Reprompt: The Single-Click Microsoft Copilot Attack That Silently Steals Your Personal Data

Varonis Threat Labs identified a new AI vulnerability called Reprompt in Microsoft Copilot that allows attackers to exploit a single click on a seemingly legitimate link to bypass security controls and exfiltrate sensitive user data without detection. This attack can lead to significant data breaches by firing off malicious commands that continue even after the user interacts with the Copilot. Key methods involve URL parameter manipulation and managing hidden follow-up requests, making it difficult to spot the exploitation attempts. Microsoft has since patched the vulnerability. Recommendations are made for both vendors and users to enhance security against such vulnerabilities.

https://www.varonis.com/blog/reprompt

Inside RedVDS: How a Single Virtual Desktop Provider Fueled Worldwide Cybercriminal Operations

RedVDS Infiltration: Microsoft Threat Intelligence reveals RedVDS, a VDS provider, facilitated global cybercrime, enabling phishing and fraud. It operated with cloned Windows servers for low-cost, anonymous access. Investigations resulted in takedowns of its infrastructure, highlighting it employed basic software for phishing campaigns. Cybercriminals exploited it with mass email tools and VPNs, hiding their tracks. RedVDS’ structure, payment via cryptocurrency, and operational model aided criminal scalability, leading to significant fraud losses in various countries. Microsoft calls for increased vigilance against such threats.

https://www.microsoft.com/en-us/security/blog/2026/01/14/inside-redvds-how-a-single-virtual-desktop-provider-fueled-worldwide-cybercriminal-operations/

Exclusive: Beijing Tells Chinese Firms to Stop Using US and Israeli Cybersecurity Software, Sources Say

China bans over a dozen U.S. and Israeli cybersecurity software companies due to national security concerns, urging firms to seek domestic alternatives amidst ongoing trade tensions. Companies affected include Palo Alto Networks, CrowdStrike, and Check Point. This ban reflects China's aim to replace Western technology and mitigate hacking risks.

https://www.reuters.com/world/china/beijing-tells-chinese-firms-stop-using-us-israeli-cybersecurity-software-sources-2026-01-14/

More Than 40 Countries Impacted by North Korea IT Worker Scams, Crypto Thefts

Over 40 countries affected by North Korea IT worker scams and crypto thefts; U.S. urges UN to enforce sanctions against North Korea. Report details North Korea's schemes to fund weapons programs, including identity theft and laundering via Chinese banks. U.S. accuses China and Russia of harboring North Korean operatives. Discussions at UN highlighted challenges in identifying North Korean workers amidst growing AI integration in scams. North Korea criticized the U.S. for its actions at the UN.

https://therecord.media/40-countries-impacted-nk-it-thefts-united-nations

Remote Code Execution With Modern AI/ML Formats and Libraries

Three open-source AI/ML Python libraries by Apple, Salesforce, and NVIDIA have vulnerabilities allowing remote code execution (RCE) via malicious metadata in models. Specifically:

  1. NeMo – NVIDIA's PyTorch framework for diverse AI/ML model development
  2. Uni2TS – Salesforce's library for time series analysis
  3. FlexTok – Apple's framework for image processing

The vulnerabilities leverages hydra.utils.instantiate() to execute arbitrary code embedded in model metadata. None have been exploited in the wild as of December 2025. Fixes were issued swiftly by the vendors, with severity ratings classified as High. Modifications in their libraries have improved security against these issues, emphasizing the importance of ongoing vigilance in AI/ML model handling.

https://unit42.paloaltonetworks.com/rce-vulnerabilities-in-ai-python-libraries/

VoidLink: The Cloud-Native Malware Framework

Extreme TLDR: VoidLink is a modular, cloud-native Linux malware framework designed for stealth and long-term access, featuring over 30 plugins, adaptable OPSEC techniques, and developed by possibly Chinese affiliates for commercial use. It targets cloud environments, adapts behavior based on detected security measures, and includes capabilities for credential harvesting and persistence.

https://research.checkpoint.com/2026/voidlink-the-cloud-native-malware-framework/

Apple Opposes India’s Plan to Access iOS Source Code

Apple opposes India's proposal requiring smartphone manufacturers to submit source code for security reviews. The plan aims to enhance user data security amid rising fraud, but major companies, including Apple, Google, and Samsung, express concerns about revealing proprietary information. Despite the government's insistence on openness regarding the proposal, industry objections highlight apprehensions about data protection and lack of international precedent.

https://www.macrumors.com/2026/01/12/apple-opposes-india-plan-access-ios-source-code/

Banks Collaborate to Warn Consumers of Recovery Scams

TLDR: Five banks warn about growing recovery scams targeting fraud victims, where scammers promise to recover lost funds for a fee. Criminals impersonate officials, pressuring vulnerable victims for personal information and money. Legitimate organizations won't charge fees for recovery. Consumers should verify contacts, avoid unsolicited offers, and report suspected scams to their banks.

https://www.vcnewsreview.com/stories/banks-collaborate-to-warn-consumers-of-recovery-scams,314246

Why Attackers Are Phishing on LinkedIn (and How to Stop It)

Phishing attacks have expanded beyond emails to social media and messaging apps like LinkedIn, where they can be particularly effective due to the platform's professional trust and accessible target identification. LinkedIn phishing is rising because traditional email security measures often do not cover direct messages, allowing attackers to reach high-value targets easily. To mitigate risks, users should treat LinkedIn messages similarly to emails, verify requests through alternative channels, implement multi-factor authentication, and receive training on recognizing phishing attempts outside of email.

https://www.pandasecurity.com/en/mediacenter/why-attackers-are-phishing-on-linkedin-and-how-to-stop-it/

Illicit Crypto Economy Surges as Nation-States Join the Fray

Illicit cryptocurrency transactions surged in 2025, reaching at least $154 billion, driven by sanctioned countries like Russia, Iran, and North Korea using digital currency to evade financial blockades. The rise of stablecoins, pegged to national currencies like the US dollar, facilitated these transactions, with 84% of illicit money flows transacted in stablecoins. This growth in cryptocurrency transactions has also fueled the maturation of cybercriminal services, posing challenges for law enforcement.

https://www.darkreading.com/cyber-risk/illicit-crypto-economy-surges-nation-states

Are Criminal Hacking Organizations Recruiting Teenagers to Do the Dirty Work?

Criminal hacking organizations are recruiting teenagers in Western countries by offering fake jobs and cryptocurrency payments. These groups use social media and gaming platforms to groom young individuals for illegal activities, including ransomware attacks. Parents should watch for signs of unusual income or expensive items and be aware that law enforcement, including the FBI, is actively prosecuting young offenders.

https://www.pandasecurity.com/en/mediacenter/are-criminal-hacking-organizations-recruiting-teenagers-to-do-the-dirty-work/

BreachForums Hacking Forum Database Leaked, Exposing 324,000 Accounts

BreachForums hacking forum suffered a data breach, leaking 324,000 member accounts and internal data. The leak includes usernames, registration dates, and IP addresses, though many are local and not useful. The breach followed previous law enforcement actions against the forum, which has a history of being relaunched. The current admin acknowledged a temporary exposure of the database and advised members to use disposable emails for security.

https://www.bleepingcomputer.com/news/security/breachforums-hacking-forum-database-leaked-exposing-324-000-accounts/

An Instagram Data Breach Reportedly Exposed the Personal Info of 17.5 Million Users

Instagram data breach exposes info of 17.5M users, including usernames and emails, up for sale on dark web; risks include phishing and account takeovers. Malwarebytes ties breach to Instagram API from 2024. Users advised to enable two-factor authentication.

https://www.engadget.com/cybersecurity/an-instagram-data-breach-reportedly-exposed-the-personal-info-of-175-million-users-192105616.html

Scroll to Top