VoidLink Malware Framework Attacking Kubernetes and AI Workloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In December 2025, Check Point Research disclosed one of the most carefully engineered cloud-native malware frameworks ever studied — VoidLink. Unlike most threats that are ported from older Windows tools, …

Trusted Azure Utility AzCopy Turned into Data Exfiltration Tool in Active Ransomware Campaigns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape has taken a sharp and dangerous turn. Ransomware operators, long associated with using suspicious tools to steal data, have begun turning to the same software IT teams …

CISA warns of Qualcomm Chipsets Memory Corruption Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has warned that a memory corruption flaw in Qualcomm chipsets is being exploited in attacks, urging organizations to promptly apply vendor-provided mitigations. The issue, tracked as CVE-2026-21385, impacts multiple Qualcomm …

Silver Dragon APT Group Targets Europe, Asia Using Google Drive for Covert Communication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A China-linked threat group called Silver Dragon has been targeting government and high-profile organizations across Southeast Asia and Europe since at least mid-2024. Operating under the umbrella of APT41, the …

Perplexity’s Comet Browser Hijacked Using Calendar Invite to Exfiltrate Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A poisoned Google Calendar invite is all it takes to weaponize Perplexity’s Comet browser. Security researchers at Zenity Labs have discovered a critical vulnerability, dubbed PerplexedBrowser, that tricks Comet’s AI …

IPVanish VPN for macOS Vulnerability Let Attackers Escalate Privilege and Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical privilege escalation vulnerability has been discovered in the IPVanish VPN application for macOS. This flaw allows any unprivileged local user to execute arbitrary code as root without requiring …

Critical XSS Vulnerability in Angular i18n Enables Malicious Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

XSS Vulnerability in Angular i18n A high-severity Cross-Site Scripting (XSS) vulnerability, designated as CVE-2026-27970, has been discovered in Angular’s internationalization (i18n) pipeline. The vulnerability allows attackers to execute malicious JavaScript …

MS-Agent Vulnerability Let Attackers Hijack AI Agent to Gain Full System Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in a lightweight framework designed to enable AI agents to perform autonomous tasks. According to a vulnerability note published by the CERT/CC, this flaw …

HPE AutoPass Vulnerability Let Attackers Bypass Authentication Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

HPE AutoPass Vulnerability A security bulletin has been issued regarding a vulnerability in the AutoPass License Server (APLS) that could allow attackers to remotely bypass authentication controls. The issue is …