🚨 ACTIVE EXPLOITS & INCIDENTS
- Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations — The Hacker News An Iranian MOIS-affiliated group is deploying a previously undocumented modular C2 framework called Cavern (aka Cav3rn) targeting Israeli IT providers and government sectors. This new framework supports stealthy, multi-stage operations linked to espionage and disruption campaigns.
- Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks — SecurityWeek Securonix reports a sophisticated attack framework abusing compromised websites and Blogspot-hosted payloads combined with fileless PowerShell techniques to evade detection. The campaign delivers the PureLog info stealer, highlighting a shift toward abusing trusted platforms for malware delivery.
- Alleged member of Scattered Spider extradited to US — Cybersecurity Dive A dual U.S.-Estonian citizen was extradited and charged for involvement in the Scattered Spider ransomware group’s hack of a luxury jewelry retailer, underscoring ongoing law enforcement pressure on ransomware affiliates.
🔓 VULNERABILITIES & CVEs
- 16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems — The Hacker News CVE-2026-53359 (Januscape) is a use-after-free bug in Linux KVM’s shadow MMU code affecting Intel and AMD x86 hosts. A guest VM can exploit this to corrupt host kernel memory, potentially enabling VM escape. Public PoC causes host panic; an unreleased exploit is claimed to exist.
- Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure — The Hacker News Active exploitation attempts observed targeting CVE-2026-20896 (CVSS 9.8), a critical unauthenticated privilege escalation in Gitea Docker images. The flaw allows attackers to bypass authentication by spoofing the “X-WEBAUTH-USER” header, risking DevOps supply chain compromise.
- VU#213560: Tenda firmware (multiple versions) contains hidden authentication backdoor — CERT/CC Multiple Tenda router firmware versions contain a hidden admin backdoor (CVE-2026-11405) allowing attackers to bypass password verification and gain full device control. Affected versions include US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD and others. Immediate firmware updates or mitigations recommended.
- VU#828543: HP Deskjet 2800 Printer Series Webservers contain Missing Authorization Vulnerability — CERT/CC HP Deskjet 2800 printers running firmware ≤ TBP1CN2612AR expose sensitive Wi-Fi credentials and management data via unauthenticated webserver API endpoints (CVE-2026-13753). This missing authorization flaw allows remote attackers to access admin-level info without credentials.
🕵️ THREAT RESEARCH & DEEP DIVES
- Armored Likho APT Targeting Government, Electric Power Entities — SecurityWeek Newly tracked financially motivated APT “Armored Likho” targets government and electric power sectors using modular RATs and info stealers. Campaign blends espionage and financial theft, indicating hybrid motivations and evolving TTPs.
- Enforce least-privilege authorization in multi-agent AI chains using Cedar — AWS Security Blog AWS details risks of privilege escalation in multi-agent AI workflows where delegated tasks can silently expand authorization scope. They propose using Cedar policy language to enforce strict least-privilege controls, addressing emerging risks in AI-powered automation.
📰 LESSER-KNOWN / UNDER-REPORTED
- Vietnam arrests suspects behind HiAnime anime piracy service — BleepingComputer Vietnamese authorities arrested seven individuals linked to HiAnime, the largest anime piracy streaming service before its June shutdown. This crackdown highlights ongoing efforts to disrupt piracy infrastructures, which often serve as malware distribution vectors.
- Between Two Nerds: Why AI has not meant more hacks. Yet. — Risky Business News Tom Uren and The Grugq discuss why AI-driven vulnerability discovery has not yet translated into a surge of devastating hacks, emphasizing current limits in exploit development and operationalization despite AI’s bug-finding capabilities.
- 5 insights from Frost & Sullivan’s 2025 Frost Radar™ for Cloud Security Posture Management — Microsoft Security Blog Summary of evolving CSPM trends moving from point-in-time compliance checks to continuous risk management, highlighting the need for dynamic cloud security controls aligned with business risk.