VoidLink is a malware family tracked across 12 threat clusters and 31 intelligence report mentions on ThreatCluster. First observed January 13, 2026; most recent activity May 1, 2026.
A newly disclosed vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named 'Copy Fail', allows unprivileged local users to gain root access on virtually all major Linux distributions released since 2017.…
The VoidLink malware framework, discovered in early 2026, represents a significant advancement in AI-assisted malware development, transitioning from theoretical discussions to a fully operational threat. Built by a…
The VoidLink rootkit has been identified as a significant threat to Linux systems, utilizing a combination of Loadable Kernel Modules (LKMs) and extended Berkeley Packet Filter (eBPF) programs for stealthy infiltration.…
A new malware framework named VoidLink has emerged, specifically targeting Linux systems in cloud environments. It utilizes advanced evasion techniques and self-deletion capabilities, and is written in the Zig…
VoidLink is a newly discovered Linux malware framework that targets cloud environments, featuring 37 plugins and advanced capabilities. It is believed to have been developed by a single individual using artificial…
VoidLink is a Linux-based command-and-control framework identified for long-term intrusions in cloud and enterprise environments. The malware is designed for credential theft, data exfiltration, and stealthy persistence…
The emergence of VoidLink marks a significant development in cybersecurity, being the first advanced malware framework almost entirely created by artificial intelligence. This new malware allows sophisticated threat…
In December 2025, Check Point Research identified a new malware framework named VoidLink, originating from a Chinese-speaking development environment. The malware consists of Linux samples that appear to be in-progress…
VoidLink, a new malware, has been developed using artificial intelligence, allowing it to evolve rapidly. The development process mimicked the work of a full development team, indicating a significant advancement in…
AI assistants like Grok and Microsoft Copilot can be exploited to serve as covert command-and-control (C2) channels for cybercriminals. These platforms can be manipulated to fetch attacker-controlled URLs, allowing…