CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (13 January 2026)

Published: Loading…

At a Glance

  • The University of Hawaii confirmed a ransomware attack on its Cancer Center exposed legacy research files, including Social Security numbers from 1990s cancer studies.
  • Illicit cryptocurrency activity reached USD 158 billion in 2025, driven by sanctions-linked flows, major hacks, and state-aligned actors using stablecoin infrastructure.
  • The GoBruteforcer botnet compromised tens of thousands of Linux servers by brute-forcing default credentials across FTP, databases, and phpMyAdmin services.
  • BreachForums suffered a database breach exposing records tied to roughly 324,000 user accounts, including administrators and long-time marketplace operators.
  • CISA ordered US agencies to patch an actively exploited Gogs remote code execution flaw used in zero-day attacks against development servers.

Summary

Healthcare and research institutions faced continued exposure after University of Hawaii Cancer Center disclosed a ransomware incident affecting historical research datasets. The breach involved encrypted systems and legacy participant identifiers, while clinical operations remained unaffected.

Illicit cryptocurrency activity expanded sharply, with USD 158 billion in flows recorded during 2025. Russia-linked sanctions activity, large-scale hacks, and state-aligned infrastructure contributed heavily to the increase, while illicit activity represented a smaller proportion of overall crypto volume.

Criminal infrastructure weaknesses were highlighted after BreachForums disclosed a database compromise impacting more than 324,000 accounts. The leak included administrator and moderator records, demonstrating operational security failures within established cybercrime marketplaces.

Automated attacks against exposed infrastructure continued through the GoBruteforcer botnet, which targeted Linux servers using reused default credentials. The campaigns extended into financially motivated activity, including theft operations against cryptocurrency and blockchain databases.

Software and platform vulnerabilities remained active targets, prompting CISA to mandate remediation of an exploited Gogs remote code execution flaw. Additional risks surfaced through unpatched n8n instances, malicious npm packages abusing community nodes, and critical vulnerabilities in enterprise security platforms.

Regulatory and platform security issues persisted alongside technical threats, with Meta patching an Instagram password reset flaw amid resurfaced scraped datasets. Authorities also advanced investigations into AI-generated sexual imagery, data brokerage practices, and alleged espionage involving government-linked IT consultants.

Highlights of the Day

Pig butchering scams scale through crime-as-a-service marketplaces

New research details how organised criminal groups are industrialising “pig butchering” scams through specialised service providers offering turnkey fraud tools, platforms, and infrastructure. The model mirrors malware-as-a-service, lowering barriers to entry and enabling large-scale operations spanning Southeast Asia, with losses increasingly reaching millions per network.

Major BreachForums database leak exposes nearly 324,000 users

A data breach of the BreachForums dark web marketplace has leaked records linked to almost 324,000 user accounts, including administrators and moderators, according to new analysis. The incident underscores that criminal platforms face similar security failures to legitimate services, while revealing the scale and geographic spread of actors using the forum.

Source: Resecurity

Illicit crypto flows hit record $158 billion in 2025

Illicit cryptocurrency activity reached an estimated USD 158 billion in 2025, marking a sharp rebound after several years of decline, according to new analysis. The increase was driven largely by sanctions-related activity linked to Russia, major hacks, and improved attribution, even as illicit transactions accounted for a slightly smaller share of overall crypto usage.

Source: TRM Labs

GoBruteforcer botnet exploits weak server defaults

Check Point Research has analysed an updated GoBruteforcer botnet that targets internet-exposed Linux servers by brute-forcing weak credentials on FTP, database services, and phpMyAdmin. The campaigns are fuelled by reused default usernames and passwords, including configurations copied from AI-generated deployment examples, and have compromised tens of thousands of servers. Researchers also observed financially motivated operations, including attacks on cryptocurrency and blockchain databases using specialised token-scanning and theft tools.

Instagram patches password reset flaw amid resurfaced data leak

Meta has confirmed and fixed an Instagram vulnerability that allowed third parties to trigger password reset emails, while stating no systems were breached. Separately, a dataset linked to over 17 million Instagram accounts circulated online, but researchers say the information originated from earlier scraping incidents and is not connected to the password reset issue.

Ransomware breach exposes legacy research data at Hawaii cancer centre

The University of Hawaii has disclosed a ransomware attack on its Cancer Center that compromised files from a single research project, including legacy records containing Social Security numbers. The incident, which occurred in August 2025, did not affect clinical operations, but delayed system restoration and investigation due to extensive encryption of affected systems.

Daily Coverage

Developments
Hawaii RansomwareRecord Crypto CrimeGobruteforcer BotnetBreachforums Leak
Vulnerabilities
CVE-2025-8110Improper Symbolic Link Handling In The Putcontents Api In Gogs Allows Local Execution Of Code.CVE-2025-12420Now Assist Ai Agents 5.0.26 (Critical)CVE-2026-20805Windows 10 Version 1809 10.0.17763.0 (Medium)CVE-2026-20822Windows 10 Version 1809 10.0.17763.0 (High)CVE-2026-20952Microsoft Office 2019 19.0.0 (High)CVE-2025-25249Fortiswitchmanager 7.2.2 (High)CVE-2026-20871Windows Server 2022 10.0.20348.0 (High)