CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (7 January 2026)

Published: Loading…

At a Glance

  • A critical path traversal flaw in @adonisjs/bodyparser, tracked as CVE-2026-21440, allows remote attackers to write arbitrary files on AdonisJS servers.
  • IBM confirmed CVE-2025-13915, a CVSS 9.8 authentication bypass in IBM API Connect, enabling unauthorised remote access without valid credentials.
  • A single infostealer-based campaign linked to one initial access broker exposed credentials from roughly 50 organisations lacking enforced multi-factor authentication.
  • The PHALT#BLYX ClickFix campaign used fake Booking.com messages and Windows BSOD lures to deliver DCRat malware across European hospitality organisations.
  • Ledger disclosed customer order and contact data exposure following a breach at ecommerce partner Global-e, prompting warnings of phishing activity.

Summary

Multiple critical software vulnerabilities were disclosed across development and automation platforms, including AdonisJS, n8n, and IBM API Connect. These flaws enable arbitrary file writes, system command execution, and authentication bypass affecting enterprise deployments.

Credential theft and resale remained prominent, with a single infostealer-linked access broker tied to breaches at dozens of organisations lacking enforced multi-factor authentication. A former Coinbase support agent was arrested in India for selling customer data to criminal groups.

The hospitality sector faced sustained malware activity through the PHALT#BLYX campaign, combining fake Booking.com emails and Windows BSOD lures. The attacks resulted in staff executing malicious code delivering DCRat remote access trojans.

Supply-chain and partner breaches continued to expose customer data, including Ledger confirming data access via ecommerce provider Global-e. Similar risks emerged from VS Code forks recommending missing Open VSX extensions susceptible to malicious takeover.

Public sector and national security impacts were reported, with UK schools and government bodies disrupted by cyber incidents amid a reset of UK cyber policy. Taiwan reported a tenfold increase in Chinese cyberattacks targeting its energy sector during 2025.

Highlights of the Day

Critical AdonisJS flaw allows arbitrary file writes

A critical path traversal vulnerability in the AdonisJS Bodyparser package allows remote attackers to write arbitrary files on affected servers. Tracked as CVE-2026-21440, the flaw stems from unsafe default handling of uploaded filenames and could enable file overwrites and, in some cases, remote code execution.

n8n flaw enables command execution by authenticated users

A critical vulnerability in the n8n workflow automation platform allows authenticated users to execute arbitrary system commands on the host. Tracked as CVE-2025-68668 with a CVSS score of 9.9, the issue stems from a sandbox bypass in the Pyodide-based Python Code Node and affects versions prior to 2.0.0.

IBM API Connect authentication bypass flaw flagged as critical

A critical authentication bypass vulnerability in IBM API Connect allows remote attackers to gain unauthorised access without valid credentials. Tracked as CVE-2025-13915 with a CVSS score of 9.8, the flaw affects multiple API Connect versions and impacts confidentiality, integrity, and availability.

NordVPN denies breach after alleged Salesforce data leak

NordVPN stated that recent claims of a Salesforce-related breach do not involve its internal systems or customer data. The company said the leaked files originated from a short-lived third-party testing environment containing only dummy data and never connected to production systems.

Source: NordVPN

Single threat actor tied to dozens of major breaches

A threat actor operating as Zestix, also linked to the persona Sentap, has been connected to dozens of major data breaches using stolen credentials. The actor functioned as an initial access broker, leveraging infostealer malware logs to compromise enterprise file-sharing services and sell stolen data or network access on underground forums.

Fake BSOD phishing delivers DCRat to hospitality sector

A malware campaign tracked as PHALT#BLYX is targeting hospitality organisations using phishing emails themed around Booking.com cancellations. The attacks rely on fake browser errors and Blue Screen of Death pages to trick users into executing malicious code, ultimately deploying the DCRat remote access trojan via trusted Windows build tools.

Source: Securonix

A command injection vulnerability tracked as CVE-2026-0625 is being actively exploited in multiple end-of-life D-Link DSL routers. The flaw allows unauthenticated remote command execution through improper input handling in a DNS configuration endpoint, with exploitation attempts observed on internet-facing devices.

jsPDF flaw exposes server files through generated PDFs

A critical path traversal vulnerability in jsPDF allows attackers to read arbitrary server-side files and embed their contents into generated PDFs. Tracked as CVE-2025-68428, the issue affects Node.js builds of the library and can expose configuration data, credentials, and other sensitive files when user-controlled paths reach vulnerable methods.

Source: Endor Labs

Daily Coverage

Developments
Adonisjs CVEIbm Api ConnectInfostealer BreachesHospitality Phishing
Vulnerabilities
CVE-2026-0625Dsl-2640B (Critical)CVE-2025-59470CVE-2026-21877N8N < 1.121.3 (Critical)CVE-2026-21858N8N < 1.121.0 (Critical)CVE-2025-69258Trend Micro Apex Central 2019 (14.0) (Critical)CVE-2025-13915Api Connect 10.0.8.0 (Critical)CVE-2025-68668CVE-2026-21440CVE-2025-68428