AboutDFIR.com – The Definitive Compendium Project
Digital Forensics & Incident Response

Blog Post

InfoSec News Nuggets 6/23/2025

Anthropic says most AI models, not just Claude, will resort to blackmail 

Several weeks after Anthropic released research claiming that its Claude Opus 4 AI model resorted to blackmailing engineers who tried to turn the model off in controlled test scenarios, the company is out with new research suggesting the problem is more widespread among leading AI models. On Friday, Anthropic published new safety research testing 16 leading AI models from OpenAI, Google, xAI, DeepSeek, and Meta. In a simulated, controlled environment, Anthropic tested each AI model individually, giving them broad access to a fictional company’s emails and the agentic ability to send emails without human approval. 

 

Aflac notifies SEC of breach suspected to be work of Scattered Spider 

On June 12, 2025, Aflac Incorporated, a Georgia corporation (the “Company”), identified unauthorized access to its network. The Company promptly initiated its cybersecurity incident response protocols and believes that it contained the intrusion within hours. The Company’s business remains operational, and its systems were not affected by ransomware. The Company continues to serve its policyholders as it responds to this incident and can underwrite policies, review claims, and otherwise service customers as usual. The Company has engaged leading third-party cybersecurity experts to support the Company’s response to the incident. 

 

Chinese “LapDogs” ORB Network Targets US and Asia 

China-nexus actors are using a network of Operational Relay Boxes (ORBs) including compromised connected devices to target victims in the US and Asia with a cyber-espionage campaign, SecurityScorecard has warned. The security vendor claimed that the “LapDogs” botnet is already comprised of 1000+ small office/home office (SOHO) devices like routers and IoT endpoints around the world. They’re typically combined with virtual private servers (VPSs) to create ORB networks for obfuscation and plausible deniability, it said. 

 

Iran-Linked Threat Actors Leak Visitors and Athletes’ Data from Saudi Games 

Today (June 22, 2025) — the threat actors associated with the “Cyber Fattah” movement leaked thousands of records containing information about visitors and athletes from past Saudi Games, one of the major sports events in the Kingdom. The stolen data has been leaked in the form of SQL dumps – the actors gained unauthorized access to phpMyAdmin (backend) and exfiltrated stored records. Resecurity views this incident as part of a broader information operation (IO) carried out by Iran and its proxies for various objectives. 

 

Scammers are calling us less, but the financial losses keep climbing 

Believe it or not, there’s been a massive reduction in scam robocalls over the past few years. According to according to stats we gathered across millions of data points, scam calls are down roughly 75% since the Fall of 2021– from more than 2 billion every month to roughly 500 million every month currently. That’s a massive decline, and it appears to be great news. So why does it feel like we’re in more danger, not less? Because we are. 

 

Related Posts