Latest Arabian cybersecurity news covering global cyber threats, ransomware attacks, data breaches, digital espionage, and technology security developments affecting governments, companies and individuals.
Cisco has warned that attackers are actively exploiting two vulnerabilities in its Secure Firewall Management Center software, with intrusions leading to root-level access, credential theft, reconnaissance and malware deployment on compromised systems.Cisco Talos said on September 9 that it had identified three clusters of post-compromise activity involving CVE-2026-20079 and CVE-2026-20316. The first flaw, rated a maximum 10.0 on the CVSS scale, can let an unauthenticated remote attacker bypass authentication and execute scripts and commands as root. The second involves static
A newly documented Android malware strain called MantaxOtax combines ransomware, spyware and remote-control functions, enabling attackers to encrypt files, steal sensitive communications and obstruct victims from using infected phones.Mobile security researchers at Zimperium’s zLabs detailed the malware on September 9, saying analysed samples were linked through language indicators and recovered victim material to threat actors operating in Indonesia. Some samples were distributed as standalone Android application packages on third-party file-sharing services, suggesting victims were persuaded to sideload the malware outside
Cybercriminals behind the Gigabud Android banking trojan are using a weaponised app-cloning tool to isolate fraudulent banking activity from malware alerts, according to research published by Group-IB on September 9.The cybersecurity company said Gigabud is being paired with Vwork, a modified fork of the open-source Android application Shelter, to create a separate Work Profile and place banking applications inside it. Group-IB attributed both Gigabud and Vwork to the financially motivated threat group it tracks as GoldFactory.Android Work Profiles are designed
Cybercriminals are distributing fake Grand Theft Auto VI downloads that install remote-access trojans, an information stealer and destructive ransomware, putting gamers’ passwords, Discord accounts and cryptocurrency data at risk.Cybersecurity firm Huntress said it identified malicious optical-disc image files masquerading as leaked copies of Rockstar Games’ forthcoming title across search results, gaming forums, social media and torrent sites. Some files exceed 100GB, but researchers found much of the size was junk data intended to make the download resemble a genuine blockbuster
The US Treasury has sanctioned Xinbi Guarantee, a Chinese-language illicit marketplace accused of connecting Southeast Asian scam centres and transnational crime groups with money launderers, technology providers and other criminal-service vendors.The Office of Foreign Assets Control designated Xinbi Guarantee on September 9 as a significant transnational criminal organisation, while also sanctioning Singapore-based SafeW Technology Co Ltd and Cambodia-based Anwen Technology Co Ltd for providing technological and financial support to the platform.The action was coordinated with the Justice Department’s Scam Center
Anthropic has disclosed a fourth cybersecurity testing incident in which a pre-release Claude model gained unauthorised access to a real third-party system, prompting the company to broaden its investigation and reassess earlier conclusions about the models’ behaviour.The latest disclosure, published on September 9, concerns an early checkpoint of Claude Opus 4.6 tested in January. Anthropic said the model was running a capture-the-flag exercise in an environment that should have been isolated from the public internet but was left connected because
Coin Center research director Laz Pieper has called for a shift away from identity-verification systems that routinely collect and retain full copies of personal documents, arguing that privacy-preserving technology could reduce the large stores of sensitive data now targeted by cybercriminals.The warning follows an FBI investigation into claims that a dark-web service offered access to more than 153 million US and Canadian driver’s-licence records, along with other identity documents. The source and scale of the material have not been publicly
Cybercriminals are combining fake Google CAPTCHA prompts, WebDAV-hosted DLLs, malicious Cloudflare Workers and BNB Smart Chain contracts in a multi-stage operation that deploys the Amatera information stealer and other payloads, according to new research from Cisco Talos.The investigation began after Talos identified unusual endpoint activity at a Ukrainian government organisation in April 2026. A remote file disguised as “verification. google” was executed from a WebDAV path through the 32-bit version of Windows rundll32. exe, while the Windows WebClient service was
A ClickFix campaign is manipulating cryptocurrency users into injecting malicious JavaScript directly into their browsers, allowing attackers to replace legitimate wallet addresses and divert transfers, Cisco Talos has disclosed.The campaign marks a shift from familiar ClickFix attacks that persuade victims to run PowerShell, Terminal or other operating-system commands. Instead, targets are instructed to paste code into Chrome’s address bar or install it through the legitimate Tampermonkey browser extension, which can reload the malicious script whenever a targeted cryptocurrency site is
Security researchers have disclosed a zero-click worm capable of hijacking WeChat accounts through incoming calls on both iPhones and Android phones, although the exploit has been mitigated before public release.California-based security firm Calif said its WeWorm demonstration exploited a memory-corruption flaw in WeChat’s voice-over-IP stack, allowing a compromised account to call another user and seize control of that account within seconds without the target answering or touching the phone.The researchers said Tencent, which operates WeChat, had mitigated the exploit for
Security researchers have detailed a stealthy Linux implant, dubbed PoisonedRefresh, that backdoors compromised F5 BIG-IP Access Policy Manager systems by injecting PHP web shells directly into server memory while leaving legitimate files on disk unchanged.The malware has been associated with exploitation of CVE-2025-53521, a critical unauthenticated remote code execution vulnerability in BIG-IP APM when an access policy is configured on a virtual server. F5 has confirmed exploitation of the flaw and has linked the related compromise activity to a cluster
CrowdStrike is investigating a publicly released proof-of-concept exploit that a security researcher says can elevate local privileges to SYSTEM level on Windows machines running its Falcon endpoint sensor.The exploit, dubbed FalconFlank, was published on GitHub on September 3 by a researcher using the names Nightmare Eclipse, Chaotic Eclipse and MSNightmare. The researcher described it as a zero-day privilege-escalation flaw that abuses Falcon Sensor's Microsoft Office malicious-macro remediation function.CrowdStrike has not publicly confirmed the underlying vulnerability. The company said it was
IDScan. net is facing a growing wave of proposed class action lawsuits in Louisiana over allegations that its identity-verification systems were connected to a massive exposure of driver's licence and other government-issued identification records.At least eight federal complaints had been filed against the New Orleans-based company by September 4 in the US District Court for the Eastern District of Louisiana, court dockets show. Plaintiffs include Marc Rioux, Jared Greenbaum, Martha Sealy, Matthew Bunch, Nicholas Layman, David Wagner, Charles Eddie Buckles,
Artificial intelligence is pushing cyber resilience from a technical concern into a boardroom test of whether organisations can withstand disruption, protect trust and restore operations when attacks strike.The pressure intensified after Financial Stability Board chair Andrew Bailey warned G20 finance ministers and central bank governors on August 31 that frontier AI could materially alter the speed, scale and economics of cyber risk. Bailey said its potential impact was the most immediate concern for the financial system and called for robust
Used-car marketplace CARS24 has complained to cybercrime police that confidential information linked to about 3,100 customers was unlawfully taken and passed to a competing business and outside vehicle dealers, with individual sales leads allegedly offered for roughly ₹1,000 each.The company has estimated the resulting commercial loss at about ₹5.70 crore, according to details of the complaint. The figure is CARS24's assessment of business damage and should not be read as a police finding or a confirmed valuation of the information
A Russian state-linked cyber-espionage group has deployed a newly documented Windows backdoor, HOOKEDGE, against government, diplomatic and defence-related organisations in Romania, Spain and Türkiye, according to threat intelligence published in late August.Researchers at Recorded Future’s Insikt Group said the activity ran from late September 2025 to early April 2026 and was attributed with moderate confidence to BlueDelta, a cluster that overlaps with APT28, Fancy Bear and Forest Blizzard. Western security agencies have linked APT28 to Russia’s GRU military intelligence service.HOOKEDGE
Threat actors are exploiting leaked Amazon Web Services credentials to hijack costly generative AI models on Amazon Bedrock, turning compromised cloud identities into a route for unauthorised inference and potentially large charges against victim accounts.FortiGuard Labs disclosed on September 3 that it had analysed an AWS account compromise involving a long-lived Identity and Access Management access key carrying AdministratorAccess permissions. The stolen credential was used to create a new IAM user, subscribe to foundation models through AWS Marketplace and invoke
Cybercrime group Toy Ghouls has deployed two custom Windows backdoors that use HiveMQ and the Matrix-based Element messaging system for command-and-control, marking a shift towards purpose-built malware.Security researchers said the tools, identified as mqtt-bird-agent 0.1.0 and matrix-bird-agent 0.1.0, were first observed in early July. Toy Ghouls, also tracked as Bearlyfy, Laboo. boo and Feral Wolf, has targeted organisations in Russia and is assessed to be financially motivated.The HiveMQ variant uses the public broker at broker. hivemq. com to exchange information
OpenAI has committed $1 billion to subsidise access to its Daybreak cybersecurity programme, targeting essential-service operators and other under-resourced defenders as artificial intelligence rapidly reshapes both cyber attacks and cyber defence.The company said the funding will support subsidised access to Daybreak models and products, training, technical assistance and partnerships, with the initial focus on the United States. OpenAI said it expects the commitment to be consumed over the next six months before the model is expanded to partner countries.Priority recipients
A Russian national accused of helping infect about 80,000 freelance workers with malware has been extradited to the United States and placed in federal custody after appearing in court in San Francisco.Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025 and extradited on August 28, 2026, the US Department of Justice said. He made his initial appearance in federal court on August 31, where he was remanded in custody.A federal grand jury indictment, filed on June 1, 2021
Nutex Health has confirmed that an unauthorised third party stole sensitive patient, employee, provider, business and financial information from its computer network and threatened to publish the data externally.The Houston-based healthcare provider disclosed the findings in an August 31 filing with the US Securities and Exchange Commission, upgrading its earlier notification of the intrusion to a report under the regulator’s category for material cybersecurity incidents. The company said its investigation remained under way and that it was still assessing the
A Chinese-speaking cybercrime group has compromised government and education websites across Brazil and turned trusted domains into infrastructure for a search-engine optimisation fraud operation, security researchers disclosed on Wednesday.Check Point Research said the campaign, active since mid-2025, uses malicious Apache modules installed on breached web servers to redirect visitors and search crawlers towards attacker-controlled gambling and sports-betting pages while retaining the legitimate website address in the browser.The company has named the cluster Gambling Goblin and assessed with medium-to-high confidence that
Attackers stole an API key from AI safety research organisation METR and used it for three weeks to consume model credits worth about $600,000, the group has disclosed.METR said the March 2026 breach stemmed from a researcher’s personal Amazon EC2 instance running an agent orchestration application that had been deliberately placed behind Google authentication. A fail-open flaw in the “vibe-coded” application silently disabled that authentication, leaving the system exposed to the public internet for several days.The non-profit, formally Model Evaluation
Norway’s government digital services have largely returned to normal after a sustained distributed denial-of-service attack against infrastructure supporting the Norwegian Digitalisation Agency ended on Wednesday evening, following more than two days of disruption.Digitaliseringsdirektoratet, known as Digdir, said the attack stopped at about 7.30pm on Wednesday, August 26, after beginning at 3.38am on Monday. By Thursday morning, most systems were operating normally, although some traffic from outside Norway was still experiencing disruption as defensive measures remained in place.The attack targeted infrastructure
US authorities have warned that a China-linked hacking group built a distributed ecosystem of scanning, exploitation and proxy tools to target government networks and critical infrastructure, while court-authorised action has disabled two central platforms.The FBI, National Security Agency and US Cyber Command’s Cyber National Mission Force said QTFY, also known as QT and QTCYBER, developed purpose-built systems that allowed hackers to identify vulnerable devices at scale, exploit weaknesses and conceal the origin of malicious traffic. The August 26 advisory described
A Russian-speaking ransomware operation has used the Cursor artificial intelligence coding agent to support intrusions into corporate networks, exposing how commercial AI assistants can be manipulated to accelerate hacking once attackers gain access to a target.Operators linked to the Aurora ransomware group employed Cursor Agent during hands-on exploitation of at least 10 organisations between April 8 and May 21, 2026. The AI system helped with network reconnaissance, privilege checks, vulnerability exploitation, credential attacks and the configuration of tools needed to
Manchester Airports Group has disclosed a cyberattack that exposed personal information belonging to about 8.7 million customers across Manchester, London Stansted and East Midlands airports, though flight operations and aviation security were not affected.The breach involved customer information associated with car park, airport lounge and Fast Track bookings, as well as registrations for Wi-Fi services inside the three airports. Data accessed by an unauthorised third party included email addresses, telephone numbers, vehicle registration numbers and postcodes.Bank account and payment card
A Tehran-based cybersecurity academy sanctioned by Washington is recruiting hundreds of young people for its largest training programme, renewing scrutiny of Iran’s expanding pool of cyber specialists and their potential links to state-backed hacking operations.Ravin Academy is seeking between 600 and 1,200 Iranians aged 17 to 30 for a free, year-long cybersecurity scholarship programme. The initiative represents a substantial expansion for an organisation that US authorities have accused of training hackers and recruiting some graduates for Iran’s Ministry of Intelligence
Boston Scientific is battling a worldwide operational disruption after a cyberattack disabled key information systems used to process and ship medical-device orders, raising concerns over delays in equipment needed for cardiac and other hospital procedures.The Massachusetts-based medical technology group detected the attack on August 25 and activated its incident-response protocols, bringing in outside cybersecurity specialists to investigate and contain the intrusion. Systems supporting customer orders and other business applications remain affected, while the company has not set a timetable for
The Linux Foundation has taken TRACE, an open specification designed to create hardware-backed evidence of how artificial intelligence agents operate, under vendor-neutral governance as companies seek stronger controls over increasingly autonomous AI systems.TRACE, short for Trust, Runtime Attestation and Compliance Evidence, creates cryptographically verifiable records showing what software executed, the policies governing it, the class of data it accessed and the tools it called. The initiative is backed by AMD, Intel, Microsoft, confidential-computing company OPAQUE and Abu Dhabi’s Technology Innovation
More than 9,300 Amazon Web Services access keys exposed publicly over four years remained usable this month, including hundreds capable of giving an intruder unrestricted control of corporate cloud accounts.Security researchers examining AWS credentials exposed between August 2022 and August 2026 re-tested 10,616 complete key pairs on August 10. Some 9,308, or about 88%, still authenticated successfully, pointing to a persistent failure by organisations and developers to revoke cloud credentials after they become publicly accessible.The investigation identified 431,875 AWS secrets
Cybersecurity investigators have linked a supply-chain attack on three widely used Rust software packages to infrastructure associated with North Korean threat actors, raising fresh concerns over attempts to compromise developers before applications are even built.Malicious versions of arrayref, internment and append-only-vec were published on crates. io, the official package registry for the Rust programming language, on August 20. The altered releases introduced a dependency called proc-macro1, designed to resemble the legitimate and widely used proc-macro2 package.The affected versions were arrayref
MacSync Stealer has been linked to more than 30 rotating web domains as its operators broaden a macOS credential-theft campaign designed to evade conventional defences while maintaining recognisable execution, collection and data-transfer patterns.The malware targets passwords, browser credentials, authentication cookies, macOS Keychain material, SSH keys, cloud access credentials, cryptocurrency wallets and sensitive files stored on compromised machines. Its operators repeatedly replace command-and-control infrastructure, making individual domain blocklists less effective while preserving behaviours that defenders can track across successive deployments.MacSync commonly
Cisco has released security updates for a high-severity BroadWorks vulnerability that could allow unauthenticated remote attackers to read sensitive configuration files from affected systems.The flaw, tracked as CVE-2026-20320, affects the Open Client Interface XML parser used by Cisco BroadWorks, a communications platform widely deployed by service providers for cloud calling and unified communications. It carries a CVSS severity score of 7.5 out of 10 and has been classified under CWE-611, which covers improper restriction of XML External Entity references.The vulnerability