Cybersecurity News | Daily Recap [17 Jan 2026]

Cybersecurity News | Daily Recap [17 Jan 2026]

Daily Recap, Gootloader now uses 1,000-part ZIP archives to evade detection and deliver payloads, while the Kimwolf botnet has infected roughly 2 million devices. Daily Recap, DeadLock leverages Polygon smart contracts to rotate proxies and obscure infrastructure, with further coverage on Modular DS WordPress exploits, AWS CodeBuild misconfigurations, StackWarp on AMD processors, Reprompt attacks against Microsoft Copilot, RedVDS seizures, Grubhub breach, and leadership shifts around the RSA Conference. #Gootloader #DeadLock

Malware & Botnets

  • Stealthy loader Gootloader now uses 1,000-part ZIP archives to evade detection and deliver payloads – Gootloader ZIP
  • Fast-growing Kimwolf botnet has infected roughly 2M devices, alarming security researchers about its rapid spread – Kimwolf Rise
  • Ransomware DeadLock leverages Polygon smart contracts for proxy rotation to obscure infrastructure and evade takedown – DeadLock Polygon

Vulnerabilities & Exploits

  • Critical WordPress Modular DS plugin flaw is being actively exploited to gain admin access – Modular DS, Modular DS
  • Misconfigured AWS CodeBuild pipelines exposed private GitHub repositories, opening risks for supply-chain attacks – AWS CodeBuild
  • New β€˜StackWarpβ€˜ attack threatens confidentiality of VMs on AMD processors, raising cloud isolation concerns – StackWarp AMD

AI Risks & Defenses

  • Researchers reveal a β€˜Repromptβ€˜ attack that enables single-click exfiltration from Microsoft Copilot, silently siphoning data – Reprompt Attack, Reprompt Attack
  • AI agents easily execute SQLi but fail on security controls in testing, underscoring automation risk tradeoffs – Vibe Coding
  • Startup isVerified emerges with voice deepfake detection apps to combat synthetic audio threats – isVerified Launch

Incidents & Enforcement

  • Microsoft seized infrastructure linked to the cybercrime marketplace RedVDS, disrupting a fast-growing criminal service – RedVDS Seizure
  • Food delivery firm Grubhub confirms hackers stole customer data in a recent security breach – Grubhub Breach
  • Anchorage Police Department took servers offline after a cyberattack on a third-party service provider, impacting operations – Anchorage Attack

Policy, Partnerships & Leadership

  • Germany and Israel deepen cybersecurity ties with a new pact to boost cooperation, knowledge exchange, and joint cyber-defense development – Germany-Israel
  • Sources say DHS is finalizing a replacement for the disbanded critical-infrastructure security council to reshape oversight and stakeholder coordination – DHS Replacement
  • Chinese hackers are targeting β€˜high value’ North American critical infrastructure, per Cisco Talos reporting – China Targeting
  • NSA/Cyber Command nominee defended his record during a Senate hearing amid scrutiny over cyber policy and readiness – NSA Nominee
  • Jen Easterly will lead ambitious expansion plans for the RSA Conference, signaling strategic shifts for the event – Jen Easterly

Industry & Market

  • Depthfirst raised $40 Million to scale its vulnerability-management platform and services – Depthfirst Raise
  • Google rolls out the option to change your @gmail.com address, adding account-name flexibility for users – Gmail Change
  • Security leaders stress practical priorities over predictions for 2026, focusing on resilience, supply-chain security, and automation controls – 2026 Priorities

Cybersecurity News | Daily Recap – hendryadrian.com