AboutDFIR.com – The Definitive Compendium Project
Digital Forensics & Incident Response

Blog Post

InfoSec News Nuggets 6/19/2025

Pro-Israel hackers drain $90 million from Iran crypto exchange, analytics firm says 

Iran’s largest cryptocurrency exchange, Nobitex, was hacked for more than $90 million Wednesday, according to blockchain analytics firm EllipticThe funds were drained from platform wallets into addresses bearing anti-government messages explicitly referencing Iran’s Islamic Revolutionary Guard Corps, or IRGC, pointing to a politically motivated cyberattack, Elliptic said. Pro-Israel hacking group Gonjeshke Darande, or “Predatory Sparrow,” claimed responsibility for the attack and said it would release the exchange’s source code. Elliptic said the exchange was offline at the time of its post. 

 

Amazon CISO: Iranian hacking crews ‘on high alert’ since Israel attack 

Iran’s state-sponsored cyber operatives and hacktivists have all increased their activities since the military conflict with Israel erupted last week – but not necessarily in the way that Amazon chief information security officer CJ Moses expected. Like most world powers and wannabes, Iran has a substantive crew of government-supported hackers who do all of the usual cyber dirty work for the state: espionagemeddling in elections , spear phishingstealing data and credentialsdeploying ransomware, and in some cases breaking into water utilities and other critical infrastructure. 

 

Researchers Warn of ‘Living off AI’ Attacks After PoC Exploits Atlassian’s AI Agent Protocol 

AI Agents hold great promise for IT ticketing services, but they also bring with them new risks. Researchers from Cato Networks have revealed that a new AI agent protocol released by Atlassian, a service desk solutions provider, could allow an attacker to submit a malicious support ticket through Jira Service Management (JSM) with a prompt injection. This proof-of-concept (PoC) attack conducted out by Cato’s team has been dubbed a ‘Living off AI’ attack. The researchers outlined the technical overview of the PoC attack in a new report shared exclusively with Infosecurity by the Cato CTRL Threat Research team on June 19. 

 

Krispy Kreme Confirms Data Breach After Ransomware Attack 

Krispy Kreme revealed being hit by a cyberattack on December 11, saying that the incident had led to operational disruptions. Roughly one week later, the Play ransomware group took credit for the attack, claiming to have stolen personal information, client documents, financial information, as well as other files related to accounting, contracts, payroll, and budget. The cybercriminals claimed to have stolen 184 Gb worth of data, which they made public on their Tor-based leak website in December 2024, after Krispy Kreme likely refused to pay a ransom. Krispy Kreme is now sending out data breach notification letters to individuals whose information was stolen as a result of the attack.  

 

Data Breach at Healthcare Services Firm Episource Impacts 5.4 Million People 

Healthcare services firm Episource has been targeted in a cyberattack that resulted in a data breach impacting more than 5.4 million individuals. Episource provides medical coding and risk adjustment services to doctors, health plans, and other types of healthcare organizations. The firm revealed in a data breach notice that it detected unauthorized access to its systems in early February. An investigation showed that “a cybercriminal” was able to view and copy data belonging to some Episource customers between January 27 and February 6, 2025.  

Related Posts