MEDIUMVulnerability
Global

New Iran-Nexus Hacking Group Targets Israel Government and IT Sectors

·Source: Infosecurity Magazine

Updated:

Executive Summary

Check Point researchers have identified a new cyber adversary targeting Israeli government and IT businesses, tracked as ‘Cavern Manticore’

Analysis

Check Point researchers have identified a new cyber adversary targeting Israeli government and IT businesses, tracked as ‘Cavern Manticore’
Source Attribution

Originally published by Infosecurity Magazine on Jul 6, 2026.

Related Threats

HIGHVulnerability

NVD HIGH: CVE-2026-1360 — The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untruste...

The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled XProfile field data. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject ar

CVE-2026-1360
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-16610 — The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to ...

The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly emitted nonce with no authentication check, CAPTCHA validation is bypassable by omitting an attacker-supplied key, and repeater row keys from cfgroup[input

CVE-2026-16610
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-14356 — The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in a...

The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the email address and password of any WordPress user, including administrat

CVE-2026-14356
NIST NVD