> InfoSec News Nuggets 10/08/2025
[AUTHOR: Mary]
[DATE: 08/10/2025 13:45]
[LANGUAGE: EN]
Foreign threat actors adopting ChatGPT to bolster “old playbook” of attacks, OpenAI finds
But, in what may be considered good news for security teams, the AI start-up also says most threat actors appear to be playing it safe and sticking with “tried and true” methods previously used to carry out their attacks. “We continue to see threat actors bolt AI onto old playbooks to move faster, not gain novel offensive capability from our models,” the company said in a security blog published on Tuesday. The latest observations are documented in OpenAI’s newly released 3rd quarter security report, “Disrupting malicious uses of AI: an update.”
ICE bought vehicles equipped with fake cell towers to spy on phones
U.S. Immigration and Customs Enforcement (ICE) paid $825,000 earlier this year to a company that manufactures vehicles equipped with various technologies for law enforcement, including fake cellphone towers known as “cell-site simulators,” which can be used to spy on nearby phones. According to public records, the award dated May 8 “provides Cell Site Simulator (CSS) Vehicles to support the Homeland Security Technical Operations program” and is a modification for “additional CSS Vehicles.”
Open-source monitor turns into an off-the-shelf attack beacon
China-affiliated hackers have quietly turned a once-benign open-source network monitoring tool into a remote access beacon. According to new findings from cybersecurity firm Huntress, the attackers used log poisoning and a web shell to install Nezha, a legitimate remote monitoring/management tool (RMM), as a foothold to deploy Ghost RAT for deeper persistence. “To our knowledge, this is the first public reporting of Nezha being used to facilitate web compromises,” Huntress researchers Jai Minton, James Northey, and Alden Schmidt, said in a blog post shared with CSO ahead of its publication on Wednesday.
Salesforce Refuses to Pay Ransom to Data-Stealing Hackers
Salesforce reportedly is refusing to pay a ransom demanded by hackers who claim to have stolen more than 1 billion data files in attacks on customers of the software-as-a-service (SaaS) company. According to Bloomberg, Salesforce this week sent emails to dozens of customers affected by the attacks by the threat group Scattered Lapsus$ Hunters, saying it wouldn’t pay any extortion demands and warning that “credible” threat intelligence indicated that the bad actors intended to publish the data they had stolen. The threat group earlier this month listed on a since-shut-down data leak site that it had stolen data – including driver’s licenses, dates of birth, and Social Security numbers – from more than three dozen high-profile companies, including Cisco, Google, Toyota, Home Depot, Marriot and Disney/Hulu, and threatened to publicly release it unless Salesforce negotiated a ransom payment.
Police arrest two suspects in connection with nursery cyber attack
Detectives with London’s Metropolitan Police (Met) investigating reports of a cyber attack on a chain of London-based nurseries have made two arrests. Hackers stole the names and photos of 8,000 children from the Kido nursery chain, posted 10 profiles online and threatened to publish more unless a ransom was paid in Bitcoin. After a backlash, the hackers blurred the images of the children then eventually took them down, claiming to have deleted to rest of the stolen data.
The post InfoSec News Nuggets 10/08/2025 appeared first on AboutDFIR - The Definitive Compendium Project.