AboutDFIR.com – The Definitive Compendium Project
Digital Forensics & Incident Response

Blog Post

InfoSec News Nuggets 8/5/2025

Fashion giant Chanel hit in wave of Salesforce data theft attacks 

French fashion giant Chanel is the latest company to suffer a data breach in an ongoing wave of Salesforce data theft attacks. Chanel says the breach was first detected on July 25th after threat actors gained access to a Chanel database hosted at a third-party service provider, as first reported by WWDThe breach only impacted customers in the United States and exposed personal contact information. 

 

New state, local cyber grant rules prohibit spending on MS-ISAC 

The Department of Homeland Security on Friday published the notice of funding opportunity for the fourth and final year of the State and Local Cybersecurity Grant Program. Among the details explaining the latest round of funding for the $1 billion program is a stipulation that grantees may not spend their funds on services provided by the Multi-State Information Sharing and Analysis Center, a group that for more than 20 years has shared critical cybersecurity intelligence across state lines and provided software and other resources at free or heavily discounted rates. 

 

YouTube to Introduce AI-Powered Age Verification in the US 

With more and more U.S. states implementing age verification laws for social media and sites with adult content, YouTube is angling to get ahead of a potential federal law by implementing an AI-powered age verification system. The system will look at factors like watch history and account age to determine whether the account holder is under 18 years old, according to YouTube’s statement. If an account gets flagged, users will have to upload government-issued ID or a credit card to override the decision. 

 

LegalPwn Attack Tricks GenAI Tools Into Misclassifying Malware as Safe Code 

A new and unique cyberattack, dubbed LegalPwn, has been discovered by researchers at Pangea Labs, an AI security firm. This attack leverages a flaw in the programming of major generative AI tools, successfully tricking them into classifying dangerous malware as safe code. The research, shared with Hackread.com, reveals that these AI models, which are trained to respect legal-sounding text, can be manipulated by social engineering. The LegalPwn technique works by hiding malicious code within fake legal disclaimers. According to the research, twelve major AI models were tested, and most were found to be susceptible to this form of social engineering. 

 

New research shows Iran’s expansive cyber offensive during ‘12-Day War’ with Israel 

Within hours of June’s 12-day war between Iran and Israel erupting, Iranian state-backed hackers and proxy groups launched phishing campaigns, defaced websites and claimed to have leaked troves of stolen data tied to the conflict, according to new threat intelligence released Tuesday. Telegram also served as a central hub for recruitment, propaganda and orchestration of cyberattacks, according to some 250,000 messages exchanged by 178 Iranian proxy and hacktivist groups throughout the war that were analyzed by SecurityScorecard’s STRIKE threat intelligence team. 

Related Posts