CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (8 January 2026)

Published: Loading…

At a Glance

  • Attackers actively exploited a critical command injection flaw, CVE-2026-0625, in legacy D-Link DSL routers via the dnscfg.cgi endpoint.
  • Veeam patched multiple Backup & Replication flaws, including CVE-2025-59470, a critical remote code execution vulnerability with CVSS 9.0.
  • Open-source automation platform n8n disclosed maximum-severity RCE flaws CVE-2026-21877 and CVE-2026-21858, allowing authenticated or unauthenticated server takeover.
  • The Crimson Collective extortion group claimed theft of sensitive PII from over one million Brightspeed residential broadband customers across 20 US states.
  • Suspected Russian attackers used fake Booking.com emails and a spoofed Blue Screen of Death to deliver DCRat malware to hospitality staff.

Summary

Multiple critical vulnerabilities were disclosed and exploited across widely deployed infrastructure software, including D-Link DSL routers, Veeam Backup & Replication, and n8n workflow automation platforms. Several flaws enabled unauthenticated or low-privilege remote code execution with CVSS scores ranging from 9.0 to 10.0.

Exploitation of unsupported or legacy network devices intensified, with attackers abusing zero-day command injection flaws in discontinued D-Link hardware. Similar device-level weaknesses were reported in Totolink range extenders, allowing full device takeover through firmware handling errors.

Supply chain and software ecosystem risks persisted as npm announced staged publishing controls following the Shai-Hulud campaign. A critical flaw in the jsPDF JavaScript library enabled attackers to exfiltrate local filesystem data through crafted PDF generation.

Extortion and data theft incidents affected telecommunications and public sector organisations, including Brightspeed, European Space Agency, and Illinois Department of Human Services. Exposed datasets included extensive personally identifiable information and internal records.

Phishing and malware delivery campaigns targeted specific industries and regions using tailored lures. Fake Booking.com emails delivered DCRat malware to hospitality staff, while misconfigured email routing enabled internal domain spoofing leveraged by phishing-as-a-service platforms.

Botnet and credential-based attacks expanded against poorly secured servers and cloud environments. The GoBruteforcer botnet exploited weak defaults on Linux servers, while threat actor Zestix breached around 50 enterprises lacking multi-factor authentication.

Highlights of the Day

Veeam fixes critical backup software code execution flaw

Veeam has released updates for Backup & Replication addressing four vulnerabilities, including a critical remote code execution flaw tracked as CVE-2025-59470. The issues affect version 13 builds prior to 13.0.1.1071 and could allow highly privileged users to execute code as system-level accounts through crafted parameters or configuration files.

n8n discloses maximum-severity code execution vulnerability

The workflow automation platform n8n has disclosed a maximum-severity remote code execution flaw that allows authenticated users to run untrusted code and fully compromise affected instances. Tracked as CVE-2026-21877, the issue affects both self-hosted deployments and n8n Cloud versions prior to 1.121.3, where it has been resolved.

Extortion group claims theft of Brightspeed customer data

US broadband provider Brightspeed is investigating claims by the Crimson Collective extortion group that data from more than one million residential customers was stolen. The alleged dataset includes extensive personal, account, billing and payment information, with a limited sample shared publicly by the group while the company continues its investigation.

GoBruteforcer botnet exploits weak server credentials at scale

Check Point Research has detailed a renewed GoBruteforcer botnet campaign targeting internet-exposed Linux servers using weak and reused credentials across FTP, database services and phpMyAdmin. The activity is linked to widespread reuse of default configurations, including those generated by AI tools and legacy server stacks, and includes financially motivated attacks against cryptocurrency and blockchain projects.

ESXi VM escape exploits observed in live intrusions

Huntress has documented active exploitation of VMware ESXi hypervisors using a sophisticated virtual machine escape toolkit observed during a real-world intrusion. The attack chain combined compromised VPN access, guest-to-host escape techniques and previously disclosed ESXi vulnerabilities to gain control of the hypervisor and deploy a stealthy backdoor.

Source: Huntress

Daily Coverage

Developments
D-Link Router ExploitationVeeam Rce PatchesN8N Ni8Mare FlawBrightspeed Extortion
Vulnerabilities
CVE-2026-21858N8N < 1.121.0 (Critical)CVE-2025-37164Hpe Oneview (Critical)CVE-2009-0556N/A N/A (High)CVE-2025-66209Coolify < 4.0.0-Beta.451 (Critical)CVE-2026-20029Cisco Identity Services Engine Software 3.1.0 (Medium)CVE-2025-69258Trend Micro Apex Central 2019 (14.0) (Critical)CVE-2025-52691Smartermail Smartermail Versions Build 9406 And Earlier (Critical)CVE-2026-0625Dsl-2640B (Critical)CVE-2026-21877N8N < 1.121.3 (Critical)CVE-2025-59470
Threat Groups
PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.KimsukyKimsuky is a North Koreabased cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subjectmatter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Its operations have overlapped with other DPRK actors, likely due to ad hoc collaboration or limited resource sharing. Because of overlapping operations, some researchers group a wide range of North Korean statesponsored cyber activity under the broader Lazarus Group umbrella rather than tracking separate subgroup or cluster distinctions. Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019). In 2023, Kimsuky was observed using commercial large language models to assist with vulnerability research, scripting, social engineering and reconnaissance.