An Iranian hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS) has been wielding a previously undocumented modular command-and-control (C2) framework dubbed Cavern (aka Cav3rn) targeting Israeli organizations.

A hacking group linked to Iran's Ministry of Intelligence and Security (MOIS) has been observed utilizing a new, modular command-and-control (C2) framework named Cavern, also known as Cav3rn. This sophisticated tool has been employed in attacks specifically targeting organizations within Israel.
The Cavern framework is designed with modularity in mind, allowing attackers to adapt its functionality to suit various stages of an intrusion. This flexibility enables the threat actors to customize their operations, potentially evading detection and increasing the effectiveness of their campaigns.
While the specific initial access vectors used by this group are not detailed, the deployment of the Cavern framework suggests a deliberate and targeted campaign against Israeli entities. The framework's capabilities likely facilitate remote control over compromised systems, enabling data exfiltration, further network pivoting, or the deployment of additional malicious payloads.
The involvement of a group associated with a state-sponsored entity like Iran's MOIS indicates a high level of resources and strategic intent behind these operations. Such actors often pursue objectives including espionage, intellectual property theft, or disruption.
The discovery of the Cavern framework highlights the ongoing evolution of cyberattack tools and techniques employed by nation-state-affiliated groups. The modular nature of the framework presents a challenge for cybersecurity defenders, as it can be reconfigured and updated to bypass existing security measures.
Further analysis of the Cavern framework's architecture and capabilities is likely underway by security researchers to better understand its full scope and potential impact. This includes identifying specific modules, communication protocols, and any unique indicators of compromise associated with its use.
Organizations, particularly those in sectors targeted by nation-state actors, are advised to maintain robust security postures. This includes implementing comprehensive network monitoring, employing up-to-date endpoint detection and response (EDR) solutions, and ensuring timely patching of all systems to mitigate potential vulnerabilities.
Regular security awareness training for employees is also crucial, as human error can often be exploited as an initial entry point for sophisticated attacks. Maintaining strong access controls and practicing the principle of least privilege can further limit the damage an attacker can inflict should they gain a foothold within a network.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a