AboutDFIR.com – The Definitive Compendium Project
Digital Forensics & Incident Response

Blog Post

InfoSec News Nuggets 7/31/2025

California Finalizes Groundbreaking Regulations on AI, Risk Assessments, and Cybersecurity

After much anticipation, the California Privacy Protection Agency has finalized the regulations on automated decisionmaking technologies (ADMT), risk assessments, and cybersecurity audits pursuant to the California Consumer Privacy Act (CCPA), with staggered compliance timelines for each set of requirements. Although the final regulations removed all references to the term “artificial intelligence,” the ADMT provisions remain a groundbreaking attempt to regulate AI technologies—particularly those used to evaluate, monitor, or make decisions about individuals. This is the first installment in a three-part series discussing the new requirements under the CCPA’s new regulations. In this article, we focus exclusively on the new provisions governing the use of an ADMT. Future posts will provide a detailed examination of the CCPA’s requirements for risk assessments and cybersecurity audits.

 

Scammers Unleash Flood of Slick Online Gaming Sites

Fraudsters are flooding Discord and other social media platforms with ads for hundreds of polished online gaming and wagering websites that lure people with free credits and eventually abscond with any cryptocurrency funds deposited by players. Here’s a closer look at the social engineering tactics and remarkable traits of this sprawling network of more than 1,200 scam sites. The scam begins with deceptive ads posted on social media that claim the wagering sites are working in partnership with popular social media personalities, such as Mr. Beast, who recently launched a gaming business called Beast Games. The ads invariably state that by using a supplied “promo code,” interested players can claim a $2,500 credit on the advertised gaming website.

 

Amazon Ring Cashes in on Techno-Authoritarianism and Mass Surveillance

Ring founder Jamie Siminoff is back at the helm of the surveillance doorbell company, and with him is the surveillance-first-privacy-last approach that made Ring one of the most maligned tech devices. Not only is the company reintroducing new versions of old features which would allow police to request footage directly from Ring users, it is also introducing a new feature that would allow police to request live-stream access to people’s home security devices. 

 

In search of riches, hackers plant 4G-enabled Raspberry Pi in bank network

Hackers planted a Raspberry Pi equipped with a 4G modem in the network of an unnamed bank in an attempt to siphon money out of the financial institution’s ATM system, researchers reported Wednesday. The researchers with security firm Group-IB said the “unprecedented tactic allowed the attackers to bypass perimeter defenses entirely.” The hackers combined the physical intrusion with remote access malware that used another novel technique to conceal itself, even from sophisticated forensic tools. The technique, known as a Linux bind mount, is used in IT administration but had never been seen used by threat actors. The trick allowed the malware to operate similarly to a rootkit, which uses advanced techniques to hide itself from the operating system it runs on.

 

Insurance won’t cover $5M in City of Hamilton claims for cyberattack, citing lack of log-in security

Many City of Hamilton departments didn’t have multi-factor authentication in place before cyber criminals launched a massive ransomware attack in February 2024, paralysing nearly all municipal services for weeks. Multi-factor authentication, also sometimes in the form of two-step verification, is a widely used layer of extra security for users logging into a system like their email accounts. They’re required to verify their identity using more than one method, such as entering a code texted to their phone. It’s been used by corporations and technology companies for years. Google, for example, launched its two-step log-in system in 2011. 

 

ChatGPT conversations are showing up on Google, internet users shocked

If you’ve ever shared a ChatGPT conversation using the “Share” button, there’s a chance it might now be floating around somewhere on Google, just a few keystrokes away from complete strangers. A growing number of internet sleuths are discovering that ChatGPT’s shared links, which were originally designed for collaboration, are getting indexed by search engines. Shared links are ChatGPT features that allow users to generate a unique URL for a ChatGPT conversation. The shared chat becomes accessible to anyone with the link. However, if you share the URL on social media, a website, or if someone else shares it, it can be noticed by Google crawlers.

Related Posts