Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations

A sophisticated Iranian hacking group has been using a novel command and control (C2) framework called Cavern to launch targeted attacks on Israeli organizations, according to a recent analysis by experts. The hackers’ arsenal includes a range of tools designed to evade detection and compromise victims’ systems. The Cavern C2 framework is a bespoke solution … Read more

Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks

Sophisticated Malware Framework Delivers Stealthy Payloads via Compromised Websites and Social Engineering A highly complex malware delivery framework has been uncovered by Securonix, exploiting compromised websites and social engineering tactics to infect users with information stealers. Dubbed “Veil#Drop”, this multi-stage framework uses JavaScript launchers, PowerShell download cradles, and Blogspot-hosted payloads to evade traditional antivirus solutions … Read more

Vietnam arrests suspects behind HiAnime anime piracy service

Vietnam Cracks Down on Massive Anime Piracy Service, Arresting Seven Suspects Behind HiAnime In a significant blow to online piracy, Vietnamese authorities have arrested and are prosecuting seven individuals suspected of running HiAnime, one of the largest anime piracy streaming services in the world. The platform, which offered a vast library of English-subbed and dubbed … Read more

Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure

A Critical Docker Flaw Left Unpatched for Weeks, Exposing Users to Potentially Catastrophic Consequences In a concerning display of vulnerability exploitation, threat actors have begun probing a critical flaw in Gitea, an open-source Git repository manager that runs on top of the Docker platform. The weakness, identified as CVE-2026-20896, was publicly disclosed just 13 days … Read more

16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems

A Critical Linux KVM Flaw Puts Millions of Servers at Risk A 16-year-old vulnerability in the Kernel-based Virtual Machine (KVM) software, which is widely used on Linux systems, has been discovered to allow guest virtual machines to escape and compromise their host environments on Intel and AMD x86-based servers. The flaw, designated as CVE-2022-2385, has … Read more

Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations

Iranian hackers have unleashed a new cyber attack tool, dubbed Cavern, targeting Israeli organizations with unprecedented precision and stealth. This sophisticated Command and Control (C2) framework allows its operators to execute complex attacks, exploiting previously unknown vulnerabilities in software applications. The Cavern C2 framework has been linked to Iranian state-sponsored hacking groups, which have been … Read more

Armored Likho APT Targeting Government, Electric Power Entities

Armored Likho APT Targets Government and Electric Power Entities with Sophisticated Malware A recent investigation has uncovered a highly skilled advanced persistent threat (APT) actor, dubbed Armored Likho, which has been targeting government and electric power organizations in multiple countries. According to Kaspersky, the group’s operations span Russia, Brazil, and Kazakhstan, and its arsenal includes … Read more

The Shift Toward Business-Aligned Risk Management

Businesses are finally getting smart about cybersecurity risks. Gone are the days of simplistic risk assessment scores that fail to account for real-world consequences. Today’s organizations need a more nuanced approach that links security threats to their financial and operational realities. At its core, this shift towards business-aligned risk management is all about connecting the … Read more

Max severity Adobe ColdFusion flaw now exploited in attacks

A Critical Adobe ColdFusion Flaw is Being Exploited by Attackers, Urgent Action Required A maximum-severity vulnerability in Adobe’s ColdFusion platform has been actively exploited by attackers just hours after being publicly disclosed. The flaw, tracked as CVE-2026-48282, affects multiple versions of the platform and allows malicious actors to gain remote code execution on unpatched systems … Read more

Software Is Now Written at the Speed of Thought. Security Isn’t.

Software Creation Speeds Up, But Security Lags Behind A revolution is underway in software development. Generative artificial intelligence and Vibe Coding are making it possible for developers to create applications at an unprecedented pace – almost as fast as they think them up. However, this accelerated creation process has left a gaping hole in security: … Read more