Isometric network nodes highlighting critical cybersecurity vulnerabilities and exploits.

Daily Cybersecurity News - January 7, 2026

New Veeam Vulnerabilities Expose Backup Servers to RCE Attacks

Critical

Executive Summary

Veeam released security updates to patch multiple security flaws in its Backup & Replication software, including a critical remote code execution (RCE) vulnerability tracked as CVE-2025-59470. This vulnerability and others can allow attackers to perform RCE and other malicious activities; patches are available to remediate these issues.

Vulnerability Details

  • Affected Product: Veeam Backup & Replication 13.0.1.180 and all earlier version 13 builds
  • Identifier: CVE-2025-59470
  • CVSS Score: 9.0 (Critical)
  • Exploitation Status: No known active exploitation

Risk & Impact

  • Triage: Immediate patching is recommended for Veeam Backup & Replication version 13 users.
  • Attack Vector: A Backup or Tape Operator can achieve remote code execution as the postgres user by sending a malicious interval or order parameter.
  • Ease of Exploit: Requires Backup or Tape Operator credentials, making it High severity.

Action Plan

  • Immediate Action: Upgrade to Version 13.0.1.1071
  • Workaround: Follow Veeam's recommended Security Guidelines to reduce the opportunity for exploitability.
  • Detection: Monitor for suspicious activity related to Backup and Tape Operator roles and review user role assignments.

Relevant professional terms

Remote Code Execution (RCE)
A vulnerability that allows an attacker to execute arbitrary code on a target system.
CVSS Score
A numerical representation of the severity of a vulnerability, used to prioritize patching and mitigation efforts.
Critical

Executive Summary

A command injection vulnerability, identified as CVE-2026-0625, affects multiple D-Link DSL gateway routers that are no longer supported and is being actively exploited in the wild. The vulnerability allows unauthenticated remote attackers to inject and execute arbitrary shell commands.

Vulnerability Details

  • Affected Product: D-Link DSL routers including DSL-2640B (<= 1.07), DSL-2740R (< 1.17), DSL-2780B (<= 1.01.14), and DSL-526B (<= 2.01)
  • Identifier: CVE-2026-0625
  • CVSS Score: 9.3 (Critical)
  • Exploitation Status: Actively Exploited

Risk & Impact

  • Triage: Critical. Immediate action is required due to active exploitation.
  • Attack Vector: Remote, unauthenticated attackers can inject and execute arbitrary shell commands via the "dnscfg.cgi" endpoint due to improper sanitization of user-supplied DNS configuration parameters.
  • Ease of Exploit: Relatively low, as the vulnerability can be triggered remotely without authentication.

Action Plan

  • Immediate Action: Retire the affected devices and upgrade to actively supported devices with regular security updates. No patch will be released.
  • Workaround: There are no known workarounds. Discontinue use of the affected devices.
  • Detection: Monitor for suspicious activity and DNS modifications.

Relevant professional terms

Command Injection
An attack in which an attacker is able to execute arbitrary commands on a host operating system. This is typically achieved by exploiting vulnerabilities in an application that improperly handles user-supplied input.
Remote Code Execution (RCE)
The ability to execute arbitrary code on a remote device or system. This can allow an attacker to gain complete control over the compromised system.

Brightspeed Breach Exposes Customer Data

Executive Summary

The Crimson Collective claims to have stolen data from over one million Brightspeed customers, impacting their personal information. Brightspeed is currently investigating the alleged breach and claims made by the extortion group.

Attack Overview

  • Attack Path: The Crimson Collective compromised Brightspeed systems, gaining access to customer data.
  • Attacker: Crimson Collective.

Impact Assessment

  • Data Stolen: Customer data including names, email addresses, phone numbers, billing and service addresses, account status, and network details.

Strategic Takeaway

This breach highlights the persistent threat to telecommunications infrastructure and the sensitive data they hold, emphasizing the need for robust security measures.

Relevant professional terms

Data Exfiltration
The unauthorized transfer of data from a computer or other device.
Personally Identifiable Information (PII)
Any data that could potentially identify a specific individual.
Source: Malwarebytes

GoBruteforcer Targets Weak Server Credentials

Executive Summary

GoBruteforcer is a botnet targeting internet-exposed services on Linux servers, including phpMyAdmin, MySQL, PostgreSQL, and FTP, by brute-forcing user passwords. Compromised hosts are then incorporated into the botnet for scanning and further attacks.

Key TTPs

  • Initial Access: Brute-forcing weak or default passwords on exposed services.
  • Execution: Deploys IRC bots and PHP web shells for remote command execution.
  • Defense Evasion: Uses UPX packer to evade detection.

Campaign Analysis

The botnet leverages AI-generated server deployment examples with weak defaults and targets legacy web stacks. This campaign has successfully compromised crypto and blockchain project databases.

Targeting & Infrastructure

  • Target Profile: Internet-exposed Linux servers running phpMyAdmin, MySQL, PostgreSQL, and FTP services.
  • Infrastructure: Utilizes compromised servers as scanning and brute-forcing nodes, controlled via IRC bots and web shells.

Actionable Intelligence

  • IPs:5.253.84.159
  • Domains:fi.warmachine.su

Relevant Terms

  • Botnet: A network of computers infected with malware that are controlled by a single attacker.
  • Brute-Force Attack: A method of gaining access to a system by trying numerous username and password combinations.

Kimwolf Botnet Exploits Residential Proxies

Executive Summary

The Kimwolf botnet, an Android-based malware variant of Aisuru, has infected over two million devices by exploiting vulnerabilities within residential proxy networks. This botnet targets devices on internal networks, turning them into conduits for malicious traffic and DDoS attacks.

Key TTPs

  • Initial Access: Exploiting exposed Android Debug Bridge (ADB) services via residential proxies.
  • Execution: Installing malware through scanning infrastructure using residential proxies.
  • Defense Evasion: Using DNS over TLS (DoT) to hide communication and EtherHiding to resist takedowns.

Campaign Analysis

Kimwolf's rapid growth is attributed to targeting vulnerable devices through residential proxy networks, with many devices pre-infected. The botnet is used for DDoS attacks, selling residential proxy bandwidth, and app installs, highlighting the risks of unsecured proxy networks.

Targeting & Infrastructure

  • Target Profile: Unofficial Android TV boxes and streaming devices with exposed ADB services, primarily in Vietnam, Brazil, India, and Saudi Arabia.
  • Infrastructure: Over two million infected devices, utilizing residential proxies, with a significant portion linked to IPIDEA.

Actionable Intelligence

  • IPs: 85.234.91.247 (C2 Node).
  • Infected Devices: Over 2 million Android devices acting as residential proxy nodes.

Relevant Terms

  • Botnet: A network of computers infected with malware that can be controlled remotely to perform tasks such as DDoS attacks.
  • Residential Proxy: A proxy service that uses IP addresses from residential internet service providers to mask the user's actual IP address.

Taiwan Faces Escalating Cyberattacks on Energy Sector

Executive Summary

Taiwan's National Security Bureau (NSB) reported a tenfold increase in cyberattacks targeting the country's energy sector in 2025, signaling a significant escalation in China's cyber activity. These attacks are often synchronized with military activities, indicating a coordinated effort to undermine Taiwan's critical infrastructure.

Key Findings

  • Cyberattacks on Taiwan's energy sector increased by 1,000% in 2025 compared to the previous year.
  • Overall cyber incidents linked to China grew by 6%, with an average of 2.63 million attacks per day.
  • Emergency rescue and hospitals sectors experienced a 54% increase in cyberattacks.

The Bottom Line

The dramatic rise in cyberattacks against Taiwan's energy sector, coupled with coordinated timing alongside military activities, suggests a deliberate strategy to destabilize critical infrastructure. This poses a significant threat to national security and economic stability, requiring enhanced cybersecurity measures and international cooperation to counter these evolving hybrid warfare tactics. The focus on industrial control systems and software upgrade monitoring highlights the need for robust vulnerability management and supply chain security practices.

Relevant Terms

  • National Security Bureau (NSB): The principal intelligence agency of Taiwan, responsible for coordinating national security intelligence efforts and counterintelligence operations.
  • Energy Sector: Encompasses companies involved in the production and distribution of energy, including fossil fuels and renewables, critical for powering the economy.

pcTattletale Founder Pleads Guilty to Hacking

Executive Summary

The founder of pcTattletale, Bryan Fleming, pleaded guilty to federal charges related to computer hacking and advertising surveillance software. The guilty plea marks the first successful U.S. federal prosecution of a stalkerware operator in over a decade.

The Scheme

  • TTP 1: Developed and marketed stalkerware, pcTattletale, for monitoring computers and phones.
  • TTP 2: Promoted the software for spying on spouses and domestic partners.
  • TTP 3: Collected and stored screenshots and private data from victims' devices.

The Players

  • Facilitators Arrested:Bryan Fleming

The Consequence

  • Outcome: Bryan Fleming pleaded guilty to computer hacking and advertising surveillance software.

Strategic Takeaway

The successful prosecution signals increased legal consequences for developing and marketing stalkerware.

Relevant Terms

  • Stalkerware: Software designed to secretly monitor individuals without their knowledge or consent.
  • Data Breach: A security incident where sensitive, protected, or confidential data is copied, transmitted, viewed, stolen, or used by an individual unauthorized to do so.
Source: TechCrunch