Category: Cybersecurity

Latest Arabian cybersecurity news covering global cyber threats, ransomware attacks, data breaches, digital espionage, and technology security developments affecting governments, companies and individuals.

ADVERTISEMENT
ADVERTISEMENT

Chinese state-backed hackers have stepped up espionage operations against European government targets after shifting attention away from the region for much of the period after 2023, according to new threat intelligence that points to a sustained campaign aimed at diplomatic missions, NATO-linked networks and European Union institutions. Researchers tracking the activity said the actor known as TA416 returned to European targeting in the middle of 2025 and continued through early 2026, using a mix of phishing, web beacons and malware

A supply-chain attack on the widely used Axios JavaScript library has raised fresh concern over the fragility of open-source software distribution after attackers slipped malicious code into two versions of the package and exposed Windows, macOS and Linux systems to remote compromise. Security researchers and Google’s threat intelligence team said poisoned Axios releases 1.14.1 and 0.30.4 were pushed to npm during a narrow window on March 31, after a maintainer account was hijacked and used to publish unauthorised updates.The

Security teams are scrambling after two malicious releases of the Telnyx Python SDK were uploaded to PyPI on March 27, turning a widely used developer tool into a credential-stealing backdoor that could execute as soon as the library was imported. The compromised versions, 4.87.1 and 4.87.2, were published at 03:51 UTC and quarantined by 10:13 UTC, leaving a window of a little over six hours in which developers and automated build systems could have pulled the tainted package.What makes

 Breaches involving employee information reported to the UK’s data regulator climbed again in 2025, reaching their highest level since the Information Commissioner’s Office began publishing comparable incident data in 2019, according to an analysis by law firm Nockolds that draws on ICO reporting. The rise adds to mounting concern among employers that staff records, payroll details and internal HR files are becoming harder to protect as hybrid working, third-party systems and everyday handling errors widen the points of exposure.The trend

Federal prosecutors have charged a Maryland man with carrying out two 2021 attacks on Uranium Finance that drained more than $53 million from the decentralised crypto exchange, a case that is drawing fresh attention to long-running weaknesses in decentralised finance and to the growing ability of authorities to follow money through blockchain networks.The accused, Jonathan Spalletta, 36, of Rockville, Maryland, surrendered on March 30 after an indictment was unsealed in the Southern District of New York. Prosecutors allege that

 EvilTokens, a newly identified phishing-as-a-service operation, is offering cybercriminals a ready-made way to hijack Microsoft accounts by abusing a legitimate sign-in process rather than stealing passwords through fake login pages. The service centres on Microsoft’s device code flow, a method designed for televisions, printers and other input-constrained devices, and researchers say the toolkit has been active since the middle of February.What makes the platform notable is not only the technique but the degree of industrialisation around it. Researchers tracking the

Hackers are weaponising trusted Windows administration tools and signed but vulnerable drivers to switch off antivirus and endpoint detection systems before launching ransomware, a tactic that is making intrusions quieter, faster and more difficult for defenders to stop. Security researchers and government-backed advisories say attackers are increasingly avoiding noisy custom malware in the opening stages of an attack, instead leaning on built-in utilities, service controls, scripts and legitimate remote administration frameworks that are already present in many corporate environments.The

Claude, Anthropic’s large language model, has been thrust into the centre of a fresh debate over software security after researchers at Calif said it helped uncover code-execution flaws affecting Vim and GNU Emacs, two of the most widely used text editors in development and research circles. The disclosure, published on March 30, said a malicious file could trigger arbitrary commands when opened, turning a routine act into a possible compromise path for a user’s machine.The clearest part of the

CareCloud, a US healthcare technology company, has disclosed that hackers gained unauthorised access to part of its electronic health record infrastructure, triggering fresh scrutiny of cyber resilience across a sector already under pressure from mounting digital attacks and tighter regulatory expectations. The company said the incident was detected on March 16, 2026, after a network disruption in its CareCloud Health division affected one of its six electronic health record environments for about eight hours before services were restored later that

Lloyds Banking Group has disclosed that an IT defect exposed the personal data of up to 447,936 customers after a faulty overnight software update allowed some mobile app users to see other people’s current-account transactions. The incident, which affected the Lloyds, Halifax and Bank of Scotland apps on 12 March, has intensified scrutiny of operational resilience at major lenders as more banking activity shifts to digital channels.The bank told the UK Treasury Committee that the problem ran between 03:28

Online anonymity is facing a sharper threat as new research suggests large language models can now identify pseudonymous internet users at scale by combining fragments of public writing with broader online data. The warning comes from a February 2026 preprint by Simon Lermen and co-authors at ETH Zurich, Anthropic and the Machine Learning Alignment and Theory Scholars programme, which argues that the “practical obscurity” that once protected many users online is eroding fast.The study tested whether AI systems could

Distributed denial-of-service attacks gathered dangerous momentum in the second half of 2025, with a new industry report showing incidents rising 150 per cent year on year as both volume and velocity increased, underscoring how quickly cyber disruption is moving from episodic nuisance to board-level operational risk. The findings point to a sharp escalation in late 2025, when total attacks climbed to about 1.3 million in the fourth quarter from 512,000 a year earlier, while peak attack volume rose to 12

A newly documented BlankGrabber infection chain is using a bogus “certificate” loader to disguise a multi-stage Windows compromise, adding another layer of deception to a commodity stealer already known for targeting browser credentials, crypto wallets and messaging sessions. Security researchers say the campaign abuses certutil. exe, a legitimate Windows utility, to make malicious code appear routine, while later stages rely on Rust, Python and packed archives to stay hidden from static scans and frustrate analysts.The technique was detailed by

Oracle WebLogic operators are under pressure to close a critical security gap after attackers began probing and exploiting a newly disclosed flaw on the same day public exploit code appeared, according to a honeypot study that tracked activity against a vulnerable WebLogic environment over 12 days. The vulnerability, tracked as CVE-2026-21962, carries a CVSS severity score of 10.0 and affects Oracle HTTP Server and the WebLogic Server Proxy Plug-in used with Apache HTTP Server and, in one case, IIS.The

A critical weakness in Open VSX’s new pre-publication scanning system allowed malicious extensions to pass security checks and become publicly available, raising fresh concerns over the safety of a software marketplace relied on by Cursor, Windsurf and other tools built on the VS Code extension ecosystem. The flaw, dubbed “Open Sesame” by Koi Security, has been patched, with Open VSX maintainers fixing it in version 0.32.0 after the issue was reported on 8 February.The vulnerability lay in the logic

The European Commission has confirmed a cyberattack on cloud infrastructure supporting parts of the Europa. eu web platform, with the intrusion discovered on March 24 and swiftly contained as investigators assess whether data was taken from affected public-facing services. The Commission has said its internal systems were not hit.The breach centres on a compromised Amazon Web Services account used to host elements of the Commission’s web presence. Officials have not publicly identified any suspect, nor have they set out the

Hundreds of organisations using Microsoft 365 are facing a fast-growing phishing threat that sidesteps conventional multi-factor authentication controls by abusing a legitimate Microsoft sign-in process rather than breaking it. Security researchers tracking the activity say more than 340 organisations across the United States, Canada, Australia, New Zealand and Germany have been affected, with attacks accelerating through March after the first known cases were detected on February 19.The campaign centres on what security specialists call device code phishing, a technique that

A ransomware group linked to Tehran has reappeared with upgraded capabilities, raising concern among cybersecurity researchers who say the threat actor is deploying more sophisticated techniques to evade detection and disrupt organisations across multiple sectors.Security analysts tracking the group known as Pay2Key report that its latest campaigns show marked improvements in execution methods, stealth mechanisms and anti-forensics tactics. The group, which gained attention during earlier waves of ransomware attacks, had largely fallen silent before its renewed activity signalled a strategic

Threat actors are refining a deceptive cyberattack method that manipulates built-in system utilities on both Microsoft Windows and Apple macOS to deploy malicious software, marking a shift in how malware bypasses browser-based security safeguards.Security researchers have identified a coordinated campaign centred on a technique known as ClickFix, which prompts users to execute seemingly harmless commands through the Windows Run dialogue or macOS Terminal. By moving the final stage of execution outside the browser environment, attackers are able to evade conventional

Artificial intelligence is emerging as the defining battleground in global cybersecurity, with defenders racing to counter increasingly sophisticated threats as cyber criminals adopt the same technologies to scale and sharpen their attacks.A report by PwC highlights how malicious actors are integrating AI into core operations, enabling even relatively inexperienced hackers to launch complex campaigns that once required advanced technical expertise. The shift is altering the threat landscape, forcing organisations to rethink traditional security frameworks and accelerate investment in AI-driven defences.Security

Cybersecurity researchers have identified an evolving macOS-focused malware strain, dubbed GhostClaw, that is leveraging developer platforms and artificial intelligence-assisted workflows to steal sensitive credentials and deploy additional malicious payloads.Security analysts tracking the campaign say the threat represents a shift in tactics, combining traditional social engineering with newer distribution channels tied to software development ecosystems. The malware has been observed circulating through code repositories that appear legitimate, including tools marketed as trading bots, software development kits and productivity utilities, making detection

Cisco has issued urgent security updates to address a critical vulnerability in its Secure Firewall Management Center software that could allow attackers to execute arbitrary code on affected systems without authentication, raising concerns across enterprise and government networks that rely on the platform for threat monitoring and control.The vulnerability, identified as CVE-2026-20131, carries a maximum severity score of 10.0 under the Common Vulnerability Scoring System, indicating a flaw that is both easy to exploit and capable of causing significant

San Francisco played host to a decisive moment for the cybersecurity industry as winners of the 2026 Cybersecurity Excellence Awards were unveiled during the RSA Conference, highlighting a sharp pivot toward artificial intelligence-driven security as the sector’s defining battleground.Organised by Cybersecurity Insiders, the awards recognised companies, technologies and professionals demonstrating leadership across a broad range of categories. This year’s results underscored the growing urgency surrounding AI governance, automated threat detection and protection against machine-led attacks, areas that attracted the highest

Security researchers are raising concerns over a growing wave of browser extensions that covertly capture and transmit users’ interactions with artificial intelligence tools, exposing sensitive prompts and responses without clear consent.Cybersecurity firm Expel highlighted the threat in a detailed analysis published on 24 March, warning that certain extensions operating within Google Chrome can quietly monitor inputs typed into AI platforms and relay them to external servers. The activity, often undetected by users, has prompted fears that confidential business information, proprietary

Banks and cybersecurity teams are confronting a sharp rise in financial fraud linked to the growing use of cloud phone technology, a system that allows users to operate mobile devices remotely through servers housed in data centres. Security analysts warn that the model, originally developed for legitimate testing, automation and business continuity, is now being exploited by fraud networks to bypass safeguards and scale attacks across borders.Cloud phones, sometimes referred to as virtual mobile devices, enable individuals to control multiple

Malicious Google advertisements linked to tax-related searches are being used to distribute a sophisticated attack chain that disables endpoint security tools before granting attackers remote control of compromised systems, according to cybersecurity researchers. The campaign, identified by Huntress, combines social engineering with a “bring your own vulnerable driver” technique to bypass detection systems and establish persistent access.Investigators found that sponsored search results tied to queries such as “W-2 tax form” and “W-9 tax forms 2026” redirected users to convincing websites

Malicious actors are exploiting search engine rankings to distribute trojanised software installers that deploy the AsyncRAT remote access tool, in a campaign that has expanded steadily since October 2025 and now targets more than two dozen widely used applications.Security analysts tracking the operation say attackers are manipulating search optimisation techniques to push fraudulent download portals to the top of results pages, increasing the likelihood that unsuspecting users install compromised versions of legitimate software. The scheme hinges on impersonating trusted brands,

Cybersecurity researchers are tracking an expansion of the MioLab infostealer targeting macOS systems, signalling a shift in cybercrime operations towards Apple devices as their adoption widens across corporate and consumer environments. The malware, also known in underground circles as Nova, is being marketed as a Malware-as-a-Service offering, allowing threat actors with limited technical expertise to deploy sophisticated attacks against macOS users.Analysts describe MioLab as a modular and evolving threat designed to extract sensitive information, including browser credentials, cryptocurrency wallet data,

Organisations faced a steep escalation in cyber threats targeting application programming interfaces, with average daily API attacks per enterprise climbing to 258 in 2025, marking a 113% increase from 121 the previous year, according to industry cybersecurity assessments tracking enterprise network activity.The data underscores a widening attack surface as businesses deepen reliance on APIs to connect cloud services, mobile applications and third-party platforms. Analysts say the growth reflects both the expansion of digital ecosystems and the increasing sophistication of attackers

Remote working has emerged as a key vulnerability in the UAE’s digital landscape, prompting authorities to warn of a sharp rise in cyber attacks targeting individuals operating outside traditional office networks.The UAE Cyber Security Council has called on employees working from home to act as the “first line of defence”, stressing that human error and weak personal security practices are increasingly being exploited by cybercriminals. Officials indicated that phishing attempts, ransomware campaigns and credential theft have all gained traction as

Cheap IP-KVM devices widely used in enterprise environments have been found to contain critical security vulnerabilities that could allow attackers to seize low-level control of entire networks, according to findings from multiple cybersecurity researchers.The flaws, identified across several budget remote management products, enable attackers to bypass standard security protections and gain direct access to connected systems at the BIOS level. Once compromised, a single IP-KVM device can effectively grant full keyboard, video and mouse control over multiple servers, turning what

A new strain of the malware-as-a-service infostealer known as VoidStealer has introduced a technique that allows attackers to extract sensitive data from Google Chrome without relying on privilege escalation or code injection, marking a shift in how browser security defences are being bypassed.Security researchers tracking the campaign say the updated variant leverages a debugger-based method to defeat Chrome’s Application-Bound Encryption, a protection designed to secure stored credentials and cookies. Instead of exploiting system-level vulnerabilities or injecting malicious code into browser

A coordinated supply chain attack targeting the Node Package Manager ecosystem has exposed a new level of automation and persistence, with threat actors hijacking trusted publisher accounts to distribute malicious code across widely used software libraries. Security researchers tracking the campaign, known as “CanisterWorm,” say it relies on stolen access tokens and compromised namespaces to infiltrate development pipelines without immediate detection.The campaign has been linked to a group identified as “TeamPCP,” which has systematically targeted maintainers of popular npm packages.

Sticker prices for website domains are drawing fresh scrutiny after a developer’s account of soaring renewal fees for a. online address highlighted what analysts describe as a structural imbalance in the domain name market, where low entry costs can mask significantly higher long-term expenses.The case centres on a developer who secured a. online domain at a heavily discounted introductory rate, only to face a sharp increase at renewal. While such pricing structures are disclosed in registration terms, the scale of

Social Media Auto Publish Powered By : XYZScripts.com