View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

16-year-old Linux KVM flaw lets guest VMs escape to the host

🚨 ACTIVE EXPLOITS & INCIDENTS

  • Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations — The Hacker News An Iranian MOIS-affiliated group is deploying a previously undocumented modular C2 framework called Cavern (aka Cav3rn) targeting Israeli IT providers and government sectors. This new framework supports stealthy, multi-stage operations linked to espionage and disruption campaigns.
  • Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks — SecurityWeek Securonix reports a sophisticated attack framework abusing compromised websites and Blogspot-hosted payloads combined with fileless PowerShell techniques to evade detection. The campaign delivers the PureLog info stealer, highlighting a shift toward abusing trusted platforms for malware delivery.
  • Alleged member of Scattered Spider extradited to US — Cybersecurity Dive A dual U.S.-Estonian citizen was extradited and charged for involvement in the Scattered Spider ransomware group’s hack of a luxury jewelry retailer, underscoring ongoing law enforcement pressure on ransomware affiliates.

🔓 VULNERABILITIES & CVEs

🕵️ THREAT RESEARCH & DEEP DIVES

  • Armored Likho APT Targeting Government, Electric Power Entities — SecurityWeek Newly tracked financially motivated APT “Armored Likho” targets government and electric power sectors using modular RATs and info stealers. Campaign blends espionage and financial theft, indicating hybrid motivations and evolving TTPs.
  • Enforce least-privilege authorization in multi-agent AI chains using Cedar — AWS Security Blog AWS details risks of privilege escalation in multi-agent AI workflows where delegated tasks can silently expand authorization scope. They propose using Cedar policy language to enforce strict least-privilege controls, addressing emerging risks in AI-powered automation.

📰 LESSER-KNOWN / UNDER-REPORTED

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check