Adobe ColdFusion RCE, Linux KVM escape, Gitea authentication bypass under active attack
ID: 03793014-1b19-5904-988a-1a5af9e6dd9c
STIX ID: report--03793014-1b19-5904-988a-1a5af9e6dd9c
Feed Name: defend.network
This briefing reports multiple high-risk active threats: a critical Adobe ColdFusion RCE under active exploitation, an Iran-linked APT deploying a new modular C2 (Cavern) against Israeli IT providers, a 16-year-old Linux KVM guest-to-host escape (CVE-2026-53359) affecting Intel/AMD, rapid weaponization of a Gitea Docker authentication bypass (CVE-2026-20896), and a widespread phishing campaign targeting Google credentials; it urges immediate patching, threat hunts, enhanced logging/EDR, and MFA enforcement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
