Latest Arabian cybersecurity news covering global cyber threats, ransomware attacks, data breaches, digital espionage, and technology security developments affecting governments, companies and individuals.
A newly disclosed technique dubbed “sockpuppeting” has sharpened concerns over how easily some artificial intelligence systems can be pushed past their safety controls, after researchers showed that a short output-prefix prompt inserted through an application programming interface can drive several leading open-weight models to produce harmful material they would normally refuse. The work, published in January by researchers at the University of Amsterdam, describes the method as a low-cost jailbreak requiring no optimisation and as little as a single line
A critical security flaw in the Ninja Forms File Uploads add-on has put thousands of WordPress sites at risk, with researchers warning that attackers can exploit the bug without logging in and, in the worst case, gain remote code execution on a vulnerable server. The issue affects all versions up to and including 3.3.26, while version 3.3.27 has been identified as the fully patched release after an earlier partial fix in 3.3.25.The vulnerability, tracked as CVE-2026-0740, carries a critical
Amazon Web Services has patched three high-severity vulnerabilities in its open-source Research and Engineering Studio platform, closing weaknesses that could have allowed authenticated users to run commands on key systems or gain broader permissions inside cloud environments used for scientific and engineering work.The flaws affected AWS Research and Engineering Studio, known as RES, a web-based portal that helps administrators build and manage controlled research and engineering environments on AWS. In a security bulletin published on 6 April, AWS said the
A cross-border espionage campaign that targeted journalists, civil society figures and some government-linked entities across the Middle East and North Africa between 2023 and 2024 has been tied by researchers to BITTER, a long-tracked South Asian threat actor, marking what investigators describe as the first documented case linking the group to attacks on civil society in the region. The attribution remains qualified rather than definitive: Lookout said it had reached its assessment with moderate confidence, while Access Now said the
Google has warned that a financially motivated cyber group tracked as UNC6783 is targeting business process outsourcers and corporate helpdesks in a campaign aimed at stealing sensitive data from large companies and then using that access for extortion. The group, which Google says may be tied to the “Raccoon” persona, has targeted several dozen high-value organisations across multiple sectors, shifting attention to a weak point that many large enterprises share: outsourced support operations and internal service desks.The warning came
STX RAT, a newly identified remote access trojan, has drawn attention in the cyber-security sector after researchers tied it to an attempted intrusion against a financial-services environment and linked it to broader opportunistic delivery campaigns that include trojanised software and script-based loaders. The malware stands out because it combines hidden remote control with data theft, while delaying some of its most suspicious behaviour until it has an active connection to its command server.Researchers said the malware was first observed
Attackers have planted a stealthy Magecart credit-card skimmer on nearly 100 Magento-based online shops by hiding the malicious code inside an invisible SVG image, according to incident findings published this week, in what security specialists describe as another sign that payment-page attacks are becoming harder for merchants and scanners to detect. The operation was identified on April 7 and affected 99 stores, with stolen payment data sent to six attacker-controlled domains.What makes the campaign stand out is the way
Atomic Stealer operators have opened a fresh lane into Apple computers by shifting a popular ClickFix scam away from Terminal and into Script Editor, a built-in macOS tool that many users would regard as less suspicious. The change matters because Apple moved in March to add stronger friction around Terminal-based copy-and-paste attacks in macOS Tahoe 26.4, and threat researchers now say attackers have adapted within weeks rather than abandoning the technique.Researchers at Jamf Threat Labs said the campaign uses
U. S. authorities have dismantled the domestic arm of a cyber-espionage network that officials say was run by APT28, the Russian military intelligence hacking group also known as Fancy Bear and Forest Blizzard, after it hijacked vulnerable internet routers to redirect traffic, steal credentials and sift victims for higher-value targets. The Justice Department said the FBI used a court-authorised technical operation to identify compromised routers on U. S. soil, collect evidence, sever the hackers’ access and restore the devices to
GitLab has issued a security update covering multiple vulnerabilities in its Community Edition and Enterprise Edition products, with the latest patch aimed at denial-of-service weaknesses and an Enterprise-only code injection issue that could expose users’ IP addresses through maliciously crafted Code Quality reports. The company said self-managed customers should upgrade immediately to versions 18.10.3, 18.9.5 or 18.8.9, while GitLab. com is already running the patched release and GitLab Dedicated customers do not need to act.At the centre of the 8
Google’s handling of API keys has come under fresh scrutiny after security researchers said Android applications are exposing credentials that can now unlock parts of the Gemini AI platform, potentially allowing unauthorised access to files, cached data and billable AI services. The latest warning, published by CloudSEK on April 7, says 32 hardcoded Google API keys were found across 22 popular Android apps and that the issue stems from how older Google Cloud keys can gain Gemini permissions when the
Palo Alto Networks has issued a high-priority security update for a flaw in its Cortex XSOAR and Cortex XSIAM platforms that could allow an unauthenticated attacker to access and alter protected resources through the Microsoft Teams integration, adding fresh pressure on security teams to review third-party connectors that sit inside core incident response systems. The vulnerability, tracked as CVE-2026-0234, was published on April 8 and affects Microsoft Teams Marketplace integration versions from 1.5.0 up to, but not including, 1.5.52.The
Iran-affiliated cyber actors are targeting internet-facing industrial control equipment used by parts of the United States’ critical infrastructure, with federal agencies warning that the campaign has already caused operational disruption and financial loss in some cases. The alert, published on April 7, said the activity was focused on operational technology devices, including programmable logic controllers, or PLCs, made by Rockwell Automation’s Allen-Bradley line.The warning matters because PLCs sit close to physical operations. They help control pumps, motors, valves and other
Fresh academic work is pushing back against some of the louder claims surrounding quantum computers and Bitcoin, arguing that one feared route of attack — using a quantum machine to dominate mining — remains so physically demanding that it would require energy on an astronomical scale. A separate paper has cast doubt on headline-grabbing “quantum factoring breakthroughs”, arguing with deliberate sarcasm that many such claims can be reproduced with primitive classical hardware and even a dog, underscoring how far the
What used to be dismissed as internet oddity is moving into the mainstream of fraud prevention, platform regulation and organised crime analysis: the distinction between sock-puppet accounts and catfishing is no longer academic. Authorities, platforms and researchers are increasingly treating fake digital personas as a wider security and financial risk, particularly as artificial intelligence makes them cheaper to create, easier to scale and harder for ordinary users to detect.At the centre of the debate is a simple but important difference.
Hackers are exploiting internet-exposed ComfyUI servers in a monetisation campaign that turns poorly secured AI image-generation systems into cryptocurrency mining machines and proxy infrastructure, according to multiple security findings published this week. Researchers say more than 1,000 exposed ComfyUI instances remain reachable online after honeypots are filtered out, giving attackers a narrow but valuable pool of GPU-equipped targets spread across cloud environments.The activity centres on unauthenticated ComfyUI deployments and the platform’s custom node ecosystem, which lets users add third-party
Russian military-linked hackers have hijacked vulnerable internet routers to steal passwords, authentication tokens and other sensitive data, according to a new warning from the UK’s National Cyber Security Centre, which said the activity was tied to APT28, a group long associated with Moscow’s GRU military intelligence unit 26165. British officials said the campaign worked by altering router settings so internet traffic could be redirected through malicious Domain Name System servers controlled by the attackers, opening the way for adversary-in-the-middle attacks
Microsoft has warned that a threat actor it tracks as Storm-1175 is exploiting vulnerabilities in internet-facing systems at high speed to deliver Medusa ransomware, in some cases moving from initial access to data theft and encryption within 24 hours. The alert points to a pattern that security teams have feared for months: a shrinking window between vulnerability disclosure, exploitation and full-scale ransomware deployment.The group, described by Microsoft as financially motivated, is said to focus on web-facing assets that remain exposed
Iran-linked hackers mounted a coordinated password-spraying operation against Microsoft 365 tenants across the Middle East in March, with Israel and the United Arab Emirates emerging as the main targets in a campaign that cyber researchers say shows how regional conflict is increasingly being mirrored in the cloud. Check Point Research said the activity came in three waves on March 3, March 13 and March 23, hitting more than 300 organisations in Israel and over 25 in the UAE, while smaller
Security leaders are being told to treat “vibe coding” as a governance issue, not merely a productivity trend, as AI assistants move deeper into software development and expose organisations to flaws ranging from insecure dependencies to credential leakage and command injection. Guidance from standards bodies and security groups now points towards a simple principle: code produced with AI should be handled as untrusted until it has passed the same scrutiny as any high-risk software change.That shift is gaining force as
A Python package presented as a privacy-first shortcut to AI models has been unmasked as a supply-chain threat that quietly captures user prompts, leans on a private university service without authorisation and repurposes proprietary Claude material to make the deception look convincing. Security researchers said the package, hermes-px, was uploaded to PyPI as a supposed “Secure AI Inference Proxy” offering OpenAI-compatible access over Tor and claiming users did not need their own API keys.Analysis by JFrog, published on April
A malware campaign targeting organisations in South Korea is using weaponised Windows shortcut files and GitHub’s infrastructure to slip past standard network defences, according to threat researchers who say the operation relies on native Windows tools, hidden scripts and trusted web traffic to keep a low profile. Technical analysis published over the past few days shows the attackers embedding or decoding malicious PowerShell from LNK files, then using GitHub repositories and APIs to fetch follow-on instructions and upload stolen system
Anthropic’s Claude Code has come under fresh scrutiny after researchers disclosed a flaw that can neutralise user-set deny rules when a shell command is padded with a long chain of harmless subcommands, raising concerns that a safety feature marketed as a hard stop may fail in exactly the kind of hostile conditions it is meant to resist.The issue centres on Claude Code’s permission system, which lets developers block specific actions such as curl or other shell commands that could
Google DeepMind has warned that autonomous AI agents face a widening security risk from malicious web content designed not for humans, but for machines that browse, interpret and act online. The threat, described by researchers as “AI Agent Traps”, centres on adversarial web pages and digital resources crafted to mislead, hijack or exploit AI systems as they move beyond chatbot functions into tasks such as handling email, searching the web, making transactions and coordinating software tools.The paper, published at the
Drift Protocol has said the theft of about $270 million to $286 million from its platform was the result of a six-month operation by North Korea-linked actors who built trust slowly, posed as a legitimate trading firm and used face-to-face meetings, capital deposits and carefully timed social engineering to prepare the strike. The Solana-based exchange’s account adds a new layer to an attack that security researchers had already described as one of the largest decentralised finance hacks of 2026.The
Attackers behind the compromise of the widely used Axios package have widened their campaign, turning from code repositories to the people who maintain them and exposing how a single deceptive approach can threaten vast stretches of the software supply chain. Security researchers and the Axios maintainer’s own post-mortem show the March 31 breach was not an isolated package hijack but part of a co-ordinated social-engineering operation aimed at high-value figures in the Node. js and npm ecosystem.The breach centred
A newly disclosed exploit chain in Progress ShareFile has raised fresh concern over the security of enterprise file-transfer systems after researchers showed that two critical flaws can be combined to seize control of vulnerable customer-managed servers without prior authentication. The vulnerabilities, tracked as CVE-2026-2699 and CVE-2026-2701, affect ShareFile Storage Zones Controller, the on-premises component used by organisations that keep files in their own infrastructure while relying on ShareFile’s broader service layer.The more severe of the two bugs, CVE-2026-2699, carries
GitHub has been drawn into another cyber threat case after researchers uncovered a multi-stage malware campaign using malicious Windows shortcut files to target users in South Korea, with the code-hosting platform serving as a covert command channel in the infection chain. The operation relied on booby-trapped. LNK files, embedded decoding routines and PowerShell to pull down follow-on payloads, maintain persistence and move stolen data through attacker-controlled infrastructure disguised as legitimate web traffic.The case illustrates how attackers are continuing to
Security researchers at Varonis have identified a new infostealer dubbed Storm that appears to mark a more polished phase in credential theft, using server-side decryption to extract browser passwords, session cookies, crypto-wallet data and other sensitive material while avoiding many of the on-device traces that endpoint tools have grown used to flagging. The malware was observed on underground forums in early 2026 and is being sold as a subscription service, underscoring how credential theft is becoming more commercialised, modular and
An Iran-linked hacking group has claimed it breached PSK Wind Technologies, an Israeli defence supplier that says it develops command-and-control shelters, communications systems and other integrated solutions for defence and homeland security customers. Material circulated online on 2 April was presented by the group, Handala, as proof of a deep intrusion into a company tied to sensitive military infrastructure. Independent verification of the full scope of the claimed breach, however, remained limited at the time of writing.The claim has
Arabian Post’s website was dealing with disruption on Thursday after website security provider Sucuri disclosed an unresolved incident affecting its Paris region and said it was mitigating the impact of a distributed denial-of-service attack, a form of assault designed to overwhelm servers with traffic and degrade access for readers. On its public status page, Sucuri first marked the incident as “Investigating” at 08:19 UTC on 2 April, then said mitigation had been applied by 09:03 UTC while warning that the
Google has moved to reassure developers and users that Android will remain open even as it rolls out a new verification regime for app makers, but the effort has opened a wider argument over whether the company is strengthening security or extending its control far beyond the Play Store. The dispute sharpened after Google published fresh details in March on how users will still be able to sideload software from unverified developers, while campaigners behind Keep Android Open warned that
Almost eight in 10 UK manufacturers suffered at least one serious cyber incident over the past 12 months, according to new ESET-commissioned research, adding fresh evidence that digital disruption is now a mainstream operational risk for one of Britain’s most exposed industrial sectors. The findings indicate that 78% of manufacturers were hit, while 53% said attacks led to lost revenue, underscoring how cyber breaches are moving from the server room to the production line.That threat became tangible across British
A compromise of the widely used Axios software package has triggered fresh concern over open-source security after attackers used a hijacked maintainer account to publish poisoned versions carrying remote access trojan malware for Windows, macOS and Linux systems. Security researchers said the malicious releases were pushed to npm on March 31 and removed within hours, but warned that any machine or build pipeline that installed them during that window should be treated as potentially compromised.The tainted releases were identified