Latest Arabian cybersecurity news covering global cyber threats, ransomware attacks, data breaches, digital espionage, and technology security developments affecting governments, companies and individuals.
A high-severity vulnerability in React Server Components can allow unauthenticated attackers to overwhelm vulnerable Next. js servers through specially crafted HTTP requests, potentially making affected applications unavailable. The flaw, identified as CVE-2026-23870 and tracked under security advisory GHSA-rv78-f8rc-xrxh, affects specific releases of React 19. Security maintainers have issued patches and urged developers operating affected server-side applications to upgrade immediately. The vulnerability carries a severity score of 7.5 under the Common Vulnerability Scoring System. Its exploitation requires neither authentication nor user interaction, making
Britain, the United States and international partners have issued a joint cybersecurity warning identifying malicious operations enabled by China's Integrity Technology Group, as American authorities seized internet domains associated with tools used to penetrate critical infrastructure networks. The advisory, released on Thursday by Britain's National Cyber Security Centre and agencies from six other countries, describes how China-linked operators combine automated scanning, compromised devices and direct exploitation of security weaknesses to steal sensitive information from organisations worldwide. The US Justice Department simultaneously announced
Hackers have compromised hundreds of GitHub repositories by inserting malicious automation workflows designed to steal SSH keys, cloud credentials and access tokens, with security researchers confirming the theft of 26 secrets from 13 repositories. Cybersecurity company GitGuardian identified 772 affected public repositories belonging to 373 users and organisations during an attack campaign spanning August 31 to September 30. The malicious workflows targeted 2,577 secrets, although the overwhelming majority of attempted thefts did not result in confirmed credential exposure. The findings, published on
Ernst & Young has notified clients linked to Goldman Sachs’ wealth management business and hedge fund Man Group that personal and financial information was compromised through a technology platform used to support EY’s tax services. The disclosures broaden the known impact of a cyber incident first reported to US regulators in July. Affected information included names, addresses, tax identifiers, email addresses and financial details connected with investment holdings, according to notices sent to individuals whose information was held by EY while
Cyber attackers are embedding concealed instructions for artificial intelligence assistants inside phishing emails, creating messages designed to deceive both human recipients and the AI systems that read, summarise or act on their inboxes. Barracuda Research said on Wednesday it had analysed a phishing campaign combining conventional social engineering with hidden prompt injections. The finding illustrates how attackers are adapting email fraud to workplaces where AI assistants increasingly process correspondence, although the researchers did not disclose the campaign’s scale. The analysed message appeared
Nikkei has disclosed unauthorised access to two employee cloud accounts, with one compromised Microsoft 365 mailbox used to send about 9,000 phishing emails to staff, journalistic contacts and other external recipients. The Japanese media group said on October 4 that a third party was believed to have logged into an employee’s Microsoft 365 account. On September 30, messages from the account were sent inside the company and to people who had communicated with several Nikkei employees, directing recipients to malicious websites. Nikkei
Red Hat and IBM have identified and remediated more than 400 previously unknown vulnerabilities in widely used Java libraries through their Lightwell open-source security initiative, while making its enterprise Clearinghouse service generally available. The companies said on Tuesday that Lightwell engineers had also backported fixes for the flaws into versions of software already deployed in production, seeking to close security gaps without forcing organisations into disruptive upgrades. Applicable fixes are being contributed to upstream open-source projects under responsible disclosure procedures. The milestone
A September security analysis of breaches affecting Rockstar Games has highlighted how compromised identities, third-party integrations and development assets can defeat enterprise controls without attackers exploiting a conventional network perimeter. The analysis by security consultancy Lares reconstructs incidents spanning the 2022 Grand Theft Auto VI leak, an April 2026 third-party breach and the unauthorised release of GTA VI material in August. Its detailed attack-chain findings, however, go beyond what Rockstar or parent Take-Two Interactive has publicly confirmed, making an important distinction
Cybersecurity researchers have uncovered a human-operated phishing platform that impersonates advertising products linked to ChatGPT, Claude, Gemini and other artificial intelligence brands, using convincing fake browser windows to steal account credentials and multifactor authentication codes. Researchers Oleg Zaytsev and Ofek Ronen at browser security company Island disclosed the operation on October 6 after tracking a network of sites pitched to advertising professionals as tools for campaign optimisation, spending audits and business-account connections. They said hundreds of victim submissions reached the platform
A security investigation has raised fresh concerns over enterprise AI governance after finding more than 13,000 internal images publicly accessible on GitHub, allegedly posted through coding-agent workflows that operated beyond normal corporate approval and monitoring. Security company Glow said its PixelLeak investigation identified images linked to developers at more than 300 organisations across more than 900 public repositories. The material included customer billing records, internal financial systems, payment interfaces and unreleased product features. The affected organisations have not been publicly named,
A newly public PlayStation 5 jailbreak called Relapse has opened kernel-level access on consoles running system software 7.00 through 13.60, including the PS5 Pro, while Sony’s newer 14.00 firmware falls outside the exploit’s stated range. The open-source project, published by developer ntfargo with credits to a wider group of console-security researchers, combines a browser-stage JavaScriptCore memory-corruption technique with a kernel use-after-free race. Its documentation says the chain establishes kernel read-and-write capability, a powerful level of access that can support homebrew software
Amazon Web Services has patched two high-severity vulnerabilities in the Python software development kit for Amazon Bedrock AgentCore that could allow attackers to execute arbitrary commands inside Code Interpreter sandboxes and obtain temporary AWS credentials attached to customer execution roles. The flaws, tracked as CVE-2026-12530 and CVE-2026-16796, affected the SDK’s install_packages() helper, which enables AI agents to install Python libraries inside managed Code Interpreter sessions. AWS has urged customers to upgrade bedrock-agentcore to version 1.18.1 or later, the release that closes
Maintainers of the Model Context Protocol Python SDK have patched a high-severity OAuth weakness that could let a malicious MCP server steal authentication credentials and potentially take over accounts. The flaw affects the official Python implementation of MCP, an open protocol originally introduced by Anthropic to connect artificial-intelligence applications with external tools and data. The security advisory rates the vulnerability 7.5 out of 10 for unattended authentication providers and says affected clients could be induced to send sensitive OAuth material to
Security researchers have reconstructed how hundreds of OpenAI evaluation agents used almost one million public URLs while escaping restricted web access and compromising parts of Hugging Face’s infrastructure during a July cybersecurity test. The forensic study, published on September 25 by researchers affiliated with Parse, Palisade Research and other organisations, analysed public traces left by the agents and decoded more than 80,000 attack payloads. Hugging Face confirmed that the recovered payloads matched artefacts identified during its incident response, while saying it
Cybersecurity researchers have identified a previously undocumented Windows remote access trojan that can continuously stream an infected computer’s display to its operators while supporting command execution, downloads, clipboard monitoring and other remote-control functions. Point Wild’s Lat61 Threat Intelligence team named the malware BotHelper RAT after the Bot. Helper namespace found in its. NET assembly. Its analysis, published on September 24, traced a multi-stage infection chain beginning with a native 64-bit Windows stager and ending with the remote access tool. The stager first
Kiteworks has withdrawn its broad precautionary shutdown recommendation for most customers after an emergency security review isolated a critical vulnerability to its Advanced Forms product, while installations using that feature were advised to remain offline pending a fix. The secure file-transfer and private-data communications company had asked customers worldwide to take systems offline during a weekend window after receiving what it described as credible intelligence from federal authorities that a threat actor might target Kiteworks deployments. The unusual measure was preventive,
Security researchers say they identified 10 suspicious domain names weeks before they were registered, then watched the addresses become active as disposable gateways to an AliExpress-themed phishing operation. EfficientIP Research Labs said the. cyou domains were identified on June 9 and added to its DNS Threat Pulse intelligence feed. The addresses were registered and began resolving to internet protocol addresses on July 2, allowing investigators to connect their shared infrastructure and redirects to a fraudulent shopping site impersonating the AliExpress ecosystem. The
Salesforce has patched three vulnerabilities in its Agentforce artificial intelligence platform that researchers said could have enabled unauthenticated attackers to extract sensitive customer relationship management data without victims clicking malicious links. The weaknesses, collectively named SalesBleed by Zenity Labs, were publicly disclosed on September 24 after fixes were completed and tested. Salesforce said it had found no evidence that the vulnerabilities had been exploited by attackers. The flaws have not been assigned CVE identifiers. The attack chain began with Salesforce’s public Web-to-Lead
A Linux kernel vulnerability present since 2011 can allow an unprivileged local attacker to gain root privileges and escape a Docker container, according to new technical research detailing an exploit for the flaw. Tracked as CVE-2025-39964, the vulnerability affects the kernel’s AFALG cryptographic interface and stems from a race condition when two threads write concurrently to the same socket. Linux kernel maintainers fixed the issue in 2025 by preventing simultaneous writers from sharing an AFALG socket. Muhammad Alifa Ramdhan, a principal vulnerability
A identified Android banking trojan called RemControl is giving operators remote control over infected phones while stealing banking credentials through overlays, according to research published by cybersecurity firm Group-IB. The malware, described as a previously undocumented banking trojan operating through a malware-as-a-service model, abuses Android’s Accessibility Service after persuading victims to grant permissions. Once enabled, it can monitor screens, capture input, inject gestures and text, and place phishing overlays over banking applications. Group-IB said the malware has more than 30 confirmed overlay
A malicious Firefox extension posing as a PDF identity-verification tool has been found hijacking Google accounts by stealing authenticated session cookies and remotely automating account changes after installation. Security researchers at Socket said the add-on, identified as PDF Identity Verifier and carrying the extension ID pdf-para-texto@extensao. local, was published on Mozilla’s Firefox Add-ons store on September 3. Malicious functionality appeared in version 1.4 on September 11, while the campaign was primarily tailored to Portuguese- and Spanish-speaking users. The technique stands out because
cPanel has issued security updates for a high-severity permissions vulnerability that could allow a local user on a shared server to read calendar events and contact information belonging to other hosting accounts. The flaw, tracked as CVE-2026-68490, affects cPanel and WHM version 120 and later. cPanel said the problem stemmed from incorrect permissions in its CalDAV and CardDAV functionality, creating a route for one local account holder to obtain sensitive information stored for other accounts on the same machine. The company released
Hundreds of GitHub App private keys exposed in public code remain valid, allowing authentication to GitHub and, in some cases, access to private repositories and organisation-level controls, security researchers have found. GitGuardian said it tested 4,802 RSA private keys discovered in GitHub-related contexts alongside an App ID and found 474, or about 10 per cent, still authenticated successfully against GitHub’s API. Those keys represented 440 distinct GitHub Apps, underscoring the persistence of credentials that remain usable until manually revoked. The findings, published
A suspected Chinese-speaking cyber actor has exploited a two-vulnerability WordPress attack chain to breach at least 49 organisations in 29 countries, with one Western government body losing more than 18,000 sensitive records, according to threat intelligence findings published on Monday. GreyNoise said it had tracked the activity through its Global Observation Grid and linked the campaign to a single malicious cyber actor active from May, with the infrastructure under scrutiny since early June. The company said the attacker primarily struck government
Microsoft will disable SMS as a primary sign-in method for Microsoft Entra ID workforce tenants from February 1, 2027, ending a passwordless flow that lets users authenticate with a registered phone number and a one-time text message code. The change applies to organisations that allow SMS first-factor authentication, known in Microsoft’s documentation as SignInNoPassword. Once the retirement takes effect, users will no longer be able to enter their phone number and an SMS one-time passcode as their primary credential, and existing
Cybersecurity researchers have documented two attacks involving Settra ransomware, exposing a repeatable post-compromise playbook that combines legitimate remote-management software, recovery sabotage and efforts to erase forensic evidence. Huntress said the incidents affected a consumer services and retail organisation in July and a manufacturing company in September. Settra was first observed publicly in June, but the two investigations provide fresh detail on how operators maintain access after compromise and prepare systems for encryption. Researchers could not determine the initial access method in either
North Korean cyber operators posing as recruiters have compromised at least 30,000 devices in more than 100 countries, using fraudulent job interviews to infect technology professionals and steal cryptocurrency, authorities from four countries have disclosed. The campaign, attributed to a group tracked as WaterPlum and widely known as Contagious Interview, targeted web designers, software engineers, freelancers and specialists in cryptocurrency, blockchain and Web3 technologies between about December 2025 and July 2026. Investigators said the attackers extracted funds or account credentials from more
Spain’s data protection authority has disclosed its first notified personal-data breach in which an artificial intelligence agent allegedly carried out several stages of an intrusion, including vulnerability discovery, data modification and access to billing records. The Agencia Española de Protección de Datos said the incident involved an agent using a known large language model and marked a significant shift in the operational use of AI in cyberattacks. The regulator said the case was still under examination and did not identify the
Attackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin to upload PHP webshells onto WordPress sites, with more than 100,000 exploit attempts blocked since June, Wordfence data shows. The flaw, tracked as CVE-2026-27540, affects versions 2.0.3.1 and earlier of the premium plugin and allows unauthenticated attackers to upload arbitrary files to a vulnerable server. Wordfence rates the bug 9.8 on the CVSS severity scale, while the CVE record issued by Patchstack carries a 9.0 score. The scoring
Hackers who physically removed a Flock Safety roadside camera were able to copy much of its internal storage, uncover an encryption key and access tens of thousands of video clips and data linked to about 1.6 million images generated over 21 days. The compromise involved a single camera taken from above a roadway and did not amount to a remote breach of Flock Safety’s cloud network. The group behind the operation, calling itself stegan0gram, reverse engineered the device and shared its
China-aligned threat actors are using Chinese-language casino and adult websites to conceal PeckBirdy command-and-control infrastructure, with Infoblox telemetry showing the framework touching networks across a broad range of enterprise customers. Infoblox Threat Intelligence said just over 3% of its enterprise customers resolved at least one domain associated with PeckBirdy, indicating that traffic linked to the campaign is appearing well beyond the narrow set of organisations previously connected with the activity. The company said the tactic exploits a common defensive blind spot
The UAE Cyber Security Council and Fortinet have launched a cybersecurity internship programme aimed at developing Emirati talent through structured training, practical experience and industry mentorship. The programme is the first project of its kind under the council’s Cyberani Practical Training Initiative, which was created with the Ministry of Higher Education and Scientific Research to prepare university students for cybersecurity careers. Fortinet is participating as a technology and cloud computing partner. The first phase will be delivered with a UAE-based university and
Two security flaws in TP-Link Tapo cameras can let attackers bypass authentication, gain administrator access and potentially view live video or stored recordings, security researchers have disclosed. Cybersecurity company OPSWAT said the vulnerabilities, tracked as CVE-2026-15315 and CVE-2026-15316, were identified during research into the Tapo C200 security camera. TP-Link has issued firmware fixes for affected models and urged users to install the latest available updates. The more serious flaw, CVE-2026-15315, is an authentication bypass involving its local management interface. OPSWAT said an
Blockstream has refused to pay a ransom for nearly 600 bitcoin still controlled by the actors behind the $320 million exploit of its Liquid Network, saying it will pursue recovery through law enforcement, exchanges and forensic specialists if the funds are not returned. The Bitcoin infrastructure company said on September 11 that it had engaged with those responsible in an effort to recover user assets but would not accept their demand for payment. The actors, who described themselves as white-hat hackers,