Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations

2026-07-07T01:24:10Z2d719394ea220f63d7fa01648e6ceb7969cc7a1508db11492817f9f459f2df75
Avalon malwareBad EpollCVE-2025-5777CVE-2026-20896CVE-2026-46242CVE-2026-53359Cavern/Cav3rnCitrix Bleed 2CrownX ransomwareFatFs vulnerabilitiesGiteaJanuscapeKVM guest escapeNetNut/PopaPamStealerPolinRiderQuimaRATSkillCloakTrojPixUmbrijair-gap exfiltrationransomwaresupply-chain attacksthreat-actors

What happened

A roundup of mid-2026 cyber news: an Iran-linked group is using a new modular C2 called Cavern/Cav3rn to target Israeli orgs; researchers disclosed a KVM guest-to-host use-after-free (Januscape, CVE-2026-53359) that can panic hosts and may allow escapes; threat actors probed the critical Gitea Docker header-trust flaw (CVE-2026-20896) soon after patching; a local root Linux/Android escalation (Bad Epoll, CVE-2026-46242) was published and fixed. The feed also highlights exploitation of Citrix Bleed 2 (CVE-2025-5777) in ransomware campaigns, seven unpatched FatFs vulnerabilities affecting many嵌d

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
2d719394ea220f63d7fa01648e6ceb7969cc7a1508db11492817f9f459f2df75
Enrichment time
2026-07-07T01:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations · Baitaphish