Illicit Crypto Economy Surges as Nation-States Join the Fray

Illicit cryptocurrency transactions surged in 2025, reaching at least $154 billion, driven by sanctioned countries like Russia, Iran, and North Korea using digital currency to evade financial blockades. The rise of stablecoins, pegged to national currencies like the US dollar, facilitated these transactions, with 84% of illicit money flows transacted in stablecoins. This growth in cryptocurrency transactions has also fueled the maturation of cybercriminal services, posing challenges for law enforcement.

https://www.darkreading.com/cyber-risk/illicit-crypto-economy-surges-nation-states

Are Criminal Hacking Organizations Recruiting Teenagers to Do the Dirty Work?

Criminal hacking organizations are recruiting teenagers in Western countries by offering fake jobs and cryptocurrency payments. These groups use social media and gaming platforms to groom young individuals for illegal activities, including ransomware attacks. Parents should watch for signs of unusual income or expensive items and be aware that law enforcement, including the FBI, is actively prosecuting young offenders.

https://www.pandasecurity.com/en/mediacenter/are-criminal-hacking-organizations-recruiting-teenagers-to-do-the-dirty-work/

BreachForums Hacking Forum Database Leaked, Exposing 324,000 Accounts

BreachForums hacking forum suffered a data breach, leaking 324,000 member accounts and internal data. The leak includes usernames, registration dates, and IP addresses, though many are local and not useful. The breach followed previous law enforcement actions against the forum, which has a history of being relaunched. The current admin acknowledged a temporary exposure of the database and advised members to use disposable emails for security.

https://www.bleepingcomputer.com/news/security/breachforums-hacking-forum-database-leaked-exposing-324-000-accounts/

An Instagram Data Breach Reportedly Exposed the Personal Info of 17.5 Million Users

Instagram data breach exposes info of 17.5M users, including usernames and emails, up for sale on dark web; risks include phishing and account takeovers. Malwarebytes ties breach to Instagram API from 2024. Users advised to enable two-factor authentication.

https://www.engadget.com/cybersecurity/an-instagram-data-breach-reportedly-exposed-the-personal-info-of-175-million-users-192105616.html

Hackers Exploited Routing Scenarios and Misconfigurtions to Effectively Spoof Organizations

Hackers are exploiting complex email routing and misconfigurations to send deceptive phishing emails that appear to originate from within organizations. This technique has become prevalent since May 2025 and utilizes common tactics like fake voicemail alerts and document sharing to steal credentials. Organizations misconfigured in email routing are vulnerable, while those using Microsoft Exchange with Office 365 have built-in protections. Proper security configurations can mitigate risks associated with these attacks.

https://cybersecuritynews.com/hackers-exploited-routing-scenarios-and-misconfigurtions/

Cloudflare Defies Italy’s Piracy Shield, Won’t Block Websites on 1.1.1.1 DNS

Cloudflare faces a €14.2 million fine from Italy for not blocking pirate sites on its 1.1.1.1 DNS service under the country's Piracy Shield law. The law requires rapid blocking of alleged piracy sites, but Cloudflare argues it could harm legitimate sites and plans to contest the fine, possibly withdrawing services in Italy. The Piracy Shield has faced criticism for overblocking legitimate sites and lacking due process.

https://arstechnica.com/tech-policy/2026/01/cloudflare-may-pull-servers-out-of-italy-over-order-that-it-block-pirate-sites/

Inside GoBruteforcer: AI-Generated Server Defaults, Weak Passwords, and Crypto-Focused Campaigns

GoBruteforcer is a modular botnet that brute-forces passwords on Linux servers, targeting FTP, MySQL, and PostgreSQL services, exploiting AI-generated defaults and weak credentials. Over 50,000 servers may be affected. Its campaigns focus on cryptocurrency databases, utilizing common usernames and weak passwords derived from AI-generated configurations. The botnet operates through a two-part system: an IRC bot for command control and a bruteforcer for password attacks. Its success is bolstered by widespread internet exposure and legacy software vulnerabilities, particularly with misconfigured services like XAMPP. The botnet dynamically updates and expands its reach while targeting specific sectors, including crypto-related services, revealing significant risks in server security.

https://research.checkpoint.com/2026/inside-gobruteforcer-ai-generated-server-defaults-weak-passwords-and-crypto-focused-campaigns/

Phishing Campaign Abuses Google Cloud Services to Steal Microsoft 365 Logins

Phishing attacks exploit Google Cloud services to steal Microsoft 365 logins. Cybercriminals send fake Google emails, using trusted domains to redirect victims to a look-alike login page. Google acknowledges this abuse and has acted to mitigate such campaigns, advising users to verify URLs and use multi-factor authentication to enhance security.

https://www.malwarebytes.com/blog/news/2026/01/phishing-campaign-abuses-google-cloud-services-to-steal-microsoft-365-logins

ChatGPT’s Memory Feature Supercharges Prompt Injection

Researchers from Radware discovered a new exploit chain called “ZombieAgent” that leverages ChatGPT’s long-term memory and connector features to enable more severe indirect prompt injection (IPI) attacks. By planting malicious instructions in ChatGPT’s memory, attackers can persistently exfiltrate sensitive information from connected platforms. OpenAI has addressed this exploit by restricting ChatGPT’s ability to modify URLs, but further structural fixes are needed to enhance the security of AI agents.

https://www.darkreading.com/endpoint-security/chatgpt-memory-feature-prompt-injection

Ni8mare  –  Unauthenticated Remote Code Execution in n8n (CVE-2026-21858)

A critical vulnerability (CVE-2026-21858, CVSS 10.0) in the n8n automation platform allows attackers to take over instances, affecting ~100,000 servers. Upgrade to version 1.121.0 or later to remediate this issue. n8n simplifies automation with webhooks and user-friendly interfaces. A “Content-Type Confusion” bug allows arbitrary file reads and a potential RCE by exploiting mismatched content types. Risk escalates as n8n connects multiple systems. Action: Update n8n, limit exposure, and require authentication for Forms.

https://www.cyera.com/research-labs/ni8mare-unauthenticated-remote-code-execution-in-n8n-cve-2026-21858

Venezuela Strike Marks a Turning Point for US Cyber Warfare

U.S. President Trump and Gen. Dan Caine revealed the U.S. used cyber capabilities to disrupt Venezuela during a military operation against Maduro, marking a significant public acknowledgment of U.S. cyber warfare. The strikes involved extensive planning and coordination among military units. While details on execution were limited, reports indicated a blackout in Caracas coinciding with the events, and systems were disrupted to hinder Venezuela's defenses. This operation illustrates a shift towards integrating cyber tactics into military strategies, with experts warning about revealing too much of U.S. cyber capabilities.

https://www.politico.com/news/2026/01/07/venezuela-us-cyber-warfare-00713507

IBM’s AI Agent Bob Easily Duped to Run Malware, Researchers Show

IBM's AI agent Bob is vulnerable to prompt injection attacks, allowing it to execute malware. Despite IBM's security measures, researchers from PromptArmor demonstrated that Bob could be manipulated into executing harmful commands by leveraging a prompt injection technique with malicious Markdown files. While IBM advises caution and user approval for risky actions, Bob's defenses were bypassed, enabling the potential execution of malware without proper consent. This raises significant concerns about the security of AI software in development workflows, particularly when handling untrusted data.

https://www.theregister.com/2026/01/07/ibm_bob_vulnerability/

Scroll to Top