Loading summary
A
The Apex Legends game is hacked again data about 17 million Instagram users put up for sale Indonesia blocks X over pornographic content and a ransomware attack hits a major Chilean energy provider this is the risky bulletin prepared by Catalyn Campanu and read by me, Amberly jack. Today is the 12th of January and this podcast episode is brought to you by cloud security company Prowler. In today's top story, Respawn Entertainment has patched an exploit in its game Apex Legends. The flaw allowed attackers to take over players in game characters. Last week the exploit was used against several Apex streamers. A similar exploit was used against the game in 2024 during a major tournament. A threat actor is selling data about more than 17 million Instagram users, according to Malwarebytes. The data contains names, phone numbers, emails and addresses. The details appear to have been scraped from one of Meta's APIs in 2024. The sale of the data coincides with a spike in fake Instagram password reset emails. Trans activists have hacked the website of the right wing British nonprofit the Free Speech Union. The Bash Back activist group says the organisation promotes transphobia and racism. The group defaced the organisation's website and leaked the names of donors. One of Chile's largest energy providers has fallen victim to a ransomware attack. The company COPEC confirmed the incident but said the attack did not impact the operations of its gas stations. The Anubis ransomware group took credit for the incident in a post on the Dark Web. Hackers have stolen $26 million worth of ether from the Truebit cryptocurrency platform. The attack exploited a mathematical vulnerability in one of the company's smart contracts. They minted new coins and sold them on the platform before being discovered. A threat actor has stolen more than $340,000 worth of crypto assets from Latin American fintech company Contigo. The company says it has since secured its systems and started repaying the 1,005 customers impacted by the hack. It also stopped a second attack three days after the initial intrusion. Hackers have breached Armenia's electronic civil litigation platform and leaked more than 8 million records. The data is currently for sale on underground hacking forums. The government confirmed the breach but has denied initial reports that the data came from its email servers. Ukrainian hackers wiped the networks of two Russian Internet service providers on New Year's Eve. Incidents were reported at Simstar in Crimea and Craft s in Samara. Hackers wiped routers, tacking down connectivity for several days. Ukrainian hacktivist group the BO Team has taken credit. Italy's communication watchdog has fined Cloudflare 14 million euros for refusing to block piracy sites on its 1.1.1.1 DNS service. The the fine represents 1% of the company's global revenue. Cloudflare argued that implementing a blocklist would have hurt performance. The Irish government has recalled 13,000 passports after a software update caused a printing error. Passports issued between December 23 and January 6 were missing. The Ireland country code officials said the cause was a technical issue with a software update. The Indonesian government has temporarily blocked access to social media platform X. Regulators across Asia and Europe have begun investigating the platform after the Grok AI feature was used to generate non consensual pornographic content. UK officials said they would also consider blocking X if Internet regulator Ofcom recommended it. According to Bloomberg, Grok is now the top source for non consensual AI generated nude images. Rather than disabling, Grok X has put it behind a paywall. Russian authorities have detained the former IT director of Sotrans, one of the country's largest transportation and logistics companies. Authorities believe 40 year old Anton Makhno was involved in a ransomware attack against the company in February last year. He was placed under house arrest in December. The attack was claimed by a group named Old Gremlins. They demanded a ransom of more than $4 million in Bitcoin. A 44 year old Dutch man has been sentenced to seven years in prison for deploying malware at the Belgian port of Antwerp. The man admitted to paying a port employee to install malware via a USB drive in 2020. Access to the port network was used to help import drugs into the country. His actions were discovered after Belgian and Dutch authorities seized the Sky ECC encrypted messaging service in 2021. Threat actors are scanning for misconfigured LLM servers A campaign Probing more than 70 AI large language model systems began late last year, according to security firm Greynoise. The scans originate from known malicious infrastructure. And finally, a major vulnerability has been patched in an academic platform used by more than 100 US universities. The flaw was an SQL injection vulnerability in the Bees Bete portal. It allowed attackers to modify test results or steal student data. The vulnerability received a 9.8 CVSS score and public proof of concept code is available. That's all for this podcast edition. Today's show was brought to you by our sponsor Prowler. Find them@prowler.com thanks to your company.
Date: January 12, 2026
Host: Amberly Jack (prepared by Catalyn Campanu)
Podcast: Risky Bulletin (Risky Business)
This episode focuses on recent high-impact cybersecurity incidents from around the world, notably a fresh exploit in “Apex Legends” hitting popular streamers, a massive Instagram user data sale, government interventions on social platforms, ransomware attacks, and newly discovered vulnerabilities in widely used academic and financial systems. The bulletin delivers concise, up-to-date briefings with a rapid-fire delivery of headline breaches, policy moves, and criminal prosecutions.
“The flaw allowed attackers to take over players in game characters. Last week the exploit was used against several Apex streamers.”
— Amberly Jack [00:14]
“The details appear to have been scraped from one of Meta’s APIs in 2024.”
— Amberly Jack [00:44]
“The company COPEC confirmed the incident but said the attack did not impact the operations of its gas stations.”
— Amberly Jack [01:31]
(On Grok AI generating non-consensual images:)
“According to Bloomberg, Grok is now the top source for non consensual AI generated nude images. Rather than disabling, Grok X has put it behind a paywall.”
— Amberly Jack [04:19]
The episode delivers a rapid roundup of fresh, high-consequence breaches and regulatory moves across gaming, social media, infrastructure, crypto, and academic sectors. The risk landscape in 2026 is shaped by sophisticated exploits (from Apex Legends to NFT platforms), evolving government interventions (content blocking, passport recalls), and the growing security impact of AI and LLM misconfigurations. Each news item provides a clear snapshot, often linking to broader trends in digital security and privacy.
Listeners come away with a timely, global perspective on today’s most urgent cybersecurity incidents.