Varonis found a “Reprompt” attack that let a single link hijack Microsoft Copilot Personal sessions and exfiltrate data; Microsoft patched it in January 2026.
CyberArk exploited StealC’s control panel via source leak and XSS flaw Researchers exposed attacker “YouTubeTA,” who stole ...