscribe and never miss a weekly edition!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Friday Wrap Up: 27 February 2026]]></title><description><![CDATA[Another Friday, another reason to question whether your apps, APIs, and Zoom calls are working for you &#8212; or someone else.]]></description><link>https://thefwu.com/p/friday-wrap-up-27-february-2026</link><guid isPermaLink="false">https://thefwu.com/p/friday-wrap-up-27-february-2026</guid><dc:creator><![CDATA[Jorge Laurel]]></dc:creator><pubDate>Fri, 27 Feb 2026 20:01:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" width="550" height="320.8333333333333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:420,&quot;width&quot;:720,&quot;resizeWidth&quot;:550,&quot;bytes&quot;:204370,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Another Friday, another reason to question whether your apps, APIs, and Zoom calls are working for you &#8212; or someone else. &#128737;&#65039;</p><p>This week&#8217;s Friday Wrap Up covers ransomware hitting chip makers and medical device companies, China-linked spies repurposing Google Sheets as a command center (productivity hack of the year, unfortunately), North Korea expanding into healthcare ransomware, and a fake Zoom meeting that installs surveillance software before you finish your first sip of coffee.</p><p>We&#8217;ve also got AI coding tools under the security microscope, a blockchain-backed botnet that laughs at takedowns, and a reminder that those old Google API keys you forgot about? They now open doors to Gemini AI data.</p><p>If your threat model doesn&#8217;t give you anxiety, you might not be reading the right newsletter. Click below for the full breakdown. &#128071;</p><p>#CyberSecurity #FWU #fridaywrapup #RansomwareWeek #NationStateThreats #DataBreach</p><div><hr></div><p>Major Cyberattacks &amp; Incidents This week was a buffet of breaches &#8212; ransomware hit chip testing and medical devices, while a casino and e-commerce giant rounded out the damage.</p><ul><li><p>&#127981; Leading semiconductor chip testing firm Advantest suffered a ransomware attack, triggering incident response protocols across operations. (Published on Feb 23, 2026, Infosecurity). <a href="https://www.infosecurity-magazine.com/news/advantest-ransomware-attack/">Read More</a></p></li><li><p>&#127973; Medical device manufacturer UFP Technologies was hit by ransomware involving both data theft and file-encrypting malware, compromising operations. (Published on Feb 25, 2026, SecurityWeek). <a href="https://www.securityweek.com/medical-device-maker-ufp-technologies-hit-by-cyberattack/">Read More</a></p></li><li><p>&#128176; PayPal confirmed a six-month data exposure via its Working Capital loan system, leaking names, birthdates, and Social Security numbers. (Published on Feb 23, 2026, Hackread). <a href="https://hackread.com/paypal-confirms-loan-system-error-data-exposure/">Read More</a></p></li><li><p>&#127920; Wynn Resorts confirmed employee data theft after appearing on ShinyHunters&#8217; extortion leak site, marking another hospitality sector breach. (Published on Feb 24, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/wynn-resorts-confirms-employee-data-breach-after-extortion-threat/">Read More</a></p></li><li><p>&#128722; Hackers allegedly stole personal data from 38 million ManoMano users, including names, emails, and phone numbers. (Published on Feb 27, 2026, SecurityWeek). <a href="https://www.securityweek.com/38-million-allegedly-impacted-by-manomano-data-breach/">Read More</a></p></li></ul><div><hr></div><p>Malware &amp; Vulnerabilities New malware variants emerged from multiple directions this week &#8212; blockchain-backed botnets, trojanized apps, and stealthy Go modules made defenders earn their paychecks.</p><ul><li><p>&#9935;&#65039; A wormable cryptojacking campaign using pirated software deploys a custom XMRig miner with BYOVD exploits and a time-based logic bomb for persistence. (Published on Feb 23, 2026, The Hacker News). <a href="https://thehackernews.com/2026/02/wormable-xmrig-campaign-uses-byovd.html">Read More</a></p></li><li><p>&#128241; ZeroDayRAT, a new Android/iOS malware-as-a-service sold via Telegram, claims full device monitoring, location tracking, and crypto theft capabilities. (Published on Feb 24, 2026, Hackread). <a href="https://hackread.com/zerodayrat-malware-monitoring-android-ios-devices/">Read More</a></p></li><li><p>&#128123; Arkanix Stealer, a C++/Python malware exfiltrating browser data and system info, quietly vanished shortly after its brief public debut. (Published on Feb 24, 2026, SecurityWeek). <a href="https://www.securityweek.com/arkanix-stealer-malware-disappears-shortly-after-debut/">Read More</a></p></li><li><p>&#9939;&#65039; The Aeternum C2 botnet uses Polygon blockchain for command-and-control, making traditional takedowns nearly impossible. (Published on Feb 26, 2026, Hackread). <a href="https://hackread.com/aeternum-c2-botnet-polygon-blockchain/">Read More</a></p></li><li><p>&#9760;&#65039; CISA warns RESURGE malware can lay dormant on Ivanti Connect Secure devices, exploiting CVE-2025-0282 with persistence capabilities that survive reboots. (Published on Feb 27, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/cisa-warns-that-resurge-malware-can-be-dormant-on-ivanti-devices/">Read More</a></p></li><li><p>&#128013; A malicious Go crypto module masquerades as a legitimate library, harvesting passwords, creating SSH backdoors, and deploying the Rekoobe Linux backdoor. (Published on Feb 27, 2026, The Hacker News). <a href="https://thehackernews.com/2026/02/malicious-go-crypto-module-steals.html">Read More</a></p></li><li><p>&#127918; Trojanized gaming utilities distributed via browsers and chat platforms deploy a Java-based RAT using PowerShell and a malicious JAR file. (Published on Feb 27, 2026, The Hacker News). <a href="https://thehackernews.com/2026/02/trojanized-gaming-tools-spread-java.html">Read More</a></p></li><li><p>&#129496; Android mental health apps with 14.7 million combined installs contain serious security vulnerabilities exposing sensitive medical data on Google Play. (Published on Feb 23, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/android-mental-health-apps-with-147m-installs-filled-with-security-flaws/">Read More</a></p></li></ul><div><hr></div><p>Espionage &amp; Data Extraction Nation-state actors kept busy this week &#8212; China-linked groups used Google Sheets as a spy tool while North Korea expanded its ransomware reach.</p><ul><li><p>&#128373;&#65039; Google disrupted UNC2814, a China-linked group that breached 53 organizations across 42 countries using the GRIDTIDE backdoor and Google Sheets as covert C2 infrastructure. (Published on Feb 25, 2026, The Hacker News). <a href="https://thehackernews.com/2026/02/google-disrupts-unc2814-gridtide.html">Read More</a></p></li><li><p>&#128202; Chinese hackers repurposed Google Sheets as a covert spy tool to issue commands and harvest PII from telecom and government targets across 42 countries. (Published on Feb 26, 2026, CSO Online). <a href="https://www.csoonline.com/article/4137834/china-linked-hackers-used-google-sheets-to-spy-on-telecoms-and-governments-across-42-countries.html">Read More</a></p></li><li><p>&#127472;&#127477; North Korea&#8217;s Lazarus Group expanded into healthcare ransomware via Medusa, targeting US organizations as part of its evolving criminal-espionage hybrid operations. (Published on Feb 24, 2026, Infosecurity). <a href="https://www.infosecurity-magazine.com/news/north-korean-lazarus-group-medusa/">Read More</a></p></li></ul><div><hr></div><p>Major Cyberattacks &amp; Infrastructure Firewalls and SD-WAN vulnerabilities reminded us that edge devices remain prime real estate for attackers this week.</p><ul><li><p>&#128293; AI-assisted attackers exploited exposed ports and weak credentials to compromise hundreds of FortiGate firewalls, according to AWS research. (Published on Feb 23, 2026, SecurityWeek). <a href="https://www.securityweek.com/hundreds-of-fortigate-firewalls-hacked-in-ai-powered-attacks-aws/">Read More</a></p></li><li><p>&#128732; A critical authentication bypass in Cisco Catalyst SD-WAN (CVE-2026-20127) has been actively exploited in zero-day attacks since 2023, allowing attackers to add rogue peers. (Published on Feb 25, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/critical-cisco-sd-wan-bug-exploited-in-zero-day-attacks-since-2023/">Read More</a></p></li></ul><div><hr></div><p>Social Engineering &amp; Phishing Sometimes the most dangerous attack vector is a convincing Zoom invite &#8212; this week proved that human behavior remains the hardest vulnerability to patch.</p><ul><li><p>&#128249; A fake Zoom meeting scam silently installs Teramind surveillance software on victims&#8217; systems via an auto-download disguised as a legitimate update. (Published on Feb 25, 2026, CSO Online). <a href="https://www.csoonline.com/article/4136834/fake-zoom-meeting-silently-installs-surveillance-software-says-malwarebytes.html">Read More</a></p></li><li><p>&#127919; The 1Campaign platform helps threat actors cloak malicious Google Ads, hiding phishing pages from security reviewers while targeting real users. (Published on Feb 27, 2026, Hackread). <a href="https://hackread.com/hackers-1campaign-hide-malicious-ads-google-reviewers/">Read More</a></p></li></ul><div><hr></div><p>Vulnerability Research &amp; Industry Analysis From AI coding tools to decade-old API keys, researchers this week found that trust is a fragile thing in software ecosystems.</p><ul><li><p>&#129302; Claude Code shows security promise but researchers caution its real-world impact has been overstated despite its stock-market ripple effect. (Published on Feb 26, 2026, Dark Reading). <a href="https://www.darkreading.com/application-security/claude-code-security-shows-promise-not-perfection/">Read More</a></p></li><li><p>&#128273; Google API keys originally embedded for Maps can now authenticate to Gemini AI, accidentally exposing private AI data through previously harmless credentials. (Published on Feb 26, 2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/previously-harmless-google-api-keys-now-expose-gemini-ai-data/">Read More</a></p></li><li><p>&#128025; The RoguePilot flaw in GitHub Codespaces allowed attackers to hijack repositories by injecting malicious Copilot instructions via GitHub Issues, now patched. (Published on Feb 24, 2026, The Hacker News). <a href="https://thehackernews.com/2026/02/roguepilot-flaw-in-github-codespaces.html">Read More</a></p></li><li><p>&#128081; Qilin ransomware gang dominated January 2026 with over 100 observed attacks, leading a rapidly fragmenting ransomware ecosystem. (Published on Feb 26, 2026, ComputerWeekly). <a href="https://www.computerweekly.com/news/366639339/Qilin-crew-continues-to-dominate-ransomware-ecosystem/">Read More</a></p></li></ul><div><hr></div><p>Law Enforcement &amp; Operations Interpol and African agencies made a dent in cybercrime this week &#8212; 651 arrests and $4.3 million recovered is a good Friday.</p><ul><li><p>&#128660; Operation Red Card 2.0 resulted in 651 arrests across Africa as Interpol and cybersecurity firms collaborated to recover $4.3 million from cybercrime groups. (Published on Feb 25, 2026, Dark Reading). <a href="https://www.darkreading.com/cybersecurity-operations/operation-red-card-2-0-leads-to-651-arrests-in-africa/">Read More</a></p></li></ul><div><hr></div><p>AI &amp; Policy The line between AI innovation and ethical guardrails got some public attention this week, with employees from competing labs taking a united stand.</p><ul><li><p>&#129309; Google and OpenAI employees co-signed an open letter supporting Anthropic&#8217;s Pentagon stance against mass domestic surveillance and autonomous weaponry. (Published on Feb 27, 2026, TechCrunch). <a href="https://techcrunch.com/2026/02/27/employees-at-google-and-openai-support-anthropics-pentagon-stand-in-open-letter/">Read More</a></p></li></ul><div><hr></div><p>Stay informed and secure in the tech and cybersecurity world. Have a great weekend, and remember to patch and protect your systems!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://thefwu.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Friday Wrap Up! Subscribe and never miss a weekly edition!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Friday Wrap Up: 20 February 2026]]></title><description><![CDATA[Another week, another reminder that the internet is basically a haunted house and someone keeps adding new rooms.]]></description><link>https://thefwu.com/p/friday-wrap-up-20-february-2026</link><guid isPermaLink="false">https://thefwu.com/p/friday-wrap-up-20-february-2026</guid><dc:creator><![CDATA[Jorge Laurel]]></dc:creator><pubDate>Fri, 20 Feb 2026 20:01:07 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" width="550" height="320.8333333333333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:420,&quot;width&quot;:720,&quot;resizeWidth&quot;:550,&quot;bytes&quot;:204370,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Another week, another reminder that the internet is basically a haunted house and someone keeps adding new rooms. &#127962;&#65039;</p><p>This week&#8217;s Friday Wrap Up covers data breaches hitting your wallet and your wardrobe, Android malware clever enough to use Google&#8217;s own AI against you, Chrome zero-days being actively exploited, fake AI tools fooling a quarter million users, and OAuth phishing attacks that let hackers waltz through MFA like they own the place.</p><p>Oh, and your password manager? Researchers had some thoughts. Not great ones.</p><p>Drop into the full newsletter for the details your security team will definitely want to see before Monday. &#128071;</p><p>#FWU #fridaywrapup #SupplyChainSecurity #MobileThreatIntelligence #AIandCyber #Malware #Ransomware #DataBreach</p><p></p><div><hr></div><p>Major Cyberattacks &amp; Incidents</p><p>This week&#8217;s breach roundup spans retail, fintech, and consumer payments &#8212; a reminder that no sector is off-limits.</p><ul><li><p>&#129442; ShinyHunters claims to have stolen 600K Canada Goose customer records containing personal and payment-related data. Canada Goose says it has not confirmed a breach of its own systems but is actively investigating. (Published on 16-Feb-2026, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/security/canada-goose-investigating-as-hackers-leak-600k-customer-records/">Read More</a></strong></p></li><li><p>&#127974; Blockchain fintech firm Figure Technology Solutions suffered a breach exposing nearly 1 million accounts&#8217; personal and contact information, with ShinyHunters leaking over 2GB of stolen data. (Published on 18-Feb-2026, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/security/data-breach-at-fintech-firm-figure-affects-nearly-1-million-accounts/">Read More</a></strong></p></li><li><p>&#128179; PayPal disclosed a data breach caused by a software error in a loan application that exposed customers&#8217; sensitive personal information, including Social Security numbers, for nearly six months. (Published on 20-Feb-2026, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/security/paypal-discloses-data-breach-exposing-users-personal-information/">Read More</a></strong></p></li><li><p>&#128421;&#65039; Hackers used fake Social Security Administration emails to hijack ScreenConnect remote access tools, bypassing Windows security to target organizations in the UK, US, and Canada. (Published on 17-Feb-2026, Hackread). <strong><a href="https://hackread.com/hackers-screenconnect-hijack-pcs-fake-social-security-emails/">Read More</a></strong></p></li><li><p>&#127917; Operation DoppelBrand used spoofed brand identities of major financial institutions like Wells Fargo to run credential theft phishing campaigns targeting corporate employees. (Published on 16-Feb-2026, Infosecurity). <strong><a href="https://www.infosecurity-magazine.com/news/operation-doppelbrand-trusted/">Read More</a></strong></p></li></ul><div><hr></div><p>Malware &amp; Vulnerabilities</p><p>This week&#8217;s malware landscape featured stealthy mobile threats, preinstalled risks, and a developer supply chain compromise.</p><ul><li><p>&#128241; ZeroDayRAT, a new mobile spyware sold on Telegram, enables real-time surveillance and data theft on Android and iOS devices, with dedicated sales and support channels for buyers. (Published on 16-Feb-2026, The Hacker News). <strong><a href="https://thehackernews.com/2026/02/new-zerodayrat-mobile-spyware-enables.html">Read More</a></strong></p></li><li><p>&#128242; Keenadu, a new Android malware, has been found preinstalled on thousands of devices and distributed through Google Play and third-party app stores, posing broad consumer risk. (Published on 18-Feb-2026, SecurityWeek). <strong><a href="https://www.securityweek.com/new-keenadu-android-malware-found-on-thousands-of-devices/">Read More</a></strong></p></li><li><p>&#128373;&#65039; An infostealer campaign is actively targeting OpenClaw users by stealing configuration files, potentially exposing sensitive credentials and operational data stored by the autonomous AI agent. (Published on 17-Feb-2026, Infosecurity). <strong><a href="https://www.infosecurity-magazine.com/news/infostealer-targets-openclaw/">Read More</a></strong></p></li><li><p>&#129302; PromptSpy, the first Android malware to abuse Google&#8217;s Gemini AI at runtime, captures lockscreen data, blocks uninstallation, and maintains persistence on the device after reboots. (Published on 19-Feb-2026, The Hacker News). <strong><a href="https://thehackernews.com/2026/02/promptspy-android-malware-abuses-google.html">Read More</a></strong></p></li><li><p>&#9939;&#65039; A supply chain attack on Cline CLI 2.3.0 used a compromised npm token to stealthily install OpenClaw on developer systems via an unauthorized package update. (Published on 20-Feb-2026, The Hacker News). <strong><a href="https://thehackernews.com/2026/02/cline-cli-230-supply-chain-attack.html">Read More</a></strong></p></li></ul><div><hr></div><p>Phishing &amp; Social Engineering</p><p>Attackers are getting craftier about bypassing security controls users thought they could rely on.</p><ul><li><p>&#129700; A new device code phishing campaign tricks employees into handing over OAuth tokens granting persistent access to Microsoft 365 accounts, including Outlook, Teams, and OneDrive &#8212; without stealing passwords. (Published on 20-Feb-2026, CSO Online). <strong><a href="https://www.csoonline.com/article/4134874/new-phishing-campaign-tricks-employees-into-bypassing-microsoft-365-mfa.html">Read More</a></strong></p></li><li><p>&#129513; Thirty fake AI browser extensions tricked over 260,000 Chrome users &#8212; and Google itself &#8212; into believing they were legitimate tools, highlighting serious gaps in extension vetting. (Published on 16-Feb-2026, Dark Reading). <strong><a href="https://www.darkreading.com/cyber-risk/chrome-fake-ai-browser-extensions">Read More</a></strong></p></li></ul><div><hr></div><p>Vulnerability Research &amp; Industry Analysis</p><p>Researchers this week exposed long-standing weaknesses in tools millions rely on daily &#8212; from browsers and IDEs to PDF platforms and password managers.</p><ul><li><p>&#128273; Security researchers challenged end-to-end encryption claims of popular commercial password managers, uncovering vulnerabilities that allow hackers to view and change stored passwords. (Published on 16-Feb-2026, Infosecurity). <strong><a href="https://www.infosecurity-magazine.com/news/vulnerabilities-password-managers/">Read More</a></strong></p></li><li><p>&#127760; Google patched CVE-2026-2441, the first actively exploited Chrome zero-day of 2026, a high-severity use-after-free flaw in Chrome&#8217;s CSS component already being exploited in the wild. (Published on 16-Feb-2026, SOC Prime). <strong><a href="https://socprime.com/blog/cve-2026-14174-vulnerability/">Read More</a></strong></p></li><li><p>&#128187; Critical vulnerabilities found in four VS Code extensions &#8212; Live Server, Code Runner, Markdown Preview Enhanced, and one other &#8212; with a combined 125 million installs could allow remote code execution and local file theft. (Published on 18-Feb-2026, The Hacker News). <strong><a href="https://thehackernews.com/2026/02/critical-flaws-found-in-four-vs-code.html">Read More</a></strong></p></li><li><p>&#128196; Researchers discovered 16 vulnerabilities in Foxit and Apryse PDF tools exploitable via malicious documents or URLs, enabling account takeover and data exfiltration from widely deployed platforms. (Published on 18-Feb-2026, SecurityWeek). <strong><a href="https://www.securityweek.com/vulnerabilities-in-popular-pdf-platforms-allowed-account-takeover-data-exfiltration/">Read More</a></strong></p></li><li><p>&#128269; A scan of 5 million JavaScript applications revealed the shocking prevalence of leaked API keys and secrets hidden in front-end bundles, exposing the true scale of a long-understated problem. (Published on 17-Feb-2026, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/security/what-5-million-apps-revealed-about-secrets-in-javascript/">Read More</a></strong></p></li><li><p>&#128300; Emerging chiplet-based computing architectures introduce new cybersecurity challenges for AI systems and autonomous vehicles, demanding fresh approaches to securing modular, flexible hardware supply chains. (Published on 20-Feb-2026, Dark Reading). <strong><a href="https://www.darkreading.com/cyber-risk/emerging-chiplet-designs-spark-fresh-cybersecurity-challenges">Read More</a></strong></p></li></ul><div><hr></div><p>Espionage &amp; Nation-State Activity</p><p>Nation-state threats dominated headlines this week, with Chinese actors at the center of long-running campaigns and legal action.</p><ul><li><p>&#128009; A Chinese APT group exploited a CVSS 10.0 zero-day vulnerability in Dell RecoverPoint for Virtual Machines for two years before Mandiant publicly disclosed the campaign. (Published on 18-Feb-2026, Infosecurity). <strong><a href="https://www.infosecurity-magazine.com/news/chinese-apt-exploits-dell-zeroday/">Read More</a></strong></p></li><li><p>&#9878;&#65039; Texas sued TP-Link Systems, alleging the company deceived consumers by marketing routers as secure while Chinese state-backed hackers exploited firmware vulnerabilities to access users&#8217; devices. (Published on 19-Feb-2026, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/security/texas-sues-tp-link-over-chinese-hacking-risks-user-deception/">Read More</a></strong></p></li><li><p>&#127757; Long-standing Western cybersecurity alliances are showing signs of fracture as geopolitical shifts cause major nations to rethink collaborative security frameworks built over the past two decades. (Published on 17-Feb-2026, Computer Weekly). <strong><a href="https://www.computerweekly.com/news/366639044/Western-cyber-alliances-risk-fragmenting-in-new-world-order">Read More</a></strong></p></li></ul><div><hr></div><p>AI &amp; Policy</p><p>AI is reshaping the threat landscape from both sides of the fence &#8212; as a tool for attackers and a defense mechanism for platforms.</p><ul><li><p>&#129440; Researchers demonstrated that Microsoft Copilot and xAI Grok can be weaponized as stealthy malware command-and-control proxies, blending malicious traffic into normal enterprise communications. (Published on 17-Feb-2026, The Hacker News). <strong><a href="https://thehackernews.com/2026/02/researchers-show-copilot-and-grok-can.html">Read More</a></strong></p></li><li><p>&#127922; AI-generated passwords are highly predictable and not truly random, making them significantly easier for cybercriminals to crack than traditional randomly generated passwords. (Published on 19-Feb-2026, Malwarebytes). <strong><a href="https://www.malwarebytes.com/blog/news/2026/02/ai-generated-passwords-are-a-security-risk">Read More</a></strong></p></li><li><p>&#129504; Memory, not just GPUs, is becoming the critical bottleneck and cost driver in AI infrastructure, shifting how organizations plan and budget for running large language models at scale. (Published on 17-Feb-2026, TechCrunch). <strong><a href="https://techcrunch.com/2026/02/17/running-ai-models-is-turning-into-a-memory-game/">Read More</a></strong></p></li><li><p>&#128737;&#65039; Google reported its AI systems prevented 1.75 million malicious apps from reaching Google Play in 2025, demonstrating measurable progress in AI-assisted platform security. (Published on 19-Feb-2026, TechCrunch). <strong><a href="https://techcrunch.com/2026/02/19/google-says-its-ai-systems-helped-deter-play-store-malware-in-2025/">Read More</a></strong></p></li><li><p>&#128272; Android 17 Beta debuts a secure-by-default architecture alongside new privacy features and a Canary development channel, raising the baseline security bar for Android devices. (Published on 17-Feb-2026, Infosecurity). <strong><a href="https://www.infosecurity-magazine.com/news/android-17-beta-secure-default/">Read More</a></strong></p></li></ul><p></p><div><hr></div><p>Stay informed and secure in the tech and cybersecurity world. Have a great weekend, and remember to patch and protect your systems!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://thefwu.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Friday Wrap Up! Subscribe and never miss a weekly edition!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Friday Wrap Up: 13 February 2026]]></title><description><![CDATA[Another week, another collection of reasons why your security team hasn&#8217;t slept properly since 2019.]]></description><link>https://thefwu.com/p/friday-wrap-up-13-february-2026</link><guid isPermaLink="false">https://thefwu.com/p/friday-wrap-up-13-february-2026</guid><dc:creator><![CDATA[Jorge Laurel]]></dc:creator><pubDate>Fri, 13 Feb 2026 19:30:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" width="550" height="320.8333333333333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:420,&quot;width&quot;:720,&quot;resizeWidth&quot;:550,&quot;bytes&quot;:204370,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p></p><p>Another week, another collection of reasons why your security team hasn&#8217;t slept properly since 2019. This week&#8217;s FWU brings you everything from ransomware gangs cosplaying as employee monitoring software to North Korean job applicants who are definitely not who they claim to be on LinkedIn (looking at you, &#8220;Senior DevOps Engineer&#8221;).</p><p>We&#8217;ve got cloud infrastructure being turned into crime bots, Olympic ice dancers accidentally committing AI plagiarism, and the eternal question: &#8220;Is that zero-day actively exploited?&#8221; (Spoiler: yes, probably within 24 hours of the PoC dropping).</p><p>Plus, if you&#8217;ve ever wondered what happens when someone hijacks an abandoned Outlook add-in with a 4.71-star rating, the answer is: 4,000 people learn an important lesson about marketplace trust models.</p><p>Dive in for your weekly dose of &#8220;things that keep CISOs up at night&#8221; &#11015;&#65039;</p><p>#FWU #fridaywrapup #ZeroDayMadness #SupplyChainChaos #CloudCrimeWave #Ransomware #DataBreach #Malware</p><div><hr></div><p><strong>Major Cyberattacks &amp; Incidents</strong> </p><p>This week delivered multiple high-impact breaches and exploitation campaigns targeting enterprise infrastructure.</p><ul><li><p>&#128680; Hackers exploit SolarWinds Web Help Desk vulnerabilities to deploy Velociraptor forensic tools for persistence and remote control on compromised systems. (Published on 9-Feb-2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/threat-actors-exploit-solarwinds-wdh-flaws-to-deploy-velociraptor/">Read More</a></p></li><li><p>&#9888;&#65039; Nearly 100 organizations compromised through Ivanti zero-day vulnerabilities, with Shadowserver identifying 86 affected instances across multiple threat groups. (Published on 9-Feb-2026, CyberScoop). <a href="https://cyberscoop.com/ivanti-zero-day-vulnerabilities-netherlands-european-commission-shadowserver/">Read More</a></p></li><li><p>&#9729;&#65039; TeamPCP threat actor compromises cloud infrastructure at scale using automated worm-like attacks against exposed services and interfaces. (Published on 9-Feb-2026, Dark Reading). <a href="https://www.darkreading.com/cloud-security/teampcp-cloud-infrastructure-crime-bots">Read More</a></p></li><li><p>&#127973; ApolloMD data breach exposes personal information of 626,000 patients from affiliated physicians and medical practices. (Published on 12-Feb-2026, SecurityWeek). <a href="https://www.securityweek.com/apollomd-data-breach-impacts-626000-individuals/">Read More</a></p></li><li><p>&#128663; Conduent breach now affects 25 million individuals, including nearly 17,000 Volvo Group employees whose data was exposed in the expanding incident. (Published on 11-Feb-2026, SecurityWeek). <a href="https://www.securityweek.com/conduent-breach-hits-volvo-group-nearly-17000-employees-data-exposed/">Read More</a></p></li></ul><p><strong>Malware &amp; Vulnerabilities</strong> </p><p>Critical flaws and sophisticated malware campaigns dominated the vulnerability landscape this week.</p><ul><li><p>&#128308; Microsoft patches six actively exploited zero-days in February 2026 Patch Tuesday, addressing roughly 60 vulnerabilities across company products. (Published on 10-Feb-2026, SecurityWeek). <a href="https://www.securityweek.com/6-actively-exploited-zero-days-patched-by-microsoft-with-february-2026-updates/">Read More</a></p></li><li><p>&#128241; ZeroDayRAT emerges as new mobile spyware targeting both Android and iOS devices, providing attackers with persistent access capabilities. (Published on 10-Feb-2026, Infosecurity). <a href="https://www.infosecurity-magazine.com/news/zerodayrat-mobile-spyware-android/">Read More</a></p></li><li><p>&#127907; Lumma Stealer rebounds with ClickFix lures and Castleloader malware, installing the information stealer at scale after previous disruption. (Published on 11-Feb-2026, Ars Technica). <a href="https://arstechnica.com/security/2026/02/once-hobbled-lumma-stealer-is-back-with-lures-that-are-hard-to-resist/">Read More</a></p></li><li><p>&#128295; BeyondTrust critical RCE vulnerability targeted by hackers within 24 hours of proof-of-concept release for unauthenticated remote code execution. (Published on 13-Feb-2026, SecurityWeek). <a href="https://www.securityweek.com/beyondtrust-vulnerability-targeted-by-hackers-within-24-hours-of-poc-release/">Read More</a></p></li><li><p>&#127963;&#65039; CISA orders federal agencies to patch critical Microsoft Configuration Manager vulnerability from October 2024 now actively exploited in attacks. (Published on 13-Feb-2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/cisa-flags-microsoft-configmgr-rce-flaw-as-exploited-in-attacks/">Read More</a></p></li><li><p>&#128231; Abandoned Outlook add-in AgreeTo hijacked through orphaned subdomain to phish 4,000 Microsoft Office Store users through verified marketplace listing. (Published on 12-Feb-2026, CSO Online). <a href="https://www.csoonline.com/article/4131632/dead-outlook-add-in-hijacked-to-phish-4000-microsoft-office-store-users-2.html">Read More</a></p></li></ul><p><strong>Espionage &amp; Data Extraction</strong> </p><p>Nation-state actors and sophisticated threat groups launched targeted espionage campaigns across multiple platforms.</p><ul><li><p>&#127917; North Korean operatives impersonate professionals using real LinkedIn accounts with verified emails and identity badges for fraudulent remote job applications. (Published on 10-Feb-2026, The Hacker News). <a href="https://thehackernews.com/2026/02/dprk-operatives-impersonate.html">Read More</a></p></li><li><p>&#128242; Hackers use Signal QR codes and fake support scams to conduct surveillance on military and political leaders, German agencies warn. (Published on 9-Feb-2026, Hackread). <a href="https://hackread.com/hackers-signal-qr-codes-spy-on-military-political-leaders/">Read More</a></p></li><li><p>&#128230; Lazarus Group plants malicious packages in npm and PyPI repositories as part of fake recruitment campaign active since May 2025. (Published on 12-Feb-2026, The Hacker News). <a href="https://thehackernews.com/2026/02/lazarus-campaign-plants-malicious.html">Read More</a></p></li><li><p>&#127919; APT36 and SideCopy deploy cross-platform RATs targeting Indian defense and government organizations, compromising Windows and Linux environments. (Published on 11-Feb-2026, The Hacker News). <a href="https://thehackernews.com/2026/02/apt36-and-sidecopy-launch-cross.html">Read More</a></p></li><li><p>&#128188; UAT-9921 threat actor deploys VoidLink modular framework targeting technology and financial sectors, active since 2019 according to Cisco Talos. (Published on 13-Feb-2026, The Hacker News). <a href="https://thehackernews.com/2026/02/uat-9921-deploys-voidlink-malware-to.html">Read More</a></p></li></ul><p><strong>Ransomware &amp; Criminal Operations</strong> </p><p>Ransomware groups adopt new tactics including legitimate tool abuse and coordinated bluster campaigns.</p><ul><li><p>&#128274; Crazy ransomware gang abuses employee monitoring software and SimpleHelp remote tool to maintain persistence and evade detection before deploying ransomware. (Published on 11-Feb-2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/crazy-ransomware-gang-abuses-employee-monitoring-tool-in-attacks/">Read More</a></p></li><li><p>&#9889; 0APT ransomware group emerges with massive victim claims potentially being hoax, but demonstrates genuine technical capabilities and attack threats. (Published on 11-Feb-2026, CyberScoop). <a href="https://cyberscoop.com/0apt-ransomware-group-hoax-technical-capabilities/">Read More</a></p></li></ul><p><strong>AI &amp; Policy</strong> </p><p>Artificial intelligence security concerns and policy developments took center stage with marketplace safeguards and threat warnings.</p><ul><li><p>&#128737;&#65039; OpenClaw integrates VirusTotal malware scanning for ClawHub marketplace after security firms identify malicious extensions and unauthorized enterprise deployments. (Published on 9-Feb-2026, CSO Online). <a href="https://www.csoonline.com/article/4129393/openclaw-integrates-virustotal-malware-scanning-as-security-firms-flag-enterprise-risks.html">Read More</a></p></li><li><p>&#9976;&#65039; Czech ice dancers learn LLMs can produce plagiarism when their AI-generated Olympic music contains copyrighted content from original sources. (Published on 10-Feb-2026, TechCrunch). <a href="https://techcrunch.com/2026/02/10/olympics-czech-ice-dancers-duo-ai-music/">Read More</a></p></li><li><p>&#129302; Google warns hackers abuse Gemini AI across all attack stages, highlighting AI model extraction attacks where actors probe models to replicate logic. (Published on 12-Feb-2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/google-says-hackers-are-abusing-gemini-ai-for-all-attacks-stages/">Read More</a></p></li><li><p>&#128176; RentAHuman experiment reveals AI agents hiring humans for gig work to promote AI startups in meatspace, raising questions about AI labor dynamics. (Published on 13-Feb-2026, Ars Technica). <a href="https://www.wired.com/story/i-tried-rentahuman-ai-agents-hired-me-to-hype-their-ai-startups/">Read More</a></p></li><li><p>&#127757; Munich Security Conference reveals G7 countries rank cyber-attacks as top risk while BICS members place cyber threats eighth on priority list. (Published on 13-Feb-2026, Infosecurity). <a href="https://www.infosecurity-magazine.com/news/munich-security-index-cyberattacks/">Read More</a></p></li></ul><div><hr></div><p>Stay informed and secure in the tech and cybersecurity world. Have a great weekend, and remember to patch and protect your systems!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://thefwu.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Friday Wrap Up! Subscribe and never miss a weekly edition!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Friday Wrap Up: 6 February 2026]]></title><description><![CDATA[Another week, another supply chain nightmare.]]></description><link>https://thefwu.com/p/friday-wrap-up-6-february-2025</link><guid isPermaLink="false">https://thefwu.com/p/friday-wrap-up-6-february-2025</guid><dc:creator><![CDATA[Jorge Laurel]]></dc:creator><pubDate>Fri, 06 Feb 2026 20:02:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" width="550" height="320.8333333333333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:420,&quot;width&quot;:720,&quot;resizeWidth&quot;:550,&quot;bytes&quot;:204370,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Another week, another supply chain nightmare. &#127906;</p><p>This week&#8217;s cybersecurity roundup features everything from compromised software updates (yes, even Notepad++) to record-breaking DDoS attacks that would make your infrastructure cry. We&#8217;ve got nation-state actors playing Olympics spoiler, fintech firms losing millions of records, and AI agents getting their own social network (because apparently they need friends too).</p><p>Whether you&#8217;re defending against WinRAR exploits or wondering if your antivirus just became your biggest threat, this week had something for everyone.</p><p>Check out the full breakdown below &#8211; your threat intel fix is served. &#11015;&#65039;</p><p>#CyberBreaches #ThreatIntelligence #SupplyChainSecurity #FWU #fridaywrapup</p><div><hr></div><p>Espionage &amp; Data Extraction </p><p>Nation-state actors dominated headlines this week with sophisticated supply chain attacks and targeted espionage campaigns.</p><ul><li><p>&#127919; Chinese state hackers hijacked Notepad++&#8217;s update feature for months, compromising users through a trusted software channel. (Published on 2-Feb-2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/notepad-plus-plus-update-feature-hijacked-by-chinese-state-hackers-for-months/">Read More</a></p></li><li><p>&#128009; APT28 deployed espionage-focused malware exploiting Microsoft Office CVE-2026-21509 in targeted attacks against high-value systems. (Published on 3-Feb-2026, The Hacker News). <a href="https://thehackernews.com/2026/02/apt28-uses-microsoft-office-cve-2026.html">Read More</a></p></li><li><p>&#127935; Italy successfully thwarted Russian-linked cyberattacks targeting Winter Olympics websites, according to the Foreign Minister. (Published on 5-Feb-2026, SecurityWeek). <a href="https://www.securityweek.com/italy-averted-russian-linked-cyberattacks-targeting-winter-olympics-websites-foreign-minister-says/">Read More</a></p></li><li><p>&#128298; China-linked DKnife AitM framework targets routers for traffic hijacking and malware delivery through advanced man-in-the-middle techniques. (Published on 6-Feb-2026, The Hacker News). <a href="https://thehackernews.com/2026/02/china-linked-dknife-aitm-framework.html">Read More</a></p></li><li><p>&#128230; Amaranth-Dragon exploits WinRAR vulnerability in sophisticated espionage campaigns targeting sensitive organizational data. (Published on 4-Feb-2026, The Hacker News). <a href="https://thehackernews.com/2026/02/china-linked-amaranth-dragon-exploits.html">Read More</a></p></li></ul><p>Major Cyberattacks &amp; Incidents This week saw multiple high-profile breaches affecting millions of users across various sectors.</p><ul><li><p>&#128272; ShinyHunters-branded extortion activity expands dramatically with escalating threats against compromised organizations worldwide. (Published on 2-Feb-2026, SecurityWeek). <a href="https://www.securityweek.com/shinyhunters-branded-extortion-activity-expands-escalates/">Read More</a></p></li><li><p>&#129366; Hackers leaked 5.1 million Panera Bread customer records exposing personal information in a massive data breach. (Published on 3-Feb-2026, SecurityWeek). <a href="https://www.securityweek.com/hackers-leak-5-1-million-panera-bread-accounts/">Read More</a></p></li><li><p>&#128176; Fintech firm Betterment suffered a data breach exposing 1.4 million customer accounts and sensitive financial information. (Published on 5-Feb-2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/data-breach-at-fintech-firm-betterment-exposes-14-million-accounts/">Read More</a></p></li><li><p>&#128231; Newsletter platform Substack notified users of a data breach compromising subscriber information and account credentials. (Published on 5-Feb-2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/newsletter-platform-substack-notifies-users-of-data-breach/">Read More</a></p></li><li><p>&#9729;&#65039; Exposed AWS credentials enabled AI-assisted cloud breach in just 8 minutes, demonstrating automation&#8217;s threat potential. (Published on 4-Feb-2026, Hackread). <a href="https://hackread.com/8-minute-takeover-ai-hijack-cloud-access/">Read More</a></p></li></ul><p>Malware &amp; Vulnerabilities </p><p>Critical vulnerabilities and sophisticated malware strains continued to challenge security teams globally.</p><ul><li><p>&#128737;&#65039; eScan Antivirus update servers were compromised to deliver multi-stage malware to unsuspecting users trusting legitimate updates. (Published on 2-Feb-2026, The Hacker News). <a href="https://thehackernews.com/2026/02/escan-antivirus-update-servers.html">Read More</a></p></li><li><p>&#128172; Stealthy Windows RAT discovered holding live conversations with operators, enabling real-time command and control capabilities. (Published on 2-Feb-2026, CSO Online). <a href="https://www.csoonline.com/article/4125567/this-stealthy-windows-rat-holds-live-conversations-with-its-operators.html">Read More</a></p></li><li><p>&#9883;&#65039; Hackers exploited critical React Native Metro bug to breach developer systems through supply chain attacks. (Published on 3-Feb-2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/hackers-use-critical-react-native-metro-bug-to-breach-dev-systems/">Read More</a></p></li><li><p>&#129713; GlassWorm malware returns to shatter developer ecosystems with enhanced capabilities targeting software supply chains. (Published on 3-Feb-2026, Dark Reading). <a href="https://www.darkreading.com/application-security/glassworm-malware-developer-ecosystems">Read More</a></p></li><li><p>&#9888;&#65039; Critical n8n workflow automation flaws disclosed publicly along with working exploits posing immediate risk. (Published on 4-Feb-2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/critical-n8n-flaws-disclosed-along-with-public-exploits/">Read More</a></p></li><li><p>&#127822; macOS users targeted by Python infostealers disguised as legitimate AI installer packages stealing credentials and data. (Published on 5-Feb-2026, Hackread). <a href="https://hackread.com/macos-users-python-infostealers-posing-ai-installers/">Read More</a></p></li><li><p>&#9728;&#65039; Fresh SolarWinds vulnerability actively exploited in attacks targeting enterprise infrastructure and management systems. (Published on 4-Feb-2026, SecurityWeek). <a href="https://www.securityweek.com/fresh-solarwinds-vulnerability-exploited-in-attacks/">Read More</a></p></li><li><p>&#128230; New hacking campaign exploits Microsoft Windows WinRAR vulnerability in widespread attacks against Windows users. (Published on 5-Feb-2026, Infosecurity). <a href="https://www.infosecurity-magazine.com/news/hacking-exploits-windows-winrar/">Read More</a></p></li><li><p>&#127760; Chinese-made malware kit targets Chinese-based routers and edge devices in coordinated infrastructure attacks. (Published on 6-Feb-2026, Infosecurity). <a href="https://www.infosecurity-magazine.com/news/china-malware-kit-targets-routers/">Read More</a></p></li><li><p>&#129693; 17% of third-party OpenClaw add-ons used in cryptocurrency theft and macOS malware distribution campaigns. (Published on 6-Feb-2026, Hackread). <a href="https://hackread.com/openclaw-add-ons-crypto-theft-macos-malware/">Read More</a></p></li></ul><p>DDoS, Outages &amp; Infrastructure </p><p>Record-breaking attacks and persistent botnets tested infrastructure resilience worldwide.</p><ul><li><p>&#128165; AISURU/Kimwolf botnet launched record-setting 31.4 Tbps DDoS attack, breaking previous volumetric attack records. (Published on 5-Feb-2026, The Hacker News). <a href="https://thehackernews.com/2026/02/aisurukimwolf-botnet-launches-record.html">Read More</a></p></li><li><p>&#129302; Global SystemBC botnet discovered active across 10,000 infected systems facilitating proxy services and malware delivery. (Published on 4-Feb-2026, Infosecurity). <a href="https://www.infosecurity-magazine.com/news/global-systembc-botnet-10000/">Read More</a></p></li></ul><p>AI &amp; Policy </p><p>Regulatory developments and AI security research shaped policy discussions this week.</p><ul><li><p>&#128737;&#65039; NSA published new Zero Trust implementation guidelines providing comprehensive framework for secure architecture deployment. (Published on 2-Feb-2026, Infosecurity). <a href="https://www.infosecurity-magazine.com/news/nsa-zero-trust-implementation/">Read More</a></p></li><li><p>&#129302; Moltbook emerges as social platform where AI agents communicate while humans observe interactions passively. (Published on 3-Feb-2026, Hackread). <a href="https://hackread.com/moltbook-social-platform-ai-agents-talk-humans-watch/">Read More</a></p></li><li><p>&#128680; CISA orders federal agencies to replace end-of-life edge devices eliminating unpatched vulnerabilities from networks. (Published on 6-Feb-2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/cisa-orders-federal-agencies-to-replace-end-of-life-edge-devices/">Read More</a></p></li><li><p>&#128269; Claude AI discovered 500 high-severity software vulnerabilities demonstrating AI&#8217;s potential in vulnerability research. (Published on 6-Feb-2026, CSO Online). <a href="https://www.csoonline.com/article/4128889/claude-ai-finds-500-high-severity-software-vulnerabilities.html">Read More</a></p></li></ul><div><hr></div><p>Stay informed and secure in the tech and cybersecurity world. Have a great weekend, and remember to patch and protect your systems!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://thefwu.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Friday Wrap Up! Subscribe and never miss a weekly edition!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Friday Wrap Up: 30 January 2025]]></title><description><![CDATA[Another week, another avalanche of cyber chaos!]]></description><link>https://thefwu.com/p/friday-wrap-up-30-january-2025</link><guid isPermaLink="false">https://thefwu.com/p/friday-wrap-up-30-january-2025</guid><dc:creator><![CDATA[Jorge Laurel]]></dc:creator><pubDate>Fri, 30 Jan 2026 20:01:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" width="550" height="320.8333333333333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:420,&quot;width&quot;:720,&quot;resizeWidth&quot;:550,&quot;bytes&quot;:204370,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Another week, another avalanche of cyber chaos! From dating apps getting breached (swipe left on that security posture) to 1.5 million devs accidentally installing code-stealing VS Code extensions, it&#8217;s been a wild ride.</p><p>This week&#8217;s highlights: ShinyHunters went on a shopping spree, North Korean hackers are forming splinter groups like a K-pop band, and apparently 175,000 AI servers are just... out there... exposed. Also, half your employees are using shadow AI tools, and your C-suite is leading the charge.</p><p>Check out the full breakdown for all the gory details, zero-days, and infrastructure takedowns that made this week memorable (for all the wrong reasons).</p><p>#CyberThreats #InfoSecCommunity #ThreatIntelligence #Malware #DataBreach #Ransomware #FWU #fridaywrapup</p><div><hr></div><h3><strong>Major Cyberattacks &amp; Incidents</strong></h3><p>This week saw multiple high-profile breaches spanning dating apps to business intelligence platforms.</p><ul><li><p>&#128148; Dating apps Match, Hinge, and OkCupid, along with Panera Bread, were breached by ShinyHunters ransomware group, exposing millions of customer records with varying impact levels. (Published on 30-Jan-2026, Malwarebytes). <strong><a href="https://www.malwarebytes.com/blog/news/2026/01/match-hinge-okcupid-and-panera-bread-breached-by-ransomware-group">Read More</a></strong></p></li><li><p>&#128202; Crunchbase confirmed a data breach after ShinyHunters&#8217; hacking campaign targeted multiple platforms including SoundCloud and Betterment, compromising business intelligence data. (Published on 26-Jan-2026, SecurityWeek). <strong><a href="https://www.securityweek.com/crunchbase-confirms-data-breach-after-hacking-claims/">Read More</a></strong></p></li><li><p>&#127907; ShinyHunters expanded operations to target over 100 organizations using vishing tactics and fake login pages to bypass SSO security and steal corporate data. (Published on 27-Jan-2026, Hackread). <strong><a href="https://hackread.com/shinyhunters-target-firms-bypass-sso-security/">Read More</a></strong></p></li></ul><p><strong>Malware &amp; Vulnerabilities</strong></p><p>Attackers deployed sophisticated malware campaigns across multiple platforms, from developer tools to mobile apps.</p><ul><li><p>&#128187; Two malicious Visual Studio Code AI extensions with 1.5 million combined installs masqueraded as coding assistants while secretly exfiltrating developer source code to China-based servers. (Published on 26-Jan-2026, The Hacker News). <strong><a href="https://thehackernews.com/2026/01/malicious-vs-code-ai-extensions-with-15.html">Read More</a></strong></p></li><li><p>&#128433;&#65039; ClickFix attacks evolved using fake CAPTCHAs combined with signed Microsoft App-V scripts to distribute Amatera infostealer, avoiding common detection patterns through sophisticated execution methods. (Published on 27-Jan-2026, The Hacker News). <strong><a href="https://thehackernews.com/2026/01/clickfix-attacks-expand-using-fake.html">Read More</a></strong></p></li><li><p>&#127975; Federal authorities charged 31 additional suspects linked to ATM jackpotting operations allegedly orchestrated by Venezuelan gang Tren de Aragua using specialized malware. (Published on 27-Jan-2026, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/security/us-charges-31-more-suspects-linked-to-atm-malware-attacks/">Read More</a></strong></p></li><li><p>&#127822; Mac users face increased risk as malicious Google Ads direct searches for legitimate software to fake Mac Cleaner pages distributing malware. (Published on 29-Jan-2026, Hackread). <strong><a href="https://hackread.com/malicious-google-ads-mac-fake-mac-cleaner/">Read More</a></strong></p></li><li><p>&#128241; Arsink spyware spread across 143 countries by disguising itself as WhatsApp, YouTube, Instagram, and TikTok, targeting Android users in another widespread mobile malware campaign. (Published on 30-Jan-2026, Hackread). <strong><a href="https://hackread.com/arsink-spyware-whatsapp-youtube-instagram-tiktok/">Read More</a></strong></p></li><li><p>&#127760; Researchers discovered malicious Chrome extensions hijacking affiliate links, stealing data, and collecting OpenAI ChatGPT authentication tokens, including a fake Amazon Ads Blocker. (Published on 30-Jan-2026, The Hacker News). <strong><a href="https://thehackernews.com/2026/01/researchers-uncover-chrome-extensions.html">Read More</a></strong></p></li></ul><p><strong>Critical Vulnerabilities &amp; Zero-Days</strong></p><p>Critical security flaws and exploited vulnerabilities demand immediate attention from security teams.</p><ul><li><p>&#9888;&#65039; Ivanti disclosed two critical vulnerabilities in Endpoint Manager Mobile (CVE-2026-1281 and CVE-2026-1340) actively exploited in zero-day attacks against enterprise systems. (Published on 29-Jan-2026, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/security/ivanti-warns-of-two-epmm-flaws-exploited-in-zero-day-attacks/">Read More</a></strong></p></li><li><p>&#128225; Nearly 800,000 Telnet servers remain exposed to remote attacks as threat actors exploit a critical authentication bypass vulnerability in GNU InetUtils telnetd server. (Published on 26-Jan-2026, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/security/nearly-800-000-telnet-servers-exposed-to-remote-attacks/">Read More</a></strong></p></li><li><p>&#128275; Critical sandbox escape vulnerability in Grist-Core enables remote code execution via malicious formulas, highlighting risks in Pyodide-based security implementations. (Published on 27-Jan-2026, Infosecurity). <strong><a href="https://www.infosecurity-magazine.com/news/pyodide-sandbox-escape-rce-grist/">Read More</a></strong></p></li></ul><p><strong>Espionage &amp; Data Extraction</strong></p><p>State-sponsored threat actors continue evolving their tactics and operational structures.</p><ul><li><p>&#128009; Chinese espionage group Mustang Panda upgraded its CoolClient backdoor to steal browser login credentials and monitor clipboard activity in targeted surveillance operations. (Published on 27-Jan-2026, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/security/chinese-mustang-panda-hackers-deploy-infostealers-via-coolclient-backdoor/">Read More</a></strong></p></li><li><p>&#127472;&#127477; Long-running North Korean threat group with Lazarus lineage has split into three distinct operations focused on espionage and cryptocurrency theft, according to CrowdStrike research. (Published on 29-Jan-2026, CyberScoop). <strong><a href="https://cyberscoop.com/north-korea-labyrinth-chollima-splits-crowdstrike/">Read More</a></strong></p></li></ul><p><strong>Infrastructure &amp; Operations</strong></p><p>Google disrupted a massive malicious proxy network affecting millions of devices globally.</p><ul><li><p>&#128737;&#65039; Google disrupted IPIDEA proxy network, one of the largest residential proxy operations that enrolled devices through SDKs for mobile and desktop applications. (Published on 29-Jan-2026, SecurityWeek). <strong><a href="https://www.securityweek.com/google-disrupts-ipidea-proxy-network/">Read More</a></strong></p></li><li><p>&#127757; Google&#8217;s action removed millions of compromised devices from IPIDEA&#8217;s infrastructure, though not completely, highlighting ongoing challenges in dismantling cybercriminal proxy networks. (Published on 30-Jan-2026, CyberScoop). <strong><a href="https://cyberscoop.com/ipidea-proxy-network-disrupted-google-lumen/">Read More</a></strong></p></li></ul><p><strong>AI &amp; Policy</strong></p><p>AI security concerns expand as organizations grapple with exposed infrastructure and shadow AI adoption.</p><ul><li><p>&#129302; Investigation uncovered 175,000 publicly accessible Ollama AI servers across 130 countries operating outside managed infrastructure, creating massive unmanaged AI compute exposure. (Published on 29-Jan-2026, The Hacker News). <strong><a href="https://thehackernews.com/2026/01/researchers-find-175000-publicly.html">Read More</a></strong></p></li><li><p>&#128101; Nearly half of employees use unsanctioned AI tools, with 69% of executives prioritizing speed over security as shadow AI proliferates across enterprises. (Published on 30-Jan-2026, CSO Online). <strong><a href="https://www.csoonline.com/article/4124775/roughly-half-of-employees-are-using-unsanctioned-ai-tools-and-enterprise-leaders-are-major-culprits-2.html">Read More</a></strong></p></li></ul><p><strong>Cybersecurity Policy &amp; Industry</strong></p><p>Stakeholders collaborate on voluntary frameworks to address emerging security challenges.</p><ul><li><p>&#129309; Industry leaders, government agencies, and nonprofits held weekend discussions advancing voluntary rules for commercial hacking tools under the Pall Mall Process framework. (Published on 26-Jan-2026, CyberScoop). <strong><a href="https://cyberscoop.com/industry-government-nonprofits-weigh-voluntary-rules-for-commercial-hacking-tools/">Read More</a></strong></p></li></ul><p><strong>Social Engineering &amp; Phishing</strong></p><p>Attackers continue exploiting trusted platforms for credential theft.</p><ul><li><p>&#128231; Scammers abused Microsoft Teams invitations to send 12,866 fake billing notice emails reaching approximately 6,135 users in phone-based phishing campaign. (Published on 26-Jan-2026, Hackread). <strong><a href="https://hackread.com/fake-microsoft-teams-billing-phishing-alerts-emails/">Read More</a></strong></p></li></ul><div><hr></div><p>Stay informed and secure in the tech and cybersecurity world. Have a great weekend, and remember to patch and protect your systems!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://thefwu.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Friday Wrap Up! Subscribe and never miss a weekly edition!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Friday Wrap Up: 23 January 2025]]></title><description><![CDATA[Another week, another mountain of security incidents to digest.]]></description><link>https://thefwu.com/p/friday-wrap-up-23-january-2025</link><guid isPermaLink="false">https://thefwu.com/p/friday-wrap-up-23-january-2025</guid><dc:creator><![CDATA[Jorge Laurel]]></dc:creator><pubDate>Fri, 23 Jan 2026 20:00:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" width="550" height="320.8333333333333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:420,&quot;width&quot;:720,&quot;resizeWidth&quot;:550,&quot;bytes&quot;:204370,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Another week, another mountain of security incidents to digest. From Fortinet&#8217;s double-feature vulnerability showcase to AI systems getting tricked into leaking your calendar (thanks, Gemini!), the headlines remind us that &#8220;fully patched&#8221; is more of a suggestion than a guarantee.</p><p>Highlights? Tesla got pwned for half a million dollars, Microsoft blamed a &#8220;coding error&#8221; for Outlook crashes (aren&#8217;t they all?), and Curl is officially done with AI-generated bug bounty spam. Somewhere, a developer shed a single tear.</p><p>The real MVP: Mandiant basically saying &#8220;if you&#8217;re still using NTLMv1, here&#8217;s how to crack it&#8212;maybe that&#8217;ll motivate you.&#8221;</p><p>Read the full Friday Wrap Up below for categorized summaries, zero-day drama, and why your firewall configs might already be someone else&#8217;s weekend reading.</p><p>#FWU #fridaywrapup #CyberSecurity #InfoSec #ZeroDay #ThreatIntel #AIGoneWild</p><div><hr></div><p>Major Cyberattacks &amp; Incidents </p><p>This week saw significant breaches spanning IT giants, automotive systems, and retail sectors.</p><ul><li><p>&#128680; Ingram Micro disclosed that a July 2025 ransomware attack exposed data of 42,000 current and former employees, including SSNs and birth dates. (Published on 19-Jan-2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/ingram-micro-says-ransomware-attack-affected-42-000-people/">Read More</a></p></li><li><p>&#9888;&#65039; RansomHouse claims data breach at Apple contractor Luxshare, though no evidence has been released and links remain offline. (Published on 20-Jan-2026, Hackread). <a href="https://hackread.com/ransomhouse-data-breach-apple-contractor-luxshare/">Read More</a></p></li><li><p>&#127942; Security researchers hacked Tesla&#8217;s Infotainment System and earned $516,500 exploiting 37 zero-days on day one of Pwn2Own Automotive 2026. (Published on 21-Jan-2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/tesla-hacked-37-zero-days-demoed-at-pwn2own-automotive-2026/">Read More</a></p></li><li><p>&#127907; Milano-Cortina 2026 Winter Olympics faces cyber threats with phishing and spoofed websites identified as primary attack vectors. (Published on 21-Jan-2026, Infosecurity). <a href="https://www.infosecurity-magazine.com/news/phishing-spoofed-sites-olympic/">Read More</a></p></li><li><p>&#128273; LastPass users targeted by backup-themed phishing emails, likely timed to exploit US holiday weekend for increased success rates. (Published on 21-Jan-2026, SecurityWeek). <a href="https://www.securityweek.com/lastpass-users-targeted-with-backup-themed-phishing-emails/">Read More</a></p></li><li><p>&#128293; Automated attacks targeting Fortinet FortiGate devices create rogue accounts and steal firewall configuration data, according to Arctic Wolf. (Published on 22-Jan-2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/hackers-breach-fortinet-fortigate-devices-steal-firewall-configs/">Read More</a></p></li><li><p>&#128085; Under Armour investigating data breach affecting customers&#8217; email addresses and other personal information, incident details still emerging. (Published on 23-Jan-2026, SecurityWeek). <a href="https://www.securityweek.com/under-armour-looking-into-data-breach-affecting-customers-email-addresses/">Read More</a></p></li><li><p>&#226;&#353;&#8211;&#239;&#184; Russian national Ianis Antropenko pleaded guilty to leading ransomware crew in four-year crime spree affecting 50+ victims, faces 25 years. (Published on 22-Jan-2026, CyberScoop). <a href="https://cyberscoop.com/ianis-antropenko-russian-ransomware-leader-guilty/">Read More</a></p></li></ul><p>Malware &amp; Vulnerabilities Critical flaws and sophisticated malware dominated security disclosures this week.</p><ul><li><p>&#128373;&#65039; XSS vulnerability in StealC malware control panel allowed researchers to monitor threat actor operations and collect system fingerprints. (Published on 19-Jan-2026, The Hacker News). <a href="https://thehackernews.com/2026/01/security-bug-in-stealc-malware-panel.html">Read More</a></p></li><li><p>&#128247; TP-Link patched vulnerability in VIGI cameras allowing remote hacking, with over 2,500 internet-exposed devices discovered by researchers. (Published on 19-Jan-2026, SecurityWeek). <a href="https://www.securityweek.com/tp-link-patches-vulnerability-exposing-vigi-cameras-to-hacking/">Read More</a></p></li><li><p>&#128196; PDFSIDER malware discovered using advanced anti-VM checks and hidden techniques for long-term covert system access. (Published on 19-Jan-2026, Infosecurity). <a href="https://www.infosecurity-magazine.com/news/pdfsider-anti-vm-checks-hidden/">Read More</a></p></li><li><p>&#128295; Three security vulnerabilities disclosed in Anthropic&#8217;s MCP Git server enable arbitrary file access and code execution via prompt injection. (Published on 20-Jan-2026, The Hacker News). <a href="https://thehackernews.com/2026/01/three-flaws-in-anthropic-mcp-git-server.html">Read More</a></p></li><li><p>&#9729;&#65039; Cloudflare fixed ACME validation bug allowing attackers to bypass WAF controls and directly access origin servers. (Published on 20-Jan-2026, The Hacker News). <a href="https://thehackernews.com/2026/01/cloudflare-fixes-acme-validation-bug.html">Read More</a></p></li><li><p>&#129302; VoidLink Linux malware framework, built with AI assistance by single developer, reached 88,000 lines of sophisticated code. (Published on 21-Jan-2026, The Hacker News). <a href="https://thehackernews.com/2026/01/voidlink-linux-malware-framework-built.html">Read More</a></p></li><li><p>&#128272; GitLab patched high-severity 2FA bypass vulnerability affecting both community and enterprise editions of its development platform. (Published on 21-Jan-2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/gitlab-warns-of-high-severity-2fa-bypass-denial-of-service-flaws/">Read More</a></p></li><li><p>&#9889; Cisco released critical patches for zero-day CVE-2026-20045 actively exploited in Unified CM and Webex Calling Dedicated Instance. (Published on 22-Jan-2026, The Hacker News). <a href="https://thehackernews.com/2026/01/cisco-fixes-actively-exploited-zero-day.html">Read More</a></p></li><li><p>&#127969; RealHomes CRM plugin vulnerability affected 30,000+ WordPress sites by allowing malicious file uploads; patches now released. (Published on 22-Jan-2026, Infosecurity). <a href="https://www.infosecurity-magazine.com/news/realhomes-crm-plugin-flaw/">Read More</a></p></li><li><p>&#128737;&#65039; Fortinet confirms active FortiCloud SSO bypass exploitation on fully-patched FortiGate firewalls, working on complete fix. (Published on 23-Jan-2026, The Hacker News). <a href="https://thehackernews.com/2026/01/fortinet-confirms-active-forticloud-sso.html">Read More</a></p></li></ul><p>Cybersecurity Tools &amp; Techniques Google&#8217;s Mandiant took an unconventional approach to forcing security upgrades.</p><ul><li><p>&#127752; Mandiant released NTLMv1 rainbow table lookup to demonstrate protocol&#8217;s insecurity, enabling credential recovery in 12 hours on $600 hardware. (Published on 19-Jan-2026, CSO Online). <a href="https://www.csoonline.com/article/4118800/mandiant-pushes-organizations-to-dump-insecure-ntlmv1-by-releasing-a-way-to-crack-it.html">Read More</a></p></li></ul><p>Vulnerability Research &amp; Industry Analysis Researchers showcased both offensive capabilities and defensive innovations.</p><ul><li><p>&#128176; Pwn2Own Automotive 2026 concluded with researchers earning $1,047,000 for exploiting 76 zero-day vulnerabilities across three days. (Published on 23-Jan-2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/hackers-get-1-047-000-for-76-zero-days-at-pwn2own-automotive-2026/">Read More</a></p></li><li><p>&#9881;&#65039; Austrian researchers optimized Linux page cache attacks, reviving old exploit techniques with dramatically improved speed and efficiency. (Published on 22-Jan-2026, SecurityWeek). <a href="https://www.securityweek.com/old-attack-new-speed-researchers-optimize-page-cache-exploits/">Read More</a></p></li></ul><p>AI &amp; Policy Artificial intelligence created both security challenges and operational headaches this week.</p><ul><li><p>&#129302; Google Gemini bypassed via natural language prompt injection, allowing attackers to create misleading Calendar events and leak private data. (Published on 20-Jan-2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/gemini-ai-assistant-tricked-into-leaking-google-calendar-data/">Read More</a></p></li><li><p>&#127466;&#127482; EU proposes mandatory 5G cybersecurity measures targeting high-risk telecom suppliers, widely seen as aimed at Chinese vendors. (Published on 20-Jan-2026, SecurityWeek). <a href="https://www.securityweek.com/eu-plans-phase-out-of-high-risk-telecom-suppliers-in-proposals-seen-as-targeting-china/">Read More</a></p></li><li><p>&#128683; Curl developer ending HackerOne bug bounty program after overwhelming flood of low-quality AI-generated vulnerability reports. (Published on 22-Jan-2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/curl-ending-bug-bounty-program-after-flood-of-ai-slop-reports/">Read More</a></p></li></ul><p>DDoS, Outages &amp; Infrastructure Microsoft acknowledged a stability issue affecting mobile users.</p><ul><li><p>&#128241; Microsoft confirmed Outlook for iOS crashes and freezes on iPad devices due to coding error, fix in progress. (Published on 23-Jan-2026, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-outlook-for-ios-crashes-freezes-due-to-coding-error/">Read More</a></p></li></ul><div><hr></div><p>Stay informed and secure in the tech and cybersecurity world. Have a great weekend, and remember to patch and protect your systems!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://thefwu.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Friday Wrap Up! Subscribe and never miss a weekly edition!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Friday Wrap Up: 16 January 2025]]></title><description><![CDATA[&#127906; This week&#8217;s cybersecurity rollercoaster: where Wi-Fi crashes with one packet, Chrome extensions cosplay as your HR portal, and ZIP files contain more layers than a lasagna made by someone with commitment issues.]]></description><link>https://thefwu.com/p/friday-wrap-up-16-january-2025</link><guid isPermaLink="false">https://thefwu.com/p/friday-wrap-up-16-january-2025</guid><dc:creator><![CDATA[Jorge Laurel]]></dc:creator><pubDate>Fri, 16 Jan 2026 20:02:06 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" width="550" height="320.8333333333333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:420,&quot;width&quot;:720,&quot;resizeWidth&quot;:550,&quot;bytes&quot;:204370,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>&#127906; This week&#8217;s cybersecurity rollercoaster: where Wi-Fi crashes with one packet, Chrome extensions cosplay as your HR portal, and ZIP files contain more layers than a lasagna made by someone with commitment issues.</p><p>The big picture? Attackers are getting sophisticated (looking at you, Predator spyware that learns from failure), infrastructure is falling over (RIP Verizon, enjoy your $20), and apparently two missing characters almost took down AWS. Two. Characters.</p><p>Meanwhile, cybercrime groups are running tighter operations than most Fortune 500 companies, complete with KPIs and customer support. The irony is painful.</p><p>Check out the full wrap-up for all the gory details on this week&#8217;s digital chaos. </p><p>#CyberSecurity #ThreatIntelligence #InfoSec #Malware #Ransomware #DataBreach #FWU #fridaywrapup</p><div><hr></div><h3><strong>Malware &amp; Vulnerabilities</strong></h3><p>This week&#8217;s vulnerability buffet features everything from Chrome extensions masquerading as HR tools to Wi-Fi bugs that can knock your network offline with a single packet.</p><ul><li><p>&#127917; Fake n8n workflow packages on npm tricked developers into revealing OAuth credentials by posing as legitimate Google Ads integrations. (Published on 12-Jan-2026, The Hacker News). <strong><a href="https://thehackernews.com/2026/01/n8n-supply-chain-attack-abuses.html">Read More</a></strong></p></li></ul><ul><li><p>&#128248; Instagram patched a password reset flaw that let third parties spam users with reset emails and potentially leak user data. (Published on 12-Jan-2026, SecurityWeek). <strong><a href="https://www.securityweek.com/instagram-fixes-password-reset-vulnerability-amid-user-data-leak/">Read More</a></strong></p></li></ul><ul><li><p>&#128039; VoidLink malware framework discovered targeting Linux cloud servers with custom loaders, rootkits, and plugins designed for modern cloud environments. (Published on 13-Jan-2026, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/security/new-voidlink-malware-framework-targets-linux-cloud-servers/">Read More</a></strong></p></li></ul><ul><li><p>&#128225; Broadcom Wi-Fi chipset flaw allows attackers to crash 5GHz networks with one malicious frame, requiring manual router reboots to restore connectivity. (Published on 13-Jan-2026, CSO Online). <strong><a href="https://www.csoonline.com/article/4116064/high-severity-bug-in-broadcom-software-enables-easy-wifi-denial-of-service.html">Read More</a></strong></p></li></ul><ul><li><p>&#129302; ServiceNow patched critical AI Platform vulnerability (CVE-2025-12420) that allowed unauthenticated attackers to impersonate users and perform arbitrary actions. (Published on 13-Jan-2026, The Hacker News). <strong><a href="https://thehackernews.com/2026/01/servicenow-patches-critical-ai-platform.html">Read More</a></strong></p></li></ul><ul><li><p>&#129695; Microsoft&#8217;s January Patch Tuesday addressed 112 vulnerabilities, including one actively exploited Windows zero-day disclosed publicly before patches were available. (Published on 13-Jan-2026, SecurityWeek). <strong><a href="https://www.securityweek.com/microsoft-patches-exploited-windows-zero-day-111-other-vulnerabilities/">Read More</a></strong></p></li></ul><ul><li><p>&#127907; Browser-in-the-browser phishing attacks surge, tricking Facebook users into surrendering login credentials through convincing fake authentication windows. (Published on 13-Jan-2026, Infosecurity). <strong><a href="https://www.infosecurity-magazine.com/news/phishing-scams-exploit-browser/">Read More</a></strong></p></li></ul><ul><li><p>&#128176; Fake PayPal payment notices deployed remote monitoring tools to steal credentials and maintain persistent access to victim systems. (Published on 14-Jan-2026, Infosecurity). <strong><a href="https://www.infosecurity-magazine.com/news/hackers-fake-paypal-notices-deploy/">Read More</a></strong></p></li></ul><ul><li><p>&#128293; Palo Alto Networks patched high-severity DoS vulnerability letting unauthenticated attackers disable firewall protections remotely. (Published on 15-Jan-2026, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/security/palo-alto-networks-warns-of-dos-bug-letting-hackers-disable-firewalls/">Read More</a></strong></p></li></ul><ul><li><p>&#129302; Microsoft Copilot vulnerability allowed &#8220;Reprompt&#8221; attack to silently exfiltrate session data even after chat windows were closed. (Published on 15-Jan-2026, SecurityWeek). <strong><a href="https://www.securityweek.com/new-reprompt-attack-silently-siphons-microsoft-copilot-data/">Read More</a></strong></p></li></ul><ul><li><p>&#9729;&#65039; AWS CodeBuild misconfiguration exposed core repositories to potential supply chain attacks affecting the entire AWS Console. (Published on 15-Jan-2026, Infosecurity). <strong><a href="https://www.infosecurity-magazine.com/news/codebuild-flaw-aws-console-risk/">Read More</a></strong></p></li></ul><ul><li><p>&#128231; Cisco patched maximum-severity AsyncOS zero-day exploited in attacks targeting Secure Email Gateway appliances since November 2025. (Published on 16-Jan-2026, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/security/cisco-finally-fixes-asyncos-zero-day-exploited-since-november/">Read More</a></strong></p></li></ul><ul><li><p>&#127760; Five malicious Chrome extensions impersonated Workday, NetSuite, and SuccessFactors to steal authentication tokens and hijack enterprise accounts. (Published on 16-Jan-2026, The Hacker News). <strong><a href="https://thehackernews.com/2026/01/five-malicious-chrome-extensions.html">Read More</a></strong></p></li></ul><ul><li><p>&#128230; GootLoader malware now concatenates 500-1,000 ZIP archives to create malformed files that evade detection by most unarchiving tools. (Published on 16-Jan-2026, The Hacker News). <strong><a href="https://thehackernews.com/2026/01/gootloader-malware-uses-5001000.html">Read More</a></strong></p></li></ul><p><strong>Major Cyberattacks &amp; Incidents</strong></p><p>Canadian financial regulators join the breach club with three-quarters of a million records exposed.</p><ul><li><p>&#127464;&#127462; Canadian Investment Regulatory Organization suffered data breach impacting personal information of 750,000 member firms and registered employees. (Published on 16-Jan-2026, SecurityWeek). <strong><a href="https://www.securityweek.com/750000-impacted-by-data-breach-at-canadian-investment-watchdog/">Read More</a></strong></p></li></ul><p><strong>Espionage &amp; Data Extraction</strong> A</p><p>dvanced spyware learns from its failures, turning unsuccessful attacks into reconnaissance for future exploits.</p><ul><li><p>&#128373;&#65039; Predator spyware revealed to possess sophisticated anti-analysis features, converting failed attack attempts into intelligence for future zero-day exploits. (Published on 14-Jan-2026, SecurityWeek). <strong><a href="https://www.securityweek.com/predator-spywares-granular-anti-analysis-features-exposed/">Read More</a></strong></p></li></ul><p><strong>Cybersecurity Tools &amp; Techniques</strong></p><p>This week defenders fought back, null-routing botnets and dismantling cybercrime infrastructure through coordinated legal action.</p><ul><li><p>&#129302; Black Lotus Labs null-routed over 550 command-and-control nodes for AISURU/Kimwolf botnet since October, disrupting massive DDoS infrastructure. (Published on 14-Jan-2026, The Hacker News). <strong><a href="https://thehackernews.com/2026/01/kimwolf-botnet-infected-over-2-million.html">Read More</a></strong></p></li></ul><ul><li><p>&#9878;&#65039; Microsoft&#8217;s coordinated legal action in US and UK disrupted RedVDS cybercrime subscription service linked to millions in fraud losses. (Published on 15-Jan-2026, The Hacker News). <strong><a href="https://thehackernews.com/2026/01/microsoft-legal-action-disrupts-redvds.html">Read More</a></strong></p></li></ul><p><strong>DDoS, Outages &amp; Infrastructure</strong></p><p>Verizon&#8217;s nationwide outage left millions phoneless, but at least they&#8217;re getting $20 credits for their trouble.</p><ul><li><p>&#128241; Verizon Wireless suffered massive nationwide outage leaving customers in SOS mode without cellular service across the US. (Published on 14-Jan-2026, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/mobile/verizon-wireless-outage-puts-phones-in-sos-mode-without-cell-service/">Read More</a></strong></p></li></ul><ul><li><p>&#128181; Verizon began issuing $20 account credits via text message following last week&#8217;s nationwide wireless outage. (Published on 16-Jan-2026, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/mobile/verizon-starts-issuing-20-credits-after-nationwide-outage/">Read More</a></strong></p></li></ul><p><strong>Vulnerability Research &amp; Industry Analysis</strong></p><p>Deep dives into how cybercrime has become more organized than most IT departments, and why npm has become ground zero for supply chain attacks.</p><ul><li><p>&#127970; Cybercrime groups now operate with corporate-level structure, offering ransomware-as-a-service with support forums, KPIs, and profit-sharing models. (Published on 14-Jan-2026, CSO Online). <strong><a href="https://www.csoonline.com/article/4116508/cybercrime-inc-when-hackers-are-better-organized-than-it.html">Read More</a></strong></p></li></ul><ul><li><p>&#128230; npm supply chain attacks evolved from simple typosquatting to coordinated credential theft campaigns targeting maintainers and CI/CD pipelines. (Published on 15-Jan-2026, CSO Online). <strong><a href="https://www.csoonline.com/article/4117139/from-typos-to-takeovers-inside-the-industrialization-of-npm-supply-chain-attacks.html">Read More</a></strong></p></li></ul><ul><li><p>&#9729;&#65039; Two missing characters in AWS CodeBuild configuration nearly compromised entire AWS Console in critical supply chain vulnerability. (Published on 16-Jan-2026, Hackread). <strong><a href="https://hackread.com/how-2-missing-chars-compromised-aws/">Read More</a></strong></p></li></ul><p><strong>AI &amp; Policy</strong></p><p>Tech giants team up while regulators crack down on deepfakes and data brokers.</p><ul><li><p>&#129309; Apple confirmed multi-year partnership with Google to power next-generation Siri using Gemini AI and Google Cloud infrastructure. (Published on 12-Jan-2026, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/apple/apple-confirms-google-gemini-will-power-siri-says-privacy-remains-a-priority/">Read More</a></strong></p></li></ul><ul><li><p>&#127973; California CPPA cracked down on unregistered data brokers illegally trading personal health data without proper authorization. (Published on 12-Jan-2026, Infosecurity). <strong><a href="https://www.infosecurity-magazine.com/news/california-shuts-health-data/">Read More</a></strong></p></li></ul><ul><li><p>&#127468;&#127463; UK regulator Ofcom launched investigation into X (formerly Twitter) for allegedly facilitating nonconsensual deepfake pornography of adults and children. (Published on 12-Jan-2026, CyberScoop). <strong><a href="https://cyberscoop.com/ofcom-opens-investigation-into-x-over-nonconsensual-deepfakes/">Read More</a></strong></p></li></ul><div><hr></div><p>Stay informed and secure in the tech and cybersecurity world. Have a great weekend, and remember to patch and protect your systems!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://thefwu.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Friday Wrap Up! Subscribe and never miss a weekly edition!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Friday Wrap Up: 9 January 2026]]></title><description><![CDATA[Another week, another wave of vulnerabilities keeping us on our toes!]]></description><link>https://thefwu.com/p/friday-wrap-up-9-january-2026</link><guid isPermaLink="false">https://thefwu.com/p/friday-wrap-up-9-january-2026</guid><dc:creator><![CDATA[Jorge Laurel]]></dc:creator><pubDate>Fri, 09 Jan 2026 20:01:46 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" width="550" height="320.8333333333333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:420,&quot;width&quot;:720,&quot;resizeWidth&quot;:550,&quot;bytes&quot;:204370,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Another week, another wave of vulnerabilities keeping us on our toes!</p><p>From nation-state hackers conducting global credential harvesting campaigns to fake AI Chrome extensions stealing nearly a million users&#8217; data, this week proved cybersecurity professionals earn every bit of their coffee budget. Critical n8n vulnerabilities reached CVSS scores that made even hardened defenders nervous, while Chinese Salt Typhoon intrusions keep expanding in scope. Meanwhile, Disney learned that YouTube privacy violations cost $10M&#8212;turns out COPPA compliance isn&#8217;t optional.</p><p>The hospitality sector got hammered by sophisticated ClickFix campaigns, Android botnets grew to 2 million devices, and WhatsApp became an unlikely malware distribution vector in Brazil. On the defensive side, researchers turned the tables with a honeypot that successfully snared Scattered Lapsus$ operators, proving that sometimes the best defense is a really convincing fake dataset.</p><p>Patch your systems, enable that MFA, and maybe check if those Chrome extensions are actually legitimate. Your Friday reminder that threat actors never take the weekend off&#8212;so neither should your security posture.</p><p>#ThreatIntelligence #InfoSec #CyberSecurity #Malware #DataBreach #Ransomware #FWU #FridayWrapUp</p><div><hr></div><h3><strong>Major Cyberattacks &amp; Incidents</strong></h3><p>This week&#8217;s breach landscape spans VPN services, hospitality targets, and gas station operations.</p><ul><li><p>&#128737;&#65039; NordVPN denied breach allegations after attackers claimed access to internal Salesforce servers, stating cybercriminals obtained dummy data from a third-party testing platform trial account. (Published on 5-Jan-2026, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/security/nordvpn-denies-breach-claims-says-attackers-have-dummy-data/">Read More</a></strong></p></li><li><p>&#127919; Sophisticated ClickFix campaign targets hospitality sector with fake <strong><a href="http://booking.com/">Booking.com</a></strong> reservation cancellations and fake BSODs, tricking victims into executing malicious code that delivers RAT infections. (Published on 6-Jan-2026, SecurityWeek). <strong><a href="https://www.securityweek.com/sophisticated-clickfix-campaign-targeting-hospitality-sector/">Read More</a></strong></p></li><li><p>&#127976; Multi-stage PHALT#BLYX ClickFix malware campaign hits hospitality organizations using social engineering tactics and MSBuild.exe abuse to compromise systems and deploy remote access trojans. (Published on 6-Jan-2026, Infosecurity). <strong><a href="https://www.infosecurity-magazine.com/news/phaltblyx-clickfix-malware/">Read More</a></strong></p></li><li><p>&#128272; ownCloud urgently recommends enabling multi-factor authentication after receiving reports of credential theft, warning users that compromised credentials could enable unauthorized data access by attackers. (Published on 7-Jan-2026, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/security/owncloud-urges-users-to-enable-mfa-after-credential-theft-reports/">Read More</a></strong></p></li><li><p>&#226;&#8250;&#189; Texas-based Gulshan Management Services, operating Handi Plus and Handi Stop gas stations, disclosed a ransomware-triggered data breach impacting over 377,000 individuals&#8217; personal information. (Published on 7-Jan-2026, Hackread). <strong><a href="https://hackread.com/data-breach-us-gas-stations-company/">Read More</a></strong></p></li><li><p>&#226;&#8250;&#189; Gulshan Management Services reported a ransomware attack led to data breach affecting 377,000 people associated with their Texas gas station operations across 150 locations. (Published on 9-Jan-2026, SecurityWeek). <strong><a href="https://www.securityweek.com/377000-impacted-by-data-breach-at-texas-gas-station-firm/">Read More</a></strong></p></li></ul><p><strong>Malware &amp; Vulnerabilities</strong></p><p>Critical flaws and emerging threats dominated patching priorities this week.</p><ul><li><p>&#128013; VVS Stealer, a Python-based information stealer sold on Telegram since April 2025, harvests Discord credentials and tokens using Pyarmor-obfuscated code to evade detection. (Published on 5-Jan-2026, The Hacker News). <strong><a href="https://thehackernews.com/2026/01/new-vvs-stealer-malware-targets-discord.html">Read More</a></strong></p></li><li><p>&#128241; Kimwolf Android botnet grows to 2 million compromised devices, monetizing through DDoS attacks, fraudulent app installations, and selling proxy bandwidth via residential proxy networks. (Published on 5-Jan-2026, SecurityWeek). <strong><a href="https://www.securityweek.com/kimwolf-android-botnet-grows-through-residential-proxy-networks/">Read More</a></strong></p></li><li><p>&#127760; RondoDox botnet expands operations by exploiting React2Shell vulnerability, targeting Next.js servers with cryptomining payloads, botnet infections, and other malicious activity threatening IoT and enterprises. (Published on 5-Jan-2026, Dark Reading). <strong><a href="https://www.darkreading.com/vulnerabilities-threats/rondodox-botnet-scope-react2shell-exploitation">Read More</a></strong></p></li><li><p>&#129302; High-severity flaw in Open WebUI Direct Connections (used for AI integrations) creates risk for account takeover and server compromises requiring immediate attention. (Published on 6-Jan-2026, Infosecurity). <strong><a href="https://www.infosecurity-magazine.com/news/flaw-open-webui-affects-ai/">Read More</a></strong></p></li><li><p>&#9888;&#65039; Critical n8n vulnerability (CVE-2025-68668, CVSS 9.9) enables authenticated attackers to execute arbitrary system commands on the underlying host in the workflow automation platform. (Published on 6-Jan-2026, The Hacker News). <strong><a href="https://thehackernews.com/2026/01/new-n8n-vulnerability-99-cvss-lets.html">Read More</a></strong></p></li><li><p>&#127760; Legacy D-Link DSL gateway routers face active exploitation of newly discovered command injection vulnerability, affecting multiple out-of-support models with no patches available. (Published on 6-Jan-2026, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/security/new-d-link-flaw-in-legacy-dsl-routers-actively-exploited-in-attacks/">Read More</a></strong></p></li><li><p>&#128190; Veeam patched critical remote code execution vulnerability allowing operator-level users to execute commands with database administrator privileges in Backup &amp; Replication software. (Published on 7-Jan-2026, CyberScoop). <strong><a href="https://cyberscoop.com/veeam-backup-replication-security-flaw-remote-code-execution-fix/">Read More</a></strong></p></li><li><p>&#128268; Malicious Chrome extensions with 900,000 combined downloads caught impersonating legitimate AITOPIA extension, exfiltrating users&#8217; AI chat conversations and browser activity to attacker infrastructure. (Published on 7-Jan-2026, SecurityWeek). <strong><a href="https://www.securityweek.com/chrome-extensions-with-900000-downloads-caught-stealing-ai-chats/">Read More</a></strong></p></li><li><p>&#128179; Ghost Tap Android malware enables remote NFC payment fraud, allowing unauthorized tap-to-pay transactions without physical access to victims&#8217; bank cards or devices. (Published on 7-Jan-2026, Infosecurity). <strong><a href="https://www.infosecurity-magazine.com/news/ghost-tap-malware-remote-nfc-fraud/">Read More</a></strong></p></li><li><p>&#128172; WhatsApp worm spreads Astaroth banking trojan across Brazil by retrieving victims&#8217; contact lists and automatically sending malicious messages to propagate the Windows malware. (Published on 8-Jan-2026, The Hacker News). <strong><a href="https://thehackernews.com/2026/01/whatsapp-worm-spreads-astaroth-banking.html">Read More</a></strong></p></li><li><p>&#128680; CISA added Microsoft Office (CVE-2009-0556) and HPE OneView vulnerabilities to Known Exploited Vulnerabilities catalog after detecting active exploitation in the wild. (Published on 8-Jan-2026, The Hacker News). <strong><a href="https://thehackernews.com/2026/01/cisa-flags-microsoft-office-and-hpe.html">Read More</a></strong></p></li><li><p>&#9888;&#65039; Second critical n8n vulnerability (CVE-2026-21877, CVSS 10.0) discovered by Upwind enables full system takeover, requiring immediate update to version 1.121.3 to prevent exploitation. (Published on 8-Jan-2026, Hackread). <strong><a href="https://hackread.com/n8n-users-patch-full-system-takeover-vulnerability/">Read More</a></strong></p></li><li><p>&#127760; Fake AI-powered Chrome extensions mimicked legitimate tools to steal 900K users&#8217; ChatGPT and DeepSeek data before sending harvested information to command-and-control servers. (Published on 8-Jan-2026, Dark Reading). <strong><a href="https://www.darkreading.com/cloud-security/fake-ai-chrome-extensions-steal-900k-users-data">Read More</a></strong></p></li><li><p>&#129302; GoBruteforcer botnet actively targets exposed Linux servers, conducting brute-force attacks against FTP, MySQL, and other services to compromise systems and expand operations. (Published on 8-Jan-2026, Infosecurity). <strong><a href="https://www.infosecurity-magazine.com/news/gobruteforcer-botnet-linux-servers/">Read More</a></strong></p></li><li><p>&#240;&#376;&#8250;&#161;&#239;&#184; Trend Micro patched critical remote code execution vulnerability in Apex Central on-premise console, allowing attackers to execute arbitrary code with SYSTEM-level privileges. (Published on 9-Jan-2026, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/security/trend-micro-fixes-critical-rce-flaw-in-apex-central-console/">Read More</a></strong></p></li><li><p>&#128295; Cisco ISE vulnerability (CVE-2026-20029, CVSS 4.9) enables authenticated administrators to exploit improper XML parsing in licensing features, gaining unauthorized read access to sensitive files. (Published on 9-Jan-2026, CSO Online). <strong><a href="https://www.networkworld.com/article/4114677/cisco-identifies-vulnerability-in-ise-network-access-control-devices.html">Read More</a></strong></p></li></ul><p><strong>AI &amp; Policy</strong></p><p>Regulatory actions and AI security concerns continue shaping the landscape.</p><ul><li><p>&#127916; Disney settles with DOJ and FTC for $10 million over YouTube privacy violations under COPPA, implementing new measures to protect children&#8217;s data collection practices. (Published on 5-Jan-2026, Hackread). <strong><a href="https://hackread.com/disney-fine-violating-children-privacy-laws-youtube/">Read More</a></strong></p></li><li><p>&#129302; Employees using personal LLM accounts for work tasks create shadow AI risks, with lack of governance and visibility resulting in increased data security exposures. (Published on 7-Jan-2026, Infosecurity). <strong><a href="https://www.infosecurity-magazine.com/news/personal-llm-accounts-drive-shadow/">Read More</a></strong></p></li><li><p>&#240;&#376;&#8221;&#167; Gmail launches AI Inbox powered by Gemini to summarize emails, with Google explicitly stating it will not train AI models on user email content. (Published on 8-Jan-2026, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/google/gmails-new-ai-inbox-uses-gemini-but-google-says-it-wont-train-ai-on-user-emails/">Read More</a></strong></p></li><li><p>&#129503; Radware researchers demonstrated ZombieAgent attack, successfully bypassing ChatGPT protections to exfiltrate user data and implant persistent logic into the agent&#8217;s long-term memory. (Published on 9-Jan-2026, SecurityWeek). <strong><a href="https://www.securityweek.com/zombieagent-attack-let-researchers-take-over-chatgpt/">Read More</a></strong></p></li></ul><p><strong>Espionage &amp; Data Extraction</strong></p><p>Nation-state actors remain persistently active across global targets.</p><ul><li><p>&#127919; Russian APT28 (BlueDelta) conducted credential harvesting campaign targeting Turkish energy and nuclear research personnel, European think tanks, and organizations in North Macedonia and Uzbekistan. (Published on 9-Jan-2026, The Hacker News). <strong><a href="https://thehackernews.com/2026/01/russian-apt28-runs-credential-stealing.html">Read More</a></strong></p></li><li><p>&#127464;&#127475; Salt Typhoon Chinese hack scope expands as investigations reveal Chinese state hackers spent over a year undetected inside major U.S. telecom networks, spying on officials. (Published on 9-Jan-2026, Techdirt). <strong><a href="https://www.techdirt.com/2026/01/09/scope-of-chinese-salt-typhoon-hack-keeps-getting-worse-as-trump-dismantles-u-s-cybersecurity-defenses/">Read More</a></strong></p></li></ul><p><strong>Vulnerability Research &amp; Industry Analysis</strong></p><p>Researchers spotlight metadata leaks and novel attack techniques.</p><ul><li><p>&#128241; WhatsApp metadata leak enables device fingerprinting useful for sophisticated spyware delivery, though impact remains limited without zero-day exploits; Meta rolling out fixes. (Published on 5-Jan-2026, SecurityWeek). <strong><a href="https://www.securityweek.com/researcher-spotlights-whatsapp-metadata-leak-as-meta-begins-rolling-out-fixes/">Read More</a></strong></p></li></ul><p><strong>Cybersecurity Tools &amp; Techniques</strong></p><p>Defenders demonstrate creative approaches to identifying threat actors.</p><ul><li><p>&#129700; Security researchers successfully trapped Scattered Lapsus$ Hunters (ShinyHunters) using a honeypot with realistic but mostly fake datasets, drawing in the notorious threat actors. (Published on 6-Jan-2026, Dark Reading). <strong><a href="https://www.darkreading.com/endpoint-security/scattered-lapsus-hunters-researcher-honeypot">Read More</a></strong></p></li></ul><div><hr></div><p>Stay informed and secure in the tech and cybersecurity world. Have a great weekend, and remember to patch and protect your systems!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://thefwu.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Friday Wrap Up! Subscribe and never miss a weekly edition!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Friday Wrap Up: 19 December 2025]]></title><description><![CDATA[The Friday Wrap Up is taking a holiday break &#127876;]]></description><link>https://thefwu.com/p/friday-wrap-up-19-december-2025</link><guid isPermaLink="false">https://thefwu.com/p/friday-wrap-up-19-december-2025</guid><dc:creator><![CDATA[Jorge Laurel]]></dc:creator><pubDate>Fri, 19 Dec 2025 20:01:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" width="550" height="320.8333333333333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:420,&quot;width&quot;:720,&quot;resizeWidth&quot;:550,&quot;bytes&quot;:204370,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>The Friday Wrap Up is taking a holiday break &#127876;</p><p>After 50 weeks of doom-scrolling through CVEs, data breaches, and supply chain incidents, the FWU is officially logging off until 2026.</p><p>Yes, 2026. The FWU will be back with more threat intelligence, more zero-days, and probably another ransomware group with a questionable naming convention.</p><p>What to expect during the FWU break:</p><p>&#9;&#8226;&#9;Threat actors will continue working (they don&#8217;t believe in work-life balance)</p><p>&#9;&#8226;&#9;Your CEO will still click on phishing emails</p><p>&#9;&#8226;&#9;Someone will definitely misconfigure an S3 bucket</p><p>&#9;&#8226;&#9;We will be blissfully unaware of all of it &#9749;</p><p>Gentle reminders while the FWU is gone:</p><p>&#9;&#8226;&#9;&#8220;admin/admin&#8221; is not a secure credential combo, no matter what your IoT device says</p><p>&#9;&#8226;&#9;Your family&#8217;s tech support questions can wait until January (probably)</p><p>&#9;&#8226;&#9;If an email says &#8220;URGENT: Your Netflix account has been suspended,&#8221; it&#8217;s lying</p><p>Stay safe out there. Patch your systems. Enable MFA. Don&#8217;t let your guard down just because we did.</p><p>See you in 2026 &#128272;</p><p>P.S. - If something catastrophic happens, I&#8217;ll probably still post about it. I have a problem.</p><div><hr></div><p>Stay informed and secure in the tech and cybersecurity world. Have a great weekend, and remember to patch and protect your systems!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://thefwu.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Friday Wrap Up! Subscribe and never miss a weekly edition!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Friday Wrap Up: 12 December 2025]]></title><description><![CDATA[Another week, another avalanche of zero-days, ransomware victims, and creative attack techniques that make you wonder if threat actors ever sleep (spoiler: they don&#8217;t).]]></description><link>https://thefwu.com/p/friday-wrap-up-12-december-2025</link><guid isPermaLink="false">https://thefwu.com/p/friday-wrap-up-12-december-2025</guid><dc:creator><![CDATA[Jorge Laurel]]></dc:creator><pubDate>Sat, 13 Dec 2025 13:28:56 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" width="550" height="320.8333333333333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:420,&quot;width&quot;:720,&quot;resizeWidth&quot;:550,&quot;bytes&quot;:204370,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Another week, another avalanche of zero-days, ransomware victims, and creative attack techniques that make you wonder if threat actors ever sleep (spoiler: they don&#8217;t). </p><p>From Chrome getting exploited in the wild to malware hiding in VS Code extensions&#8212;because apparently, even our dev tools need therapy now&#8212;this week had it all. We&#8217;ve got nation-state shenanigans, AI security guardrails, and someone at Accenture allegedly fudging DoD compliance (yikes). </p><p>Click through for the full breakdown before your CISO asks if you&#8217;ve seen the latest Chrome patch.</p><p>#CyberSecurity #ThreatIntelligence #InfoSec #FWU #fridaywrapup #Malware #DataBreach #Ransomware</p><div><hr></div><p><strong>Major Cyberattacks &amp; Incidents</strong></p><p>This week saw multiple significant data breaches and sophisticated attack campaigns targeting organizations worldwide.</p><ul><li><p>&#128680; Marquis Software Solutions suffered a firewall vulnerability breach exposing personal data of over 780,000 individuals across the United States. (Published on 8-Dec-2025, Infosecurity). <strong><a href="https://www.infosecurity-magazine.com/news/marquis-software-breach/">Read More</a></strong></p></li><li><p>&#128202; Fieldtex Products disclosed a data breach impacting 238,000 people after the Akira ransomware group claimed responsibility for stealing 14GB of company data. (Published on 12-Dec-2025, SecurityWeek). <strong><a href="https://www.securityweek.com/fieldtex-data-breach-impacts-238000/">Read More</a></strong></p></li><li><p>&#127978; South Korean police raided Coupang&#8217;s offices following a major data breach, prompting the CEO&#8217;s resignation amid the investigation. (Published on 12-Dec-2025, Infosecurity). <strong><a href="https://www.infosecurity-magazine.com/news/seoul-police-raid-coupang-ceo/">Read More</a></strong></p></li><li><p>&#127919; Storm-0249 initial access broker weaponized endpoint detection and response platforms and Windows utilities in highly targeted precision attacks against organizations. (Published on 10-Dec-2025, Dark Reading). <strong><a href="https://www.darkreading.com/cyberattacks-data-breaches/storm-0249-edr-processes-stealthy-attacks">Read More</a></strong></p></li></ul><p><strong>Malware &amp; Vulnerabilities</strong></p><p>Critical flaws and new malware campaigns dominated security headlines with exploits targeting enterprise and consumer platforms alike.</p><ul><li><p>&#128376;&#65039; JS#SMUGGLER campaign leverages compromised websites to inject obfuscated JavaScript loaders distributing NetSupport RAT through encrypted HTML applications. (Published on 8-Dec-2025, The Hacker News). <strong><a href="https://thehackernews.com/2025/12/experts-confirm-jssmuggler-uses.html">Read More</a></strong></p></li><li><p>&#128295; SAP released December security updates patching 14 vulnerabilities including three critical-severity flaws affecting Solution Manager, Commerce Cloud, and other products. (Published on 9-Dec-2025, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/security/sap-fixes-three-critical-vulnerabilities-across-multiple-products/">Read More</a></strong></p></li><li><p>&#129302; Google patched a critical Gemini Enterprise vulnerability enabling attackers to inject malicious instructions into documents to exfiltrate sensitive corporate information. (Published on 9-Dec-2025, Dark Reading). <strong><a href="https://www.darkreading.com/remote-workforce/gemini-enterprise-exposes-sensitive-data">Read More</a></strong></p></li><li><p>&#128221; Adobe addressed nearly 140 vulnerabilities in its December update, including 116 cross-site scripting bugs in Experience Manager. (Published on 9-Dec-2025, SecurityWeek). <strong><a href="https://www.securityweek.com/adobe-patches-nearly-140-vulnerabilities/">Read More</a></strong></p></li><li><p>&#127984; CastleLoader malware used by four distinct threat clusters confirms GrayBravo&#8217;s malware-as-a-service business model expanding infrastructure. (Published on 9-Dec-2025, The Hacker News). <strong><a href="https://thehackernews.com/2025/12/four-threat-clusters-using-castleloader.html">Read More</a></strong></p></li><li><p>&#128241; DroidLock Android malware locks device screens demanding ransom while accessing text messages, call logs, contacts, and audio data. (Published on 10-Dec-2025, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/security/new-droidlock-malware-locks-android-devices-and-demands-a-ransom/">Read More</a></strong></p></li><li><p>&#128273; Gladinet&#8217;s CentreStack and Triofox products contain hard-coded cryptographic keys enabling unauthorized access and remote code execution in active attacks. (Published on 10-Dec-2025, The Hacker News). <strong><a href="https://thehackernews.com/2025/12/hard-coded-gladinet-keys-let-attackers.html">Read More</a></strong></p></li><li><p>&#128190; Three security vulnerabilities in PCIe 5.0+ Integrity and Data Encryption protocol expose systems to faulty data handling by local attackers. (Published on 10-Dec-2025, The Hacker News). <strong><a href="https://thehackernews.com/2025/12/three-pcie-encryption-weaknesses-expose.html">Read More</a></strong></p></li><li><p>&#9729;&#65039; ConsentFix attack variant exploits Azure CLI OAuth app to hijack Microsoft accounts without passwords or bypassing multi-factor authentication. (Published on 11-Dec-2025, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/security/new-consentfix-attack-hijacks-microsoft-accounts-via-azure-cli/">Read More</a></strong></p></li><li><p>&#128187; Nineteen malicious Visual Studio Code extensions embedded malware in dependency folders using legitimate npm packages to compromise developer environments. (Published on 11-Dec-2025, Infosecurity). <strong><a href="https://www.infosecurity-magazine.com/news/malware-discovered-in-19-vs-code/">Read More</a></strong></p></li><li><p>&#128013; PyStoreRAT JavaScript-based remote access trojan distributed through fake OSINT and GPT utility GitHub repositories targeting developers. (Published on 12-Dec-2025, The Hacker News). <strong><a href="https://thehackernews.com/2025/12/fake-osint-and-gpt-utility-github-repos.html">Read More</a></strong></p></li><li><p>&#127822; Apple issued emergency patches for two zero-day vulnerabilities exploited in extremely sophisticated attacks targeting specific individuals. (Published on 12-Dec-2025, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/security/apple-fixes-two-zero-day-flaws-exploited-in-sophisticated-attacks/">Read More</a></strong></p></li><li><p>&#127760; Google Chrome faced active in-the-wild exploitation of an undisclosed high-severity vulnerability prompting emergency security updates. (Published on 11-Dec-2025, The Hacker News). <strong><a href="https://thehackernews.com/2025/12/chrome-targeted-by-active-in-wild.html">Read More</a></strong></p></li></ul><p><strong>Vulnerability Research &amp; Exploitation</strong></p><p>Rapid exploitation campaigns demonstrated how quickly threat actors weaponize newly disclosed vulnerabilities.</p><ul><li><p>&#9883;&#65039; React2Shell (CVE-2025-55182) exploitation activity intensified as more threat actors weaponized the flaw immediately following public disclosure. (Published on 8-Dec-2025, Dark Reading). <strong><a href="https://www.darkreading.com/vulnerabilities-threats/exploitation-activity-ramps-react2shell">Read More</a></strong></p></li><li><p>&#127472;&#127477; Sophisticated React2Shell exploitation campaigns delivering EtherRAT show indicators linking attacks to North Korean cyber intrusion tactics. (Published on 9-Dec-2025, Infosecurity). <strong><a href="https://www.infosecurity-magazine.com/news/react2shell-exploit-campaigns/">Read More</a></strong></p></li></ul><p><strong>Espionage &amp; Nation-State Activity</strong></p><p>Pro-Russia hacktivist groups escalated targeting of critical infrastructure in coordinated campaigns.</p><ul><li><p>&#127919; Pro-Russia hacktivist groups exploited exposed virtual network computing connections to breach operational technology systems in US critical infrastructure. (Published on 10-Dec-2025, Infosecurity). <strong><a href="https://www.infosecurity-magazine.com/news/russia-hackers-target-us-critical/">Read More</a></strong></p></li></ul><p><strong>AI &amp; Policy</strong></p><p>Developments in AI security, regulatory compliance, and industry guidance shaped conversations around emerging technologies.</p><ul><li><p>&#128737;&#65039; Google detailed security guardrails protecting Chrome&#8217;s upcoming agentic browsing features from indirect prompt injection and other AI-specific attacks. (Published on 8-Dec-2025, TechCrunch). <strong><a href="https://techcrunch.com/2025/12/08/google-details-security-measures-for-chromes-agentic-features/">Read More</a></strong></p></li><li><p>&#129302; Chrome&#8217;s agentic AI protections include user alignment critic, expanded origin-isolation capabilities, and mandatory user confirmations for sensitive actions. (Published on 8-Dec-2025, SecurityWeek). <strong><a href="https://www.securityweek.com/google-fortifies-chrome-agentic-ai-against-indirect-prompt-injection-attacks/">Read More</a></strong></p></li><li><p>&#128176; Microsoft expanded its bug bounty program to reward security researchers for critical vulnerabilities in any online service regardless of code origin. (Published on 11-Dec-2025, BleepingComputer). <strong><a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-bounty-program-now-includes-any-flaw-impacting-its-services/">Read More</a></strong></p></li><li><p>&#9878;&#65039; Former Accenture employee Danielle Hillmer faces cybersecurity fraud charges for allegedly concealing that cloud platforms failed DoD security requirements. (Published on 11-Dec-2025, SecurityWeek). <strong><a href="https://www.securityweek.com/former-accenture-employee-charged-over-cybersecurity-fraud/">Read More</a></strong></p></li><li><p>&#127917; UK&#8217;s National Cyber Security Centre released new cyber deception guidance and learnings from pilot programs advancing defensive capabilities. (Published on 12-Dec-2025, Infosecurity). <strong><a href="https://www.infosecurity-magazine.com/news/ncsc-plugs-gap-cyber-deception/">Read More</a></strong></p></li></ul><div><hr></div><p>Stay informed and secure in the tech and cybersecurity world. Have a great weekend, and remember to patch and protect your systems!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://thefwu.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Friday Wrap Up! Subscribe and never miss a weekly edition!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Friday Wrap Up: 5 December 2025]]></title><description><![CDATA[Another week, another reminder that cybercriminals are getting creative while defenders scramble to keep up!]]></description><link>https://thefwu.com/p/friday-wrap-up-5-december-2025</link><guid isPermaLink="false">https://thefwu.com/p/friday-wrap-up-5-december-2025</guid><dc:creator><![CDATA[Jorge Laurel]]></dc:creator><pubDate>Fri, 05 Dec 2025 20:01:31 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" width="550" height="320.8333333333333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:420,&quot;width&quot;:720,&quot;resizeWidth&quot;:550,&quot;bytes&quot;:204370,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Another week, another reminder that cybercriminals are getting creative while defenders scramble to keep up! From malware disguising itself as helpful browser extensions to hackers learning poetry (yes, really) to break AI systems, this week had it all.</p><p>We&#8217;re talking massive DDoS attacks breaking records, nation-states playing the long game with backdoors, and even an Aussie getting jail time for fake airport Wi-Fi. Plus, the eternal struggle continues: zero trust is still more &#8220;aspirational framework&#8221; than &#8220;accomplished mission&#8221; for most organizations.</p><p>Whether you&#8217;re patching React vulnerabilities, investigating ransomware claims, or just trying to understand why cybercrime has become a subscription service, this week&#8217;s wrap-up has the details you need.</p><p>Scroll through for the full breakdown of attacks, breaches, and security developments that shaped the week. Stay vigilant out there! &#128272;</p><p>#ThreatIntel #SecurityBreaches #CyberThreats #FWU #fridaywrapup #CyberSecurity #InfoSec #Malware #DateBreach #Ransomware</p><div><hr></div><p><strong>Malware &amp; Vulnerabilities</strong> </p><p>This week revealed a disturbing landscape of evolving malware threats and critical software flaws demanding immediate attention.</p><ul><li><p>&#129440; ShadyPanda malicious campaign amassed 4.3 million Chrome and Edge browser extension installations, transforming seemingly legitimate tools into malware over seven years. (Published on 1-Dec-2025, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/shadypanda-browser-extensions-amass-43m-installs-in-malicious-campaign/">Read More</a></p></li><li><p>&#128176; Albiriox banking trojan surfaces as new Android malware-as-a-service offering from Russian cybercriminals, available for $720 monthly subscription targeting 400+ global banking apps. (Published on 1-Dec-2025, SecurityWeek). <a href="https://www.securityweek.com/new-albiriox-android-malware-developed-by-russian-cybercriminals/">Read More</a></p></li><li><p>&#129302; Malicious npm package manipulates AI security detection systems with misleading prompts, exploiting automated analysis tools in sophisticated supply chain attack. (Published on 1-Dec-2025, Infosecurity). <a href="https://www.infosecurity-magazine.com/news/malware-ai-detection-npm-package/">Read More</a></p></li><li><p>&#128269; Chrome and Edge extensions caught profiling users, reading cookie data to create unique identifiers, and executing malicious payloads with full browser API access. (Published on 2-Dec-2025, SecurityWeek). <a href="https://www.securityweek.com/chrome-edge-extensions-caught-tracking-users-creating-backdoors/">Read More</a></p></li><li><p>&#128241; Google patches 107 Android vulnerabilities including two Framework bugs actively exploited in the wild, addressing flaws across multiple system components and chipset manufacturers. (Published on 2-Dec-2025, The Hacker News). <a href="https://thehackernews.com/2025/12/google-patches-107-android-flaws.html">Read More</a></p></li><li><p>&#9883;&#65039; Critical React vulnerability threatens major applications as developers scramble to patch flaw found in 39% of cloud environments using this widely-deployed framework. (Published on 3-Dec-2025, CyberScoop). <a href="https://cyberscoop.com/react-server-vulnerability-critical-severity-security-update/">Read More</a></p></li><li><p>&#129695; Microsoft silently patches Windows LNK file vulnerability actively exploited since 2017, addressing UI misinterpretation flaw that enabled threat actors&#8217; campaigns for years. (Published on 3-Dec-2025, The Hacker News). <a href="https://thehackernews.com/2025/12/microsoft-silently-patches-windows-lnk.html">Read More</a></p></li><li><p>&#127464;&#127475; Chinese hackers actively exploit React2Shell vulnerability as AWS observes multiple China-linked threat groups targeting the critical flaw in coordinated campaigns. (Published on 4-Dec-2025, SecurityWeek). <a href="https://www.securityweek.com/chinese-hackers-exploiting-react2shell-vulnerability/">Read More</a></p></li></ul><p><strong>Major Cyberattacks &amp; Incidents</strong> </p><p>Significant breaches this week exposed vulnerabilities across emergency services, manufacturing, financial sectors, and government infrastructure.</p><ul><li><p>&#128680; CodeRED emergency alert platform shut down following cyberattack, with Inc ransomware gang claiming responsibility and threatening sensitive subscriber data exposure. (Published on 1-Dec-2025, Dark Reading). <a href="https://www.darkreading.com/cyberattacks-data-breaches/codered-emergency-alert-platform-shut-down-cyberattack">Read More</a></p></li><li><p>&#127970; Everest ransomware group claims ASUS breach, alleging theft of over 1TB data including camera source code with 21-hour response deadline via Qtox. (Published on 2-Dec-2025, Hackread). <a href="https://hackread.com/everest-ransomware-asus-breach-1tb-data/">Read More</a></p></li><li><p>&#127974; Marquis Software Solutions data breach impacts over 74 U.S. banks and credit unions, exposing customers&#8217; financial information through compromised software provider infrastructure. (Published on 3-Dec-2025, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/marquis-data-breach-impacts-over-74-us-banks-credit-unions/">Read More</a></p></li><li><p>&#128241; Freedom Mobile confirms data breach as hackers stole customers&#8217; personal information from account management platform, compromising subscriber details and credentials. (Published on 4-Dec-2025, SecurityWeek). <a href="https://www.securityweek.com/personal-information-compromised-in-freedom-mobile-data-breach/">Read More</a></p></li><li><p>&#128187; Two Virginia contractors arrested for allegedly wiping 96 government databases and stealing sensitive information after termination from federal positions. (Published on 4-Dec-2025, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/contractors-with-hacking-records-accused-of-wiping-96-govt-databases/">Read More</a></p></li></ul><p><strong>Espionage &amp; Data Extraction</strong> </p><p>Nation-state actors and commercial spyware operators continued targeting sensitive data through sophisticated intelligence operations.</p><ul><li><p>&#127472;&#127477; North Korean recruiters exposed in unprecedented operation luring software engineers to rent their identities for illicit IT worker schemes funding regime activities. (Published on 2-Dec-2025, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/north-korea-lures-engineers-to-rent-identities-in-fake-it-worker-scheme/">Read More</a></p></li><li><p>&#128722; Arizona Attorney General sues Chinese retailer Temu and parent company PDD Holdings over allegations of stealing customers&#8217; data through e-commerce platform. (Published on 3-Dec-2025, SecurityWeek). <a href="https://www.securityweek.com/arizona-attorney-general-sues-chinese-online-retailer-temu-over-data-theft-claims/">Read More</a></p></li><li><p>&#128272; CISA reveals BRICKSTORM backdoor used by PRC state-sponsored threat actors for maintaining long-term persistence in compromised VMware vSphere and Windows systems. (Published on 5-Dec-2025, The Hacker News). <a href="https://thehackernews.com/2025/12/cisa-reports-prc-hackers-using.html">Read More</a></p></li><li><p>&#128065;&#65039; Predator spyware maker Intellexa continues operations despite sanctions, with new data leaks exposing flagship spyware infrastructure, attack vectors, and additional victims. (Published on 5-Dec-2025, Infosecurity). <a href="https://www.infosecurity-magazine.com/news/predator-spyware-intellexa-evades/">Read More</a></p></li></ul><p><strong>Cybersecurity Tools &amp; Techniques</strong> </p><p>From criminal prosecution to underground marketplace evolution, this week highlighted both enforcement successes and emerging threat landscapes.</p><ul><li><p>&#9992;&#65039; Australian man sentenced to 7 years 4 months in prison for deploying evil twin Wi-Fi networks at airports and mid-flight to steal travelers&#8217; data. (Published on 1-Dec-2025, Hackread). <a href="https://hackread.com/evil-twin-wifi-hacker-jail-steal-data-midflight/">Read More</a></p></li><li><p>&#128736;&#65039; Cybercrime fully shifts to subscription model with phishing kits, Telegram OTP bots, infostealer logs, and RATs now rented like SaaS tools for low-skill attackers. (Published on 2-Dec-2025, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/cybercrime-goes-saas-renting-tools-access-and-infrastructure/">Read More</a></p></li></ul><p><strong>DDoS, Outages &amp; Infrastructure</strong> </p><p>Massive DDoS attacks and critical infrastructure failures demonstrated the fragility of internet services under targeted assault.</p><ul><li><p>&#127754; Cloudflare detects and mitigates record-breaking 29.7 Tbps DDoS attack originating from AISURU botnet-for-hire with up to 4 million infected hosts. (Published on 3-Dec-2025, The Hacker News). <a href="https://thehackernews.com/2025/12/record-297-tbps-ddos-attack-linked-to.html">Read More</a></p></li><li><p>&#9888;&#65039; Cloudflare outage causes widespread website crashes with 500 Internal Server Error messages affecting numerous sites relying on the infrastructure provider&#8217;s services. (Published on 5-Dec-2025, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/technology/cloudflare-down-websites-offline-with-500-internal-server-error/">Read More</a></p></li></ul><p><strong>AI &amp; Policy</strong> </p><p>Emerging research reveals AI vulnerabilities while industry grapples with implementing foundational security frameworks.</p><ul><li><p>&#127917; Researchers demonstrate AI jailbreaking through poetry, increasing attack success rates from 8% to 43% when prompts use poetic rather than prose formatting. (Published on 2-Dec-2025, Dark Reading). <a href="https://www.darkreading.com/threat-intelligence/researchers-use-poetry-to-jailbreak-ai-models">Read More</a></p></li><li><p>&#128667; California revises rules potentially ending self-driving truck ban, allowing autonomous vehicle testing on public highways while closing driverless vehicle ticketing loopholes. (Published on 4-Dec-2025, TechCrunch). <a href="https://techcrunch.com/2025/12/04/californias-ban-on-self-driving-trucks-could-soon-be-over/">Read More</a></p></li><li><p>&#128737;&#65039; After 15 years, zero trust implementation remains elusive as organizations struggle with fragmented tooling, legacy infrastructure, and emerging AI agent security challenges. (Published on 4-Dec-2025, CSO Online). <a href="https://www.csoonline.com/article/4101457/15-years-in-zero-trust-remains-elusive-with-ai-rising-to-complicate-the-challenge.html">Read More</a></p></li></ul><div><hr></div><p>Stay informed and secure in the tech and cybersecurity world. Have a great weekend, and remember to patch and protect your systems!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://thefwu.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Friday Wrap Up! Subscribe and never miss a weekly edition!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Friday Wrap Up: 28 November 2025]]></title><description><![CDATA[This week&#8217;s cybersecurity landscape?]]></description><link>https://thefwu.com/p/friday-wrap-up-28-november-2025</link><guid isPermaLink="false">https://thefwu.com/p/friday-wrap-up-28-november-2025</guid><dc:creator><![CDATA[Jorge Laurel]]></dc:creator><pubDate>Fri, 28 Nov 2025 20:00:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NXyq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png" width="550" height="320.8333333333333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:420,&quot;width&quot;:720,&quot;resizeWidth&quot;:550,&quot;bytes&quot;:204370,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NXyq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 424w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 848w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1272w, https://substackcdn.com/image/fetch/$s_!NXyq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc854414a-a5ba-4e26-b9e0-d44539828b94_720x420.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>This week&#8217;s cybersecurity landscape? Let&#8217;s just say the supply chain attacks are getting creative, the credential leaks are getting embarrassing, and emergency alert systems proved they&#8217;re not immune to ransomware. </p><p>From worms named after sci-fi sandworms to threat groups with identity crises, we&#8217;ve got breaches affecting everything from real estate finance to your favorite analytics platforms. </p><p>Oh, and reminder: those &#8220;helpful&#8221; code formatting websites? They&#8217;ve been collecting your credentials like Pok&#233;mon cards. Click through for the full roundup of this week&#8217;s digital chaos.</p><div><hr></div><p><strong>Malware &amp; Vulnerabilities</strong> </p><p>Critical flaws and malicious software dominated headlines this week, from widely-used tools to emerging threats.</p><ul><li><p>&#128680; Critical 7-Zip vulnerability CVE-2025-11001 has a public exploit requiring manual update to version 25.01 to protect against high-risk attacks. (Published on 23-Nov-2025, Hackread). <a href="https://hackread.com/7-zip-vulnerability-public-exploit-manual-update/">Read More</a></p></li><li><p>&#128293; Firefox patched CVE-2025-13016, a critical Wasm memory bug that exposed 180 million users to code execution risks for six months. (Published on 25-Nov-2025, Hackread). <a href="https://hackread.com/update-firefox-patch-cve-2025-13016-vulnerability/">Read More</a></p></li><li><p>&#128241; RadzaRat Android RAT disguises itself as a file manager with zero detection on VirusTotal, stealing passwords and files through keylogging. (Published on 24-Nov-2025, Hackread). <a href="https://hackread.com/radzarat-spyware-hijack-android-devices/">Read More</a></p></li><li><p>&#129713; Sha1-Hulud worm returned in a second wave, infecting nearly 500 npm packages and exposing over 26,000 GitHub repositories within 24 hours. (Published on 24-Nov-2025, CyberScoop). <a href="https://cyberscoop.com/supply-chain-attack-shai-hulud-npm/">Read More</a></p></li><li><p>&#127907; Shai-Hulud attack compromised 25,000+ repositories through npm preinstall credential theft in a sophisticated supply chain campaign targeting developers. (Published on 24-Nov-2025, The Hacker News). <a href="https://thehackernews.com/2025/11/second-sha1-hulud-wave-affects-25000.html">Read More</a></p></li><li><p>&#9729;&#65039; Five Fluent Bit vulnerabilities expose cloud services to path traversal, remote code execution, denial-of-service, and tag manipulation attacks. (Published on 25-Nov-2025, SecurityWeek). <a href="https://www.securityweek.com/fluent-bit-vulnerabilities-expose-cloud-services-to-takeover/">Read More</a></p></li><li><p>&#128230; North Korean hackers deployed 197 malicious npm packages with 31,000+ downloads, spreading updated OtterCookie malware combining BeaverTail features. (Published on 28-Nov-2025, The Hacker News). <a href="https://thehackernews.com/2025/11/north-korean-hackers-deploy-197-npm.html">Read More</a></p></li><li><p>&#129302; ShadowV2 botnet malware targets IoT devices from D-Link, TP-Link vendors, exploiting known vulnerabilities and testing during AWS outages. (Published on 26-Nov-2025, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/new-shadowv2-botnet-malware-used-aws-outage-as-a-test-opportunity/">Read More</a></p></li></ul><p><strong>Major Cyberattacks &amp; Incidents</strong> </p><p>Enterprise platforms and service providers faced significant breaches this week, exposing customer data and disrupting critical services.</p><ul><li><p>&#127970; SitusAMC real-estate finance giant disclosed data breach affecting customer information from banks and lenders served by their back-end platform. (Published on 24-Nov-2025, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/real-estate-finance-services-giant-situsamc-breach-exposes-client-data/">Read More</a></p></li><li><p>&#128176; Gainsight expanded impacted customer list beyond initial three customers following Salesforce security alert, with CEO acknowledging broader impact. (Published on 26-Nov-2025, The Hacker News). <a href="https://thehackernews.com/2025/11/gainsight-expands-impacted-customer.html">Read More</a></p></li><li><p>&#128680; Inc Ransom ransomware group targeted OnSolve CodeRED platform, disrupting local emergency alert systems across the US and causing data breach. (Published on 26-Nov-2025, SecurityWeek). <a href="https://www.securityweek.com/ransomware-attack-disrupts-local-emergency-alert-system-across-us/">Read More</a></p></li><li><p>&#128202; Mixpanel hack exposed OpenAI user data along with multiple other customers in cyberattack targeting the product analytics company. (Published on 27-Nov-2025, SecurityWeek). <a href="https://www.securityweek.com/openai-user-data-exposed-in-mixpanel-hack/">Read More</a></p></li><li><p>&#128250; Comcast will pay $1.5 million FCC fine after February 2024 vendor data breach exposed personal information of nearly 275,000 customers. (Published on 26-Nov-2025, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/comcast-to-pay-15-million-fine-after-a-vendor-data-breach-affecting-270-000-customers/">Read More</a></p></li></ul><p><strong>Espionage &amp; Data Extraction</strong> </p><p>Sophisticated threat actors continued targeting organizations through social engineering and supply chain attacks.</p><ul><li><p>&#128188; RomCom threat actors used SocGholish fake JavaScript updates to deliver Mythic Agent malware to US civil engineering company. (Published on 26-Nov-2025, The Hacker News). <a href="https://thehackernews.com/2025/11/romcom-uses-socgholish-fake-update.html">Read More</a></p></li><li><p>&#127919; Scattered Lapsus$ Hunters deployed 40+ fake Zendesk domains and fraudulent support tickets to steal credentials and install malware. (Published on 28-Nov-2025, CSO Online). <a href="https://www.csoonline.com/article/4097846/scattered-lapsus-hunters-target-zendesk-users-with-fake-domains.html">Read More</a></p></li><li><p>&#128100; Report names 15-year-old Saif Khader from Jordan as Scattered Lapsus$ Hunters admin &#8220;Rey,&#8221; though group denies the allegation. (Published on 27-Nov-2025, Hackread). <a href="https://hackread.com/report-names-teen-scattered-lapsus-hunters-group/">Read More</a></p></li><li><p>&#128197; Threat actors exploit calendar subscriptions to deliver phishing links, malware, and social engineering attacks through hijacked domains. (Published on 28-Nov-2025, Infosecurity). <a href="https://www.infosecurity-magazine.com/news/threat-actors-exploit-calendar-subs/">Read More</a></p></li></ul><p><strong>Vulnerability Research &amp; Industry Analysis</strong> </p><p>Years of accumulated security gaps exposed sensitive data across multiple platforms and tools.</p><ul><li><p>&#128273; JSONFormatter and CodeBeautify leaked 80,000+ files over years, exposing passwords and API keys from governments, telecoms, and infrastructure. (Published on 25-Nov-2025, The Hacker News). <a href="https://thehackernews.com/2025/11/years-of-jsonformatter-and-codebeautify.html">Read More</a></p></li><li><p>&#128736;&#65039; Code beautifiers expose thousands of credentials from banks, government, and tech organizations in publicly accessible JSON snippets. (Published on 25-Nov-2025, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/code-beautifiers-expose-credentials-from-banks-govt-tech-orgs/">Read More</a></p></li><li><p>&#128274; Microsoft Teams B2B Guest Access flaw allows attackers to bypass all Defender for Office 365 protections with single invite. (Published on 26-Nov-2025, Hackread). <a href="https://hackread.com/microsoft-teams-guest-chat-flaw-malware/">Read More</a></p></li></ul><p><strong>Cybersecurity Tools &amp; Techniques </strong></p><p>New defensive capabilities and improved security measures provide organizations with better protection options.</p><ul><li><p>&#128272; Tor upgraded to Counter Galois Onion encryption algorithm, replacing old tor1 relay design for enhanced circuit traffic security. (Published on 25-Nov-2025, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/tor-switches-to-new-counter-galois-onion-relay-encryption-algorithm/">Read More</a></p></li><li><p>&#128269; GreyNoise launched free IP Check tool to detect if your address appears in malicious botnet or residential proxy scanning operations. (Published on 28-Nov-2025, BleepingComputer). <a href="https://www.bleepingcomputer.com/news/security/greynoise-launches-free-scanner-to-check-if-youre-part-of-a-botnet/">Read More</a></p></li></ul><div><hr></div><p>Stay informed and secure in the tech and cybersecurity world. Have a great weekend, and remember to patch and protect your systems!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://thefwu.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Friday Wrap Up! Subscribe and never miss a weekly edition!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>