lol there’s no real technical details in this article sadly. Checkpoint has a better analysis.
https://research.checkpoint.com/2026/voidlink-the-cloud-nati...
Some kind of opensource ish malware framework the kids are running that can use eBPF …. In addition to limiting CAP_BPF or CAP_SYS_ADMIN you should also take other measures.