AboutDFIR.com – The Definitive Compendium Project
Digital Forensics & Incident Response

Blog Post

InfoSec News Nuggets 9/3/2025

Attackers Abuse Velociraptor Forensic Tool to Deploy Visual Studio Code for C2 Tunneling 

Cybersecurity researchers have called attention to a cyber attack in which unknown threat actors deployed an open-source endpoint monitoring and digital forensic tool called Velociraptor, illustrating ongoing abuse of legitimate software for malicious purposes. “In this incident, the threat actor used the tool to download and execute Visual Studio Code with the likely intention of creating a tunnel to an attacker-controlled command-and-control (C2) server,” the Sophos Counter Threat Unit Research Team said in a report published this week. 

 

Noem fires two dozen FEMA employees over alleged cybersecurity gaps 

Homeland Security Secretary Kristi Noem has fired two dozen Federal Emergency Management Agency IT employees, including top leaders, for allegedly neglecting security protocols and compromising sensitive data. A DHS press release Friday claims a routine cybersecurity review uncovered major vulnerabilities that allowed a “threat actor” to breach FEMA’s network. While the breach was detected before any sensitive data was extracted, an investigation found that security lapses enabled the intrusion, the release states. CNN has reached out to DHS, which oversees FEMA, for more details. 

 

Supply-chain attack hits Zscaler via Salesloft Drift, leaking customer info 

Zscaler discloses a data breach that is linked to the recent Salesloft Drift attack. The cybersecurity vendor confirmed it was affected by a campaign targeting Salesloft Drift, a marketing SaaS integrated with Salesforce. Threat actors stole OAuth tokens from the company, the incident impacted multiple Salesforce customers, including Zscaler. Attackers gained unauthorized access to Drift credentials, allowing limited visibility into some of Zscaler’s Salesforce information. The company pointed out that its products, services, and core infrastructure were not compromised. 

 

Palo Alto Networks data breach exposes customer info, support cases 

Palo Alto Networks suffered a data breach that exposed customer data and support cases after attackers abused compromised OAuth tokens from the Salesloft Drift breach to access its Salesforce instance. The company states that it was one of hundreds of companies affected by a supply-chain attack disclosed last week, in which threat actors abused the stolen authentication tokens to exfiltrate data. BleepingComputer learned of the breach this weekend from Palo Alto Networks’ customers, who expressed concern that the breach exposed sensitive information, such as IT information and passwords, shared in support cases. 

 

In the rush to adopt hot new tech, security is often forgotten. AI is no exception 

Cisco’s Talos security research team has found over 1,100 Ollama servers exposed to the public internet, where miscreants can use them to do nasty things. Ollama provides a framework that makes it possible to run large language models locally, on a desktop machine or server. Cisco decided to research it because, in the words of Senior Incident Response Architect Dr. Giannis Tziakouris, Ollama has “gained popularity for its ease of use and local deployment capabilities.” 

 

Bitcoin could be broken by quantum computers, El Salvador warns 

El Salvador has announced plans to split its vast bitcoin holdings into multiple wallets in order to protect against potential quantum attacks. The Central American country owns roughly half a billion pounds worth of the cryptocurrency, having introduced it as legal tender in 2021. The country’s Bitcoin Office said the move to split its holdings was part of a strategic initiative to “enhance the security and long-term custody” of its bitcoin reserve in the event of quantum computing advances. 

 

Cloudflare hit by data breach in Salesloft Drift supply chain attack 

Cloudflare is the latest company impacted in a recent string of Salesloft Drift breaches, part of a supply-chain attack disclosed last week. The internet giant revealed on Tuesday that the attackers gained access to a Salesforce instance it uses for internal customer case management and customer support, which contained 104 Cloudflare API tokens. Cloudflare was notified of the breach on August 23, and it alerted impacted customers of the incident on September 2. Before informing customers of the attack, it also rotated all 104 Cloudflare platform-issued tokens exfiltrated during the breach, even though it has yet to discover any suspicious activity linked to these tokens. 

 

Disney agrees to $10 million settlement for collecting data from children 

The Federal Trade Commission (FTC) on Tuesday announced Disney has agreed to pay $10 million to settle allegations that it collected personal data from children watching YouTube videos without parental notification or consent. Following a referral from the FTC, the Department of Justice filed a complaint alleging that Disney broke the Children’s Online Privacy Protection Rule (COPPA) by neglecting to label a “significant number” of videos it places on YouTube as “Made for Kids.” Targeted advertising is disabled on videos designated as intended for children. Disney’s actions allowed the children to be subjected to targeted advertising based on personal data collected without parental notice or consent, the complaint says.  

Related Posts