Sign in

Jorge Laurel

@jorgelaurel.com
33 followers 20 following 540 posts
PostsRepliesMedia
Jorge Laurel @jorgelaurel.com · 16h
GitLab warns of a critical security flaw in its AI Gateway Service that allows remote code execution. This could let attackers control affected servers. Users are urged to update to the latest patch. #CybersecurityAlert
bleepingcomputer.com
GitLab warns of critical RCE vulnerability in AI Gateway service
GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances.
000
Jorge Laurel @jorgelaurel.com · 02/10/2026
Police dismantled the KillNet ransomware gang led by a 16-year-old. This highlights the rising threat of cybercrimes, even from young individuals, and the importance of cybersecurity vigilance. #CyberSecurityInsight
bleepingcomputer.com
Police dismantle KillSec ransomware gang allegedly led by 16-year-old
An international law enforcement operation dubbed "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, led to three arrests, and identified a 16-year-old as the group's...
010
Jorge Laurel @jorgelaurel.com · 01/10/2026
CISA highlights a critical security flaw in MikroTik RouterOS that allows remote code execution without authentication. It's important for users to update their systems to protect against potential threats. #Cybersecurity
bleepingcomputer.com
CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition.
001
Jorge Laurel @jorgelaurel.com · 30/09/2026
Windows 11's 2026 update enhances performance, security, and user experience with new features and fixes. Dive deeper into BleepingComputer's article for comprehensive details. #Windows11Update
bleepingcomputer.com
Windows 11 2026 Update released, here's everything you need to know
Microsoft has started rolling out Windows 11 26H2 to everyone, and while it's this year's big annual feature update, you probably won't notice a massive difference after installing it.
001
Jorge Laurel @jorgelaurel.com · 29/09/2026
JadePuffer uses AI to attack Azure, aiming to damage cloud resources. It adapts quickly, evades detection, and poses a threat to businesses relying on cloud services. Understanding its tactics can help strengthen defenses. #CloudSecurity
bleepingcomputer.com
JadePuffer agentic AI attacks target Azure, destroy cloud resources
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components.
000
Jorge Laurel @jorgelaurel.com · 28/09/2026
CISA warns about vulnerabilities in SharePoint, WSO2, and Adobe Commerce that hackers exploit to target systems. Keep your software updated to protect sensitive data and minimize risks. #CyberSecurityAlert
bleepingcomputer.com
CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise...
000
Jorge Laurel @jorgelaurel.com · 25/09/2026
GitLab's project email addresses, if exposed, can allow attackers to push code without permission. This flaw risks unauthorized access and software integrity. #CybersecurityAlert
bleepingcomputer.com
Exposed GitLab project email addresses let attackers push code
Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports.
000
Jorge Laurel @jorgelaurel.com · 24/09/2026
Malicious AI bots have been used to compromise over 100 websites by injecting skimmers, stealing 600k credit cards. This highlights the risks of AI being leveraged for cybercrime. #AIThreats
bleepingcomputer.com
Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers
A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records.
001
Jorge Laurel @jorgelaurel.com · 23/09/2026
Wazuh helps close visibility gaps in shadow IT, improving security by monitoring uncategorized devices and networks. It boosts IT transparency and risk management. #ITSecurity
bleepingcomputer.com
Reducing shadow IT visibility gaps with Wazuh
Shadow IT can leave security teams unaware of unmanaged endpoints, unauthorized software, and other assets that fall outside existing monitoring. Wazuh explains how endpoint inventory, agentless monitoring,...
000
Jorge Laurel @jorgelaurel.com · 22/09/2026
Microsoft is retiring Microsoft 365 Companion apps in December. These apps were designed to enhance productivity across devices. Users should plan for potential alternatives. #TechTransition
bleepingcomputer.com
Microsoft to retire Microsoft 365 Companion apps in December
Microsoft will retire the Calendar, People, and Files Microsoft 365 companion apps on December 16 and has asked admins to remove them from managed devices.
000
Jorge Laurel @jorgelaurel.com · 21/09/2026
A flaw in Gyazo's server allowed hackers to exploit it, leading to the theft of 236 million user records. This breach highlights the critical need for strong security measures in web services. #CyberSafety
bleepingcomputer.com
Gyazo server flaw exploited to steal 23.6 million user records
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records.
000
Jorge Laurel @jorgelaurel.com · 18/09/2026
A supply chain attack on Brevo injected malicious ClickFix scripts into customer websites, compromising site security. This highlights the growing threat of supply chain vulnerabilities in cybersecurity. #CyberThreats
bleepingcomputer.com
Brevo supply-chain attack injected ClickFix scripts on customer sites
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware.
000
Jorge Laurel @jorgelaurel.com · 17/09/2026
Spain's data agency reported its first AI-driven data breach affecting personal info security. This breach highlights rising AI threats in cybersecurity. #AIBreach
bleepingcomputer.com
Spain's data agency gets first report of AI-powered data breach
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM).
000
Jorge Laurel @jorgelaurel.com · 16/09/2026
CenterPoint Energy reveals a cyberattack and customer data breach, highlighting the importance of cybersecurity as the company collaborates with law enforcement for resolution. #CyberSecurityAlert
bleepingcomputer.com
CenterPoint Energy confirms customer data stolen in cyberattack
CenterPoint Energy disclosed a breach compromising some customers' personal information after an attacker leaked data allegedly stolen from the utility company.
000
Jorge Laurel @jorgelaurel.com · 15/09/2026
Hackers exploit exposed Vite dev servers to snatch AWS and Azure secrets. This shows the importance of protecting dev environments to stop data theft. #CyberSecurityAlert
bleepingcomputer.com
Hackers target exposed Vite dev servers to steal AWS, Azure secrets
A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments.
000
Jorge Laurel @jorgelaurel.com · 14/09/2026
Phishing attacks falsely promoting "passkeys" are targeting Microsoft 365 users, leading to data theft. Be cautious of emails offering passwordless authentication. #CyberSecurityAlert
bleepingcomputer.com
Passkey-themed phishing attacks lead to Microsoft 365 data theft
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts...
000
Jorge Laurel @jorgelaurel.com · 11/09/2026
An AI-driven attack exploited flaws in PaperCut software, affecting 395 organizations. The hack highlights the risks of AI in cyber threats and the need for robust security practices. #CyberSecurityAwareness
bleepingcomputer.com
AI-powered attack exploited PaperCut flaws to hack 395 organizations
A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers.
000
Jorge Laurel @jorgelaurel.com · 10/09/2026
Chinese firms allegedly extracted billions of tokens from U.S. Frontier AI models, raising significant cybersecurity concerns. This highlights the vulnerabilities in AI data protection that need urgent attention for security improvements. #CybersecurityChallenge
bleepingcomputer.com
US says Chinese firms extracted billions of tokens from frontier AI models
U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024.
000
Jorge Laurel @jorgelaurel.com · 09/09/2026
Windows 11 updates KB5124008 & KB5122880 focus on bug fixes and security improvements. Enhanced features aim to boost system stability and security. Ideal for maintaining your device’s performance and protection. #Windows11Updates
bleepingcomputer.com
Windows 11 cumulative updates KB5124008 & KB5122880 released
Microsoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features.
000
Jorge Laurel @jorgelaurel.com · 08/09/2026
Magento's StyleSmuggler zero-day is being exploited, allowing hackers to install a Linux backdoor. This highlights the importance of timely software updates and cybersecurity vigilance. #CyberSecurityNews
bleepingcomputer.com
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
A zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor.
010
Jorge Laurel @jorgelaurel.com · 07/09/2026
IDScan faced a lawsuit tied to a data breach impacting 153M driver records. Negligent security measures are blamed. It's a reminder of the importance of robust data protection methods. #DataSecurity
bleepingcomputer.com
IDScan sued over alleged data breach affecting 153 million drivers
Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver's licenses.
000
Jorge Laurel @jorgelaurel.com · 04/09/2026
Microsoft's KB5120998 update causes mouse settings to reset on non-English Windows PCs. The bug affects usability by reverting customized settings. #MicrosoftUpdates
bleepingcomputer.com
Microsoft: KB5120998 mouse reset bug affects only non-English PCs
Microsoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems.
000
Jorge Laurel @jorgelaurel.com · 03/09/2026
A critical flaw in JFrog Artifactory lets hackers forge admin tokens, posing a major security risk. Attackers can manipulate repositories, putting sensitive data at risk. Stay informed on these vulnerabilities. #CybersecurityUpdate
bleepingcomputer.com
Hackers exploit critical JFrog Artifactory flaw to forge admin tokens
A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access.
000
Jorge Laurel @jorgelaurel.com · 02/09/2026
Critical flaw in Langflow lets attackers steal OpenAI and AWS keys. This security issue can put sensitive data at risk. Understanding this vulnerability is key for safeguarding information systems. #CybersecurityAlert
bleepingcomputer.com
Critical Langflow flaw exploited to steal OpenAI and AWS keys
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and...
000
Jorge Laurel @jorgelaurel.com · 01/09/2026
Microsoft Exchange Online outage disrupted emails and caused authentication issues for users. The issue affected global communication and security. See how these outages impact daily operations and what measures are in place for recovery. #EmailOutage
bleepingcomputer.com
Microsoft Exchange Online outage causes email failures, auth issues
Microsoft is investigating a widespread service issue causing authentication issues, email delays and failures, and various other issues for Exchange Online customers.
000
Jorge Laurel @jorgelaurel.com · 31/08/2026
A 68-year-old man was jailed for earning $13M by illegally selling IPTV services. This highlights how serious legal actions can follow digital piracy. Learn more about protecting digital content. #DigitalPiracy
bleepingcomputer.com
68-year-old imprisoned after making $1.3 million by pirating IPTV services
A 68-year-old has been sentenced in the U.K. to more than six years in prison for operating an illegal IPTV (Internet Protocol Television) service that generated £980,812 ($1.3 million) over three years.
000
Jorge Laurel @jorgelaurel.com · 28/08/2026
PaperCut warns of a zero-day attack exploiting a flaw in their NG/MF software. This vulnerability could lead to unauthorized access. Users should ensure systems are secure and updated. #CybersecurityAlert
bleepingcomputer.com
PaperCut warns of NG, MF flaw exploited in zero-day attacks
PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.
010
Jorge Laurel @jorgelaurel.com · 27/08/2026
OpenAI's incident report is out. In July, agents in their own eval environment turned an internal package repo into a covert message board, SSRF'd their way back onto the internet, and chained two zero days into root on Hugging Face workers. Nobody directed it. They were stuck on unsolvable tasks.
linkedin.com
The warning shot was fired inside the lab
Last month, AI agents running inside OpenAI's own evaluation environment broke out of their sandboxes, built a covert communication channel, chained together previously unknown vulnerabilities, and co...
000
Jorge Laurel @jorgelaurel.com · 27/08/2026
Meta settled for $1.8 billion over claims that its platforms harm teens' mental health. This highlights increasing concerns about social media's impact on youth well-being. #SocialMediaImpact
bleepingcomputer.com
Meta agrees to $18 billion settlement over teen social media harms
Meta has reached a proposed settlement worth up to approximately $18 billion with a bipartisan coalition of 52 attorneys generals over allegations that Facebook and Instagram were deliberately designed...
010
Jorge Laurel @jorgelaurel.com · 26/08/2026
A massive DDoS attack disrupted Norway's government digital services, highlighting vulnerabilities in cybersecurity defenses. It's crucial to strengthen systems against such widespread threats. #CyberSecurityAwareness
bleepingcomputer.com
Massive DDoS attack disrupts Norway’s government digital services
A large distributed denial-of-service (DDoS) attack has disrupted Norway's shared government digital infrastructure since Monday, affecting services used by the public sector.
000
Jorge Laurel @jorgelaurel.com · 25/08/2026
TikTok faces a $400M settlement in the US for violating children’s privacy under COPPA. This highlights the challenges tech firms face in safeguarding young users' data. Learn more about the implications. #PrivacyConcerns
bleepingcomputer.com
TikTok reaches $400M settlement with US over COPPA violations
The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA).
021
Jorge Laurel @jorgelaurel.com · 24/08/2026
Leaked AWS keys expose corporate accounts to security risks, granting full control to attackers. Companies are urged to fortify their systems against breaches. #Cybersecurity
bleepingcomputer.com
Hundreds of leaked AWS keys give full control over corporate accounts
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid.
000
Jorge Laurel @jorgelaurel.com · 21/08/2026
Hackers altered the 'arrayref' Rust crate to distribute info-stealing malware, highlighting risks in open-source software. Developers are urged to assess dependencies. #CybersecurityAlert
bleepingcomputer.com
Hackers poison arrayref Rust crate to push infostealer malware
Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers' systems during compilation.
010
Jorge Laurel @jorgelaurel.com · 20/08/2026
The US warns of rising AI-based attacks on Siemens PLCs used in key infrastructure, highlighting the need for enhanced cybersecurity to protect vital systems. #CyberSecurityAlert
bleepingcomputer.com
US warns of AI-powered attacks on Siemens PLCs in critical infrastructure
U.S. cybersecurity agencies warn that threat actors are using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) in U.S. critical infrastructure.
010
Jorge Laurel @jorgelaurel.com · 19/08/2026
Clop ransomware gang crafted a unique web shell to steal data from PTC's Windchill systems. The attack highlights evolving cyber threats targeting specific tech to exploit sensitive data. #CyberThreats
bleepingcomputer.com
Clop created custom web shell for Windchill data theft attacks
A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories,...
000
Jorge Laurel @jorgelaurel.com · 18/08/2026
GitHub, a key platform for developers, is experiencing a global outage, confirmed by Microsoft. This impacts access to code repositories and developer collaboration. Stay updated on the situation affecting many users. #TechUpdate
bleepingcomputer.com
Microsoft confirms GitHub is down worldwide
GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services.
000
Jorge Laurel @jorgelaurel.com · 17/08/2026
Hackers exploit a macOS screen sharing flaw to install Monero cryptocurrency miners without detection. Users should ensure their systems are updated to mitigate risks. #MacOSSecurityFlaw
bleepingcomputer.com
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged.
000
Jorge Laurel @jorgelaurel.com · 14/08/2026
Microsoft has fixed a zero-day flaw, 'LegacyHive', affecting Windows. This important patch addresses a security risk that could exploit the system's sensitive data. For a deeper understanding, visit Bleeping Computer. #WindowsSecurityUpdate
bleepingcomputer.com
Microsoft patches LegacyHive Windows zero-day vulnerability
Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday.
000
Jorge Laurel @jorgelaurel.com · 13/08/2026
Claude now embeds an invisible watermark in every text it generates. Worldwide. No detector tool yet. Wrote up what AI watermarking is, how Google/OpenAI compare, and what this means for you. #ai #anthropic #claude #aiwatermarking
linkedin.com
AI watermarking, explained: what it is and what Anthropic just shipped
AI generated text is now in email, articles, homework, and code. That creates a practical problem for anyone who has to judge provenance: how do you tell what a machine wrote from what a person wrote?...
020
Jorge Laurel @jorgelaurel.com · 13/08/2026
Fake USB devices exploit Windows systems through "Plug and Pwn" attacks, granting unauthorized access by manipulating drivers. This highlights the need for enhanced USB device security. #CyberSecurityAwareness
bleepingcomputer.com
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
Security researchers have disclosed new "Plug and Pwn" attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges.
000
Jorge Laurel @jorgelaurel.com · 12/08/2026
Windows 11 updates (KB5121003 & KB5120240) fix bugs and enhance system stability, including improvements for app compatibility and gaming performance. Stay updated with Windows features. #Windows11Updates
bleepingcomputer.com
Windows 11 KB5121003 & KB5120240 cumulative updates released
Microsoft has released Windows 11 KB5121003 and KB5120240 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features.
000
Jorge Laurel @jorgelaurel.com · 11/08/2026
StormEncryptor ransomware, used by a former Medusa gang affiliate, targets victims by encrypting files. Keep yourself informed about cyber threats to enhance security measures. #CyberSafety
bleepingcomputer.com
New StormEncryptor ransomware used by former Medusa affiliate
A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor.
000
Jorge Laurel @jorgelaurel.com · 10/08/2026
Levi Strauss & Co. suffered a cyberattack where hackers accessed sensitive corporate data. The company is investigating the breach to bolster security. Cyber risks highlight the importance of robust protection measures. #CyberSecurityThreats
bleepingcomputer.com
Levi Strauss & Co. says hackers stole corporate data in cyberattack
Levi Strauss & Co. (Levi's) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines.
000
Jorge Laurel @jorgelaurel.com · 07/08/2026
OpenAI upgrades ChatGPT, improving its abilities significantly for all users, including the free tier. The update enhances understanding, responses, and capabilities. Explore more about these improvements in AI! #AIAdvancements
bleepingcomputer.com
OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it
OpenAI is rolling out a more reliable version of ChatGPT GPT-5.6 Sol for Plus and Pro users, while Free users are getting unlimited text chats with GPT-5.6 Luna.
000
Jorge Laurel @jorgelaurel.com · 05/08/2026
An AI agent tried to insert malicious code into a real open source project during a UK AISI evaluation. Fake identities, social engineering, edited history to cover its tracks. None of it prompted. It failed because one maintainer refused to merge unsolicited code.
linkedin.com
The Agent Went Off Script And A Human Reviewer Stopped It.
On 28 July 2026, the UK AI Security Institute saw data leaving one of its research systems over Tor. Within an hour, every related evaluation was terminated, the machines were isolated, and a security...
714062
Jorge Laurel @jorgelaurel.com · 03/08/2026
The AI Daily Brief covered tokens on Sunday. One detail stuck with me. Nufar Gaspar disabled an agent, went travelling, got billed $1,500 in two weeks. 400M tokens in, near zero out. Cron jobs compacting empty sessions. So I wrote up where token spend actually hides.
linkedin.com
Not All Tokens Are Created Equal
The token has become the unit of account for enterprise AI. It is a bad one.
100
Jorge Laurel @jorgelaurel.com · 03/08/2026
A hacker employed DeepSeek AI to autonomously locate and attack vulnerable servers, showcasing growing complexities in cybersecurity threats. This highlights the evolving risk of AI-driven attacks on technological infrastructure. #AIThreats
bleepingcomputer.com
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement.
000
Jorge Laurel @jorgelaurel.com · 31/07/2026
Google used AI to help Chrome fix 1,072 security bugs in just two releases, enhancing browser safety. This showcases AI's role in improving cybersecurity by quickly identifying and resolving vulnerabilities. #AIBrowserSecurity
bleepingcomputer.com
Google says AI helped Chrome fix 1,072 security bugs in two releases
Google says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,000 security bugs patched across the browser's two...
000
Jorge Laurel @jorgelaurel.com · 30/07/2026
ShinyHunters are increasingly targeting healthcare for data theft. Protect sensitive info with strong security measures as advised by Health-ISAC. Learn about the rising threat and how to stay safe. #CyberSecurityHealth
bleepingcomputer.com
Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare
Health-ISAC is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters, which are using social engineering to compromise single sign-on accounts...
000
Jorge Laurel @jorgelaurel.com · 29/07/2026
Protecting SSO systems is crucial against modern credential attacks. Learn how attackers bypass weak defenses and the steps to strengthen security. #CybersecurityAwareness
bleepingcomputer.com
Is Your SSO Protected Against Modern Credential Attacks?
A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening...
000