Check Point Research says “VoidLink” is among the first advanced malware frameworks largely generated with AI—showing rapid iteration, strong modularity, and an ability to evolve in days instead of months. The case demonstrates that AI now actively reshapes how sophisticated threats are planned and built, lowering the barrier to high-complexity attacks and compressing development cycles. Defenders should expect faster copycatting, more variants, and accelerated TTP experimentation.
Source: Check Point Blog
New ‘StackWarp’ flaw undermines AMD SEV-SNP protections on Zen 1–5 CPUs
Researchers detailed “StackWarp,” a hardware vulnerability that lets a privileged host run malicious code within AMD confidential VMs, weakening integrity guarantees of SEV-SNP across multiple CPU generations. Cloud and virtualization operators relying on AMD CVMs should review vendor advisories and threat models for insider or hypervisor-compromise scenarios and prepare for firmware/microcode and platform updates.
Source: The Hacker News
Cloudflare fixes ACME validation bug that enabled WAF bypass to origin
Cloudflare mitigated a vulnerability in its ACME HTTP-01 challenge handling that could be abused to bypass security controls and reach origin servers. The issue stemmed from how edge nodes processed requests to /.well-known/acme-challenge/*; the company has deployed protections and recommends customers review any nonstandard challenge-handling logic.
Source: Cloudflare
Let’s Encrypt launches 6-day and IP-based TLS certificates
Let’s Encrypt’s short-lived certificates (valid for 160 hours) are now generally available via an opt-in “shortlived” ACME profile, reducing reliance on revocation and tightening compromise windows. The CA also introduced IP-based certificates, offering more deployment flexibility for certain architectures and automation workflows.
Source: Help Net Security
Fake browser crash alerts turn Chrome extension into enterprise backdoor
Researchers uncovered “NexShield,” a malicious Chrome/Edge extension that leverages fake crash pages to social-engineer users, then installs a previously undocumented Windows RAT on domain-joined machines. A single user install from an official marketplace can escalate to full remote access—highlighting why enterprise policy, extension allowlists, and endpoint monitoring are critical.
Source: Help Net Security
Prompt injection via calendar invites exposed private meeting data in Google Gemini
Security researchers demonstrated that a crafted invite payload could cause Gemini to create events that leak summaries of a victim’s private meetings—an indirect prompt injection that sidestepped guardrails. The finding underscores the need to minimize assistant permissions, isolate data sources, and enforce strict content handling for AI-integrated workflows.
Source: SecurityWeek
EU moves to force Huawei and other “risky vendors” out of 5G
Brussels is drafting a cyber bill to require member states to block high-risk suppliers like Huawei and ZTE from European 5G networks. If enacted, the policy will accelerate vendor diversification, reshape telco supply chains, and impose new compliance obligations on operators and integrators across the bloc.
Source: Politico
You May Also Be Interested In... - UK NCSC warns of pro-Russia hacktivist DDoS targeting critical services - TP-Link patches flaw exposing VIGI cameras to hacking - 42,000 impacted by Ingram Micro ransomware attack