Just in:
US oil reserve sinks towards four-decade low // NASA ground software flaw exposes spacecraft commands // Saudi Arabia raises US Treasury holdings to $142.5bn // Controller shortage puts Sydney Airport safety under scrutiny // UAE freezes trade and financial dealings with Iran // Asia Responsible Enterprise Awards and Asia Pacific Enterprise Awards 2026 China Chapter Celebrate Resilient Enterprises Forging Legacies of Excellence and Impact // CodeRabbit secures $143 million for AI governance push // Trump rejects Iran truce extension as Lebanon flares // Warsh Fed will do nothing to derail rally in US bank shares // Employed but stuck: Malaysia’s resilient labour market masks a career mobility gap // Alpro Group and AstraZeneca Collaborate to Advance Early Detection Across the Cardio-Kidney-Metabolic Spectrum and Raise Awareness of Hyperkalemia // UK fraud filings reach first-half record // Telegram seeks .gram domain for user web identities // India pushes coal gasification to reduce import risks // Annual Maintenance Contracts in Dubai: Why Property Owners Are Moving Beyond Reactive Maintenance // Oil prices climb as Iran tensions deepen // JSCCIB Joins Forces with Public Sector and World Bank to Launch “The Bangkok Business Summit 2026: Reinvent Thailand, Resilient ASEAN” // At Just 27, Hamdan Bin Turki Al Mehairi Is Building One of the Most Ambitious Business Groups // 2026 Taiwan Four-Season Springs Travel Campaign Officially Launches // LG deepens Gulf streaming push with stc tv //

Category: Cybersecurity

Latest Arabian cybersecurity news covering global cyber threats, ransomware attacks, data breaches, digital espionage, and technology security developments affecting governments, companies and individuals.

ADVERTISEMENT
ADVERTISEMENT

Britain recorded more than 220,000 fraud-risk cases in the first six months of 2026, the highest total ever registered for the January-to-June period, as identity theft, account takeovers and money-mule activity intensified across financial and digital services. The figure was about 1% higher than a year earlier. Identity fraud remained the dominant threat, accounting for 59% of all cases entered into the National Fraud Database during the period. More than 129,000 identity fraud cases were recorded, an increase of 9%

A critical authentication flaw in NASA’s open-source ground-control software could allow network attackers to obtain a valid session and transmit arbitrary spacecraft or instrument commands without supplying credentials. The vulnerability affects versions of the AMMOS Instrument Toolkit GUI released before version 2.5.1 and has been assigned CVE-2026-60112. The weakness carries a CVSS 4.0 severity score of 9.3 out of 10 and a CVSS 3.1 score of 9.8, placing it firmly in the critical category. Exploitation requires no prior privileges, user

An autonomous security agent developed by Wiz uncovered and exploited a serious vulnerability in a Snowflake GitHub Actions workflow that had passed GitHub Advanced Security checks, highlighting emerging risks as artificial intelligence becomes increasingly embedded in software development and cyber defence. The flaw affected the public snowflakedb/snowflake-connector-net repository and allowed an unauthenticated GitHub user to execute arbitrary commands simply by opening an issue containing a specially crafted title. The vulnerable workflow automatically created Jira tickets when issues were opened and

SafePal has warned nearly 40,000 customers that their personal information was exposed after attackers exploited a flaw in an order-tracking system, creating a heightened risk of targeted phishing and impersonation attacks against cryptocurrency holders. The cryptocurrency wallet provider said information belonging to approximately 39,798 customers was accessed without authorisation. The affected records covered purchases made between March 2, 2025 and April 11, 2026 and contained names, email addresses, shipping addresses, telephone numbers and purchase details. Seed phrases, private keys, wallet

Cl0p has claimed a sweeping data-theft campaign affecting nearly 50 companies worldwide, placing Shell, Philips, GE and financial technology group Fiserv among the organisations named on the cybercrime operation’s leak site. Several companies have opened investigations, although the scale of the alleged theft remains unverified. The campaign appears to mark another large-scale attempt by the Russia-linked extortion group to exploit a weakness in widely deployed enterprise software rather than penetrate victims individually. Security investigators have connected the activity to vulnerabilities

A newly analysed macOS information-stealing malware is targeting cryptocurrency holdings, passwords and Apple Keychain data after victims are tricked into executing malicious commands through ClickFix social-engineering attacks. The malware, written in the Go programming language and compiled as a native Mach-O executable, can steal browser credentials and cached authentication data while also manipulating cryptocurrency transactions. Its most unusual capability allows operators to siphon either part or all of a victim’s cryptocurrency balance rather than simply emptying a wallet in a

A newly analysed macOS information-stealing malware is targeting cryptocurrency holdings, passwords and Apple Keychain data after victims are tricked into executing malicious commands through ClickFix social-engineering attacks. The malware, written in the Go programming language and compiled as a native Mach-O executable, can steal browser credentials and cached authentication data while also manipulating cryptocurrency transactions. Its most unusual capability allows operators to siphon either part or all of a victim’s cryptocurrency balance rather than simply emptying a wallet in a

Microsoft is preparing a major change to enterprise identity security, making passkeys the default authentication experience in Entra ID from September 1, 2026, before ending its own SMS and voice authentication delivery services on February 1, 2027. The shift will affect organisations whose employees still rely on text messages or telephone calls for multifactor authentication. As Microsoft's rollout reaches individual organisations, users enabled for SMS or voice authentication will automatically become eligible for passkeys. They will then be prompted to register

VINclarity has launched an investigation into what it says is a coordinated campaign aimed at damaging its reputation across Reddit, YouTube, search engines and artificial intelligence services. The vehicle-history platform said its review identified patterns linking negative Reddit posts, YouTube videos and entries on the Better Business Bureau's Scam Tracker with searches containing phrases such as “VINclarity scam”, “VINclarity fraud” and “is VINclarity legit”. The company argues that the combination can influence both conventional Google results and answers produced by AI-powered

Cybersecurity researchers have found evidence that ExfilSquad obtained sensitive information belonging to at least 13 organisations, strengthening earlier claims by the emerging extortion group after it began distributing stolen datasets through torrent networks. The disclosures cover organisations in the United States, Britain and Sweden and span government, education, aviation, insurance, technology and consumer services. Investigators examining the material say the leaked files contain personally identifiable information, customer records, internal case-management data and other sensitive information. ExfilSquad surfaced publicly in July 2026 and

The FBI and NCAA have launched a joint effort to protect college athletes from hackers seeking private images and using stolen material for sexual exploitation, blackmail and online harassment. The initiative follows growing concern that athletes’ highly visible digital profiles are giving criminals more opportunities to identify targets, compromise accounts and obtain intimate photographs or videos. Attackers commonly use phishing messages, stolen or guessed passwords and PINs, and fake social-media customer service accounts that claim urgent security action is required.

North Korea-linked hackers exploited a previously unknown Windows vulnerability to gain the highest level of system privileges while targeting defence, aerospace and aviation organisations across several countries. The flaw, tracked as CVE-2026-68820, affects the Windows Ancillary Function Driver for WinSock, known as AFD. sys. Microsoft patched the vulnerability on August 11 after it was found being actively exploited as part of the long-running Operation Dream Job cyber-espionage campaign associated with the Lazarus Group. Attack activity was confirmed against organisations in France, Germany,

Cursor has patched a security flaw in its command-line coding agent that allowed a malicious repository to execute commands on a developer’s computer before the user was asked whether the workspace should be trusted. The weakness affected Cursor CLI’s worktree feature and could be triggered when a user launched the agent with the -w option inside a repository containing a specially crafted. cursor/worktrees. json file. The file could specify a shell command that was executed during worktree setup before Cursor displayed

Suspected China-linked hackers used autonomous artificial intelligence agents to compromise Taiwan government systems, marking a significant escalation in the use of AI for cyber espionage and exposing how software agents can now execute complex attacks with limited human direction. The campaign unfolded over four days at the beginning of July and targeted 21 government systems. The attackers deployed as many as eight AI agents simultaneously to map networks, identify vulnerabilities, test possible entry points and change tactics when individual attack

Washington’s accelerating adoption of autonomous artificial intelligence is colliding with warnings from cybersecurity specialists that AI agents could inadvertently breach government systems, after a model evaluation led to an intrusion into Hugging Face’s production infrastructure. The General Services Administration has expanded federal access to agentic AI through its OneGov programme, including an agreement with CORAS. ai that gives agencies access to GARY, an AI orchestration platform designed to automate reporting, data preparation, analytics and operational workflows. The platform uses specialised AI

Valve has warned Steam hardware customers across Europe that their personal and order information was likely stolen during a cyberattack on CEVA Logistics, the company responsible for distributing its physical products in the region. The attack gave intruders access to CEVA systems between July 29 and August 1, 2026. Valve learned on August 7 that information belonging to its customers was among the data potentially compromised. The gaming company has since begun sending breach notifications to people whose hardware orders

The compromise of LiteLLM has sharpened concerns that software underpinning artificial intelligence systems is becoming a strategic target for attackers seeking credentials, cloud access and pathways into other technology projects. Two malicious versions of the widely used LiteLLM Python package, 1.82.7 and 1.82.8, were published to the Python Package Index on March 24. They remained available for about 40 minutes before PyPI quarantined the project. The affected packages were subsequently deleted. The short exposure window masked a potentially significant security event.

Hackers penetrated a Polish combined heat and power plant through a private cellular network, manipulating industrial controllers and temporarily halting cogeneration at a facility supplying heat to about 50,000 residents. The attack has exposed a previously undocumented route into critical operational technology systems. The intrusion occurred on December 29, 2025, during a broader campaign against Poland’s energy infrastructure. Investigators have now established that attackers moved from a compromised wind farm into a private access point name, or APN, network used

GitHub has expanded Dependabot malware alerts across major open-source package ecosystems, widening automated protection against compromised and deliberately malicious software dependencies beyond the npm registry. The change gives developers earlier warnings when projects depend on packages identified as malware. The expanded coverage is powered by the GitHub Advisory Database importing malicious-package intelligence from the OpenSSF Malicious Packages project. The database can now feed those records directly into Dependabot, which compares them with dependencies used in participating repositories and creates an

A coordinated campaign involving 77 counterfeit extensions on the Open VSX Registry exposed sensitive information about developer machines, Git repositories and continuous integration environments, highlighting a growing software supply-chain risk around code-editor plugins. The extensions appeared between July 26 and August 1 and impersonated legitimate tools available through the Visual Studio Code ecosystem. All 77 had been removed from Open VSX by August 3, but security specialists have warned that marketplace removal does not eliminate copies already installed on developer workstations,

A Windows Hello for Business authentication technique can allow malware operating inside an unlocked Windows session to gain access to Microsoft Entra ID services without obtaining the user’s password, PIN or biometric data. Security researcher Dirk-jan Mollema demonstrated that an attacker who already controls a user process can invoke the cryptographic key underpinning Windows Hello for Business, or WHFB, and use it to generate authentication signatures. The private key itself does not have to be extracted from the device’s Trusted Platform

A security weakness in Anthropic’s Claude Code could allow a malicious pull request to trigger arbitrary code execution on a developer’s machine by exploiting previously granted trust for project-level Model Context Protocol configurations. The issue centres on Claude Code’s handling of the. mcp. json file, which allows repositories to define MCP servers used by the coding agent. These servers can launch local commands and connect Claude Code to external tools, databases and services. Because project-scoped configurations are designed to travel with

A Canadian hacker has pleaded guilty to taking part in a sweeping cybercrime operation that compromised accounts belonging to more than 165 organisations using cloud data platform Snowflake, exposing sensitive information belonging to at least 100 million people. Connor Riley Moucka, 26, of Kitchener, Ontario, admitted computer fraud, wire fraud, aggravated identity theft and conspiracy in federal court in Washington state. He is scheduled to be sentenced on October 27 and faces a maximum combined prison term of 32 years.

A self-propagating malware campaign has compromised more than 430 npm packages, exposing software projects linked to dependencies that collectively record about two billion installations each month. The campaign, known as ChainDrop, emerged on 4 August after attackers gained control of the account behind Keyv, a widely used caching library in the JavaScript ecosystem. Malicious code was then introduced into Keyv and several related packages, including flat-cache, file-entry-cache and cacheable, allowing the infection to spread through interconnected developer accounts and publishing permissions. Security

Ransomware operators are using Ethereum smart contracts to conceal command-and-control addresses, giving malware a resilient way to locate attacker-controlled servers even after defenders block known domains. The technique has been linked to an affiliate of The Gentlemen ransomware operation, which deployed a Node. js backdoor known as EtherRAT during intrusions targeting Windows networks. Instead of storing a fixed command server inside the malware, EtherRAT reads a smart contract on the Ethereum blockchain to obtain an active domain. The arrangement allows operators to

A WhatsApp account takeover scam is spreading through messages that ask users to vote for a friend or relative in an online competition, before covertly linking the victim’s account to a device controlled by criminals. The attack often begins with a message from a familiar contact whose account has already been compromised. The recipient is asked to support someone participating in a dance contest, school competition, pet show or similar event. The personal connection makes the request appear credible and encourages

Apache NiFi has released version 2.11.0 to address four vulnerabilities in its web application programming interface, including high-severity weaknesses that could exhaust server memory or allow users with limited permissions to manipulate sensitive configuration processes. The most broadly applicable flaw, tracked as CVE-2026-68981, affects NiFi versions 1.5.0 through 2.10.0. It stems from the way the platform processed gzip-compressed HTTP requests sent to its REST API. NiFi enforced its configurable request-size limit against the compressed data rather than the much larger decompressed output.

Microsoft has warned travellers and organisations about a Russian state-linked cyberespionage campaign that manipulates hotel and venue Wi-Fi networks to steal credentials, compromise cloud accounts and install surveillance malware. The operation, named CaptiveCrunch, has been active since early May and is attributed to Storm-2945, an operational subgroup of Midnight Blizzard. The wider hacking organisation, also known as APT29 and Cozy Bear, has been linked by the United States and Britain to Russia’s Foreign Intelligence Service. The attackers target wireless networks that use

A newly identified malware operation has used a counterfeit Python component to bypass security scrutiny, disable parts of Microsoft Defender and establish persistent remote access inside a law firm’s network. The intrusion compromised two endpoints after employees received spear-phishing emails directing them to an encrypted archive hosted on the Mega file-sharing service. The archive contained a malicious Windows shortcut named “Case Documents”, designed to resemble material connected with legal work. Opening the shortcut triggered a multi-stage infection chain involving native Windows utilities,

CareCloud has begun notifying about 345,000 people that hackers accessed and removed sensitive medical, financial and identity information from an electronic health record environment operated by its CareCloud Health division. The compromised information may include names, residential addresses, dates of birth, Social Security numbers, driving licence and passport details, medical record numbers and health insurance information. Clinical data such as diagnoses, treatment details, prescription information, laboratory results and provider names may also have been exposed. Financial information potentially affected includes bank account

A Chinese-speaking hacker used DeepSeek artificial intelligence to autonomously identify vulnerable systems, obtain publicly available exploit code and launch attacks against hundreds of internet-facing targets, exposing how generative AI is moving closer to independently conducting offensive cyber operations. The campaign involved more than 460 targets and combined AI-directed activity with conventional manual hacking. The operator, who used the online aliases “knaithe” and “KnYuan”, controlled an open-source framework called Hermes Agent through Telegram. DeepSeek functioned as its principal reasoning engine, selecting targets,

Amazon Web Services has attributed a series of compromises involving widely used npm software packages, including Axios, Debug and Chalk, to a financially motivated hacking group linked to North Korea. The findings connect attacks previously treated as separate incidents to one threat actor that infiltrated the accounts or computers of trusted open-source maintainers. The attackers then published malicious updates capable of stealing credentials, installing remote-access tools and opening thousands of downstream systems to further intrusion. Amazon Threat Intelligence assessed with medium confidence

A custom ransomware family linked to the Toy Ghouls cybercrime group is targeting Windows, Linux and VMware ESXi systems, giving its operators the ability to disrupt entire corporate networks through a single attack campaign. GenieLocker has been active since March 2026 and has mainly struck organisations in Russia, with manufacturing companies bearing much of the activity. Construction, financial services, retail and technology businesses have also encountered the malware, indicating that its operators may be widening their target profile. Toy Ghouls, also tracked

LogoKit has evolved into a cloud-based phishing platform capable of constructing customised fake login pages for individual victims as soon as they click a malicious link. The kit uses a person’s email domain to identify their organisation, retrieve authentic branding and capture an image of the organisation’s genuine website. The material is then assembled into a convincing credential-harvesting page designed to resemble the victim’s familiar online environment. Security researchers examining active LogoKit campaigns found that the service used Thum. io, a commercial