Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
2026-07-07T01:24:10Z•2d719394ea220f63d7fa01648e6ceb7969cc7a1508db11492817f9f459f2df75
Avalon malwareBad EpollCVE-2025-5777CVE-2026-20896CVE-2026-46242CVE-2026-53359Cavern/Cav3rnCitrix Bleed 2CrownX ransomwareFatFs vulnerabilitiesGiteaJanuscapeKVM guest escapeNetNut/PopaPamStealerPolinRiderQuimaRATSkillCloakTrojPixUmbrijair-gap exfiltrationransomwaresupply-chain attacksthreat-actors
What happened
A roundup of mid-2026 cyber news: an Iran-linked group is using a new modular C2 called Cavern/Cav3rn to target Israeli orgs; researchers disclosed a KVM guest-to-host use-after-free (Januscape, CVE-2026-53359) that can panic hosts and may allow escapes; threat actors probed the critical Gitea Docker header-trust flaw (CVE-2026-20896) soon after patching; a local root Linux/Android escalation (Bad Epoll, CVE-2026-46242) was published and fixed. The feed also highlights exploitation of Citrix Bleed 2 (CVE-2025-5777) in ransomware campaigns, seven unpatched FatFs vulnerabilities affecting many嵌d
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 2d719394ea220f63d7fa01648e6ceb7969cc7a1508db11492817f9f459f2df75
- Enrichment time
- 2026-07-07T01:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.