Latest Arabian cybersecurity news covering global cyber threats, ransomware attacks, data breaches, digital espionage, and technology security developments affecting governments, companies and individuals.
A malicious npm dependency slipped into an AI-assisted crypto trading project has exposed how automated coding tools can be manipulated into importing software that steals credentials, wallet data and source code. The campaign, named PromptMink by security researchers, centres on the npm package @validate-sdk/v2, which presents itself as a utility for hashing, validation, encoding, decoding and random generation. Its actual function is to harvest secrets from infected developer environments, including files linked to crypto wallets, API keys and project credentials. The package
Cyber literacy has become the leading global people risk as employers confront ransomware, AI-enabled fraud, technology skills gaps and fragile workforce readiness, Marsh’s 2026 People Risks survey has found. The report, based on views from 4,517 human resources and risk professionals across 26 markets and 12 industries, places inadequate cyber threat literacy at the top of the global risk list. Technology skills shortages, including cyber and artificial intelligence capabilities, rank third, showing how quickly digital ambition is colliding with the limits
ZetaChain has paused cross-chain transactions after a smart contract attack targeted its GatewayEVM infrastructure, adding fresh pressure on interoperability projects that move assets and messages across multiple blockchains. The incident was flagged on April 27 when Blockaid warned users about an active exploit involving ZetaChain cross-chain contracts and urged anyone with approvals to GatewayEVM contracts on Ethereum, Arbitrum, Base and other EVM-compatible chains to revoke permissions immediately. ZetaChain later said the attack affected only internal team wallets, that no user funds
A hardcoded API key embedded in ClickUp’s public website exposed 959 corporate and government email addresses and more than 3,000 internal feature flags for over a year, intensifying scrutiny of security controls at widely used software-as-a-service platforms. The exposure was tied to a production JavaScript bundle that loaded before authentication, allowing anyone inspecting the page source to extract a third-party SDK token and send an unauthenticated request to a backend service. The data returned reportedly included enterprise email addresses, internal targeting
Vect 2.0 has emerged as a fast-evolving ransomware-as-a-service operation capable of striking Windows, Linux and VMware ESXi systems, raising concern among security teams responsible for hybrid corporate networks and virtualised infrastructure. The group’s latest tooling marks a shift from single-platform extortion campaigns towards attacks designed to spread across workstations, servers and hypervisors. That matters because ESXi environments often host multiple virtual machines on a single physical server, allowing one intrusion to disrupt a large part of an organisation’s operations. For companies
BlueNoroff has intensified its campaign against cryptocurrency executives by combining fake Zoom meetings, AI-generated video lures and fileless PowerShell malware in an intrusion that gave attackers access to a North American Web3 company for 66 days. The operation, first detected after an intrusion began on 23 January 2026, marks a sharper turn in North Korea-linked cyber activity against digital asset businesses. Instead of relying on crude phishing pages or malicious attachments, the attackers used a manipulated Calendly invitation, a typosquatted Zoom
Rival ransomware crews 0APT and KryBit have disrupted each other’s operations after leaking internal data, exposing an unusual cybercriminal feud that has given defenders a rare view into the infrastructure, tactics and credibility gaps behind emerging extortion groups. The confrontation began on 13 April 2026, when 0APT listed KryBit, Everest and RansomHouse as victims on its leak site. KryBit responded a day later by breaching 0APT’s infrastructure, defacing its leak site and publishing operational files that undermined 0APT’s own claims. The
North Korean state-linked hackers have intensified attacks on cryptocurrency companies by combining fake video meetings, AI-generated identities and “ClickFix” infection tactics to compromise executives, founders and staff with access to wallets, exchanges and investment infrastructure. A large spear-phishing operation attributed with high confidence to BlueNoroff, the financially motivated arm of the Lazarus Group, targeted a North American Web3 company through a manipulated calendar invitation that led to a spoofed Zoom meeting. The attack chain moved from a single click to full
Security researchers have identified a 2005-era malware framework that appears to have targeted high-precision engineering software, raising new questions about covert attempts to disrupt Iran’s nuclear programme before Stuxnet became the defining case of cyber sabotage. The malware, tracked as Fast16, was analysed by SentinelOne researchers Vitaly Kamluk and Juan Andrés Guerrero-Saade, who found that its core components pre-date the earliest known Stuxnet operations by at least five years. Their findings point to a sophisticated tool designed not to steal files
Hugging Face’s LeRobot robotics framework is facing scrutiny after disclosure of a critical remote code execution vulnerability that could allow unauthenticated attackers to run arbitrary commands on affected systems through exposed inference services. The flaw, tracked as CVE-2026-25874, affects LeRobot versions up to 0.5.1 and carries a critical CVSS 4.0 score of 9.3. The issue centres on unsafe deserialisation in the framework’s asynchronous inference pipeline, where Python’s pickle. loads() is used to process data received over gRPC channels that lack authentication
Retail and hospitality companies are facing a widening extortion campaign by BlackFile, a financially motivated hacking group using voice calls, fake helpdesk scripts and spoofed caller identities to steal credentials and force ransom negotiations. The group has been linked to attacks that began surfacing in January 2026, with sustained targeting of customer-facing businesses from February. Its activity has been tracked under several names, including CL-CRI-1116, UNC6671 and Cordial Spider, reflecting overlaps seen by different cyber-intelligence teams. Investigators assess with moderate confidence
OpenClaw has issued security updates for three vulnerabilities in its autonomous AI agent framework, warning administrators that older npm package versions could expose systems to policy bypasses, unauthorised configuration changes and API credential leakage. The flaws affect versions released before 2026.4.20, with one issue limited to versions between 2026.4.5 and 2026.4.20. The patched version tightens how the framework handles trusted operator settings, bundled tools and workspace environment variables, areas that are especially sensitive because autonomous agents often operate with access to
Fake software downloads promoted through YouTube are being used to infect corporate employees with Vidar, an information-stealing malware that harvests passwords, browser data, session cookies and cryptocurrency wallet files before stolen credentials are traded through Russian-language cybercrime markets. The campaign shows how threat actors are shifting from noisy phishing emails to search-driven lures that exploit ordinary workplace behaviour. Employees looking for software tutorials, installers or utilities on video platforms are being pushed towards links placed in video descriptions, where apparently legitimate
Cybercriminals are exploiting tax-season anxiety by circulating fake Income Tax Department notices that push taxpayers and companies towards malware-laden downloads disguised as assessment orders and compliance documents. The campaign uses official-looking emails and cloned tax portals to make recipients believe they are facing scrutiny over alleged violations, including concealment of income or inaccurate filings. Victims are directed to external websites that imitate government communication, where buttons labelled as assessment order downloads trigger malicious files instead of official documents. Security researchers tracking the
A targeted malware campaign aimed at Pakistan’s government-linked security infrastructure has exposed how threat actors are combining social engineering, obfuscated code and trusted online services to evade conventional cyber defences. The attack was directed at employees of the Punjab Safe Cities Authority and PPIC3, using a spear-phishing email that impersonated an internal consultant and referred to the Safe Jail Project, a theme designed to appear relevant to public-security operations. The message was marked as high priority and included a read-receipt request,
Anthropic’s Claude Desktop application for macOS is facing scrutiny after a cybersecurity researcher reported that the app installs a Native Messaging bridge into multiple Chromium-based browsers without a clear consent prompt, widening concern over how AI desktop agents gain access to local systems and browser sessions. Privacy researcher Alexander Hanff published his findings on 18 April 2026 after identifying a manifest file named com. anthropic. claudebrowserextension. json on a Mac where he said he had not knowingly authorised such browser integration.
OpenAI has opened a GPT-5.5 Bio Bug Bounty programme that invites selected researchers to test whether the company’s latest model can be pushed past safeguards designed to block dangerous biological guidance. The initiative offers a reward of up to $25,000 for the first verified “universal jailbreak” capable of defeating a five-question biosafety challenge from a clean chat without triggering moderation. The model in scope is GPT-5.5 in Codex Desktop, narrowing the exercise to a defined environment while giving external specialists a
Hackers have turned a critical React Server Components flaw into a structured exploitation operation, using Telegram bots, automated scanners and AI-assisted tooling to track more than 900 confirmed compromises across internet-facing applications. The campaign centres on React2Shell, tracked as CVE-2025-55182, a maximum-severity remote code execution vulnerability disclosed in December 2025. The flaw affects React 19.0, 19.1.0, 19.1.1 and 19.2.0 through packages including react-server-dom-webpack, react-server-dom-parcel and react-server-dom-turbopack, and can allow unauthenticated attackers to execute commands on vulnerable servers through crafted HTTP requests. Fresh
Cybersecurity teams running local artificial intelligence models are facing a high-risk exposure after a flaw in Ollama’s model-processing system was found to allow attackers to extract sensitive server memory through a malicious model file. Tracked as CVE-2026-5757, the vulnerability affects the model quantisation engine used by Ollama, an open-source platform widely adopted by developers and enterprises to run large language models on personal computers, workstations and servers. The flaw enables an unauthenticated attacker with access to the model upload function to
Cyber-attacks on higher and further education institutions jumped 63 per cent over a year, exposing universities and colleges to a sharper wave of ransomware, data theft, hacktivism and state-linked intrusion as digital learning systems become central to academic life. The findings point to 425 recorded incidents across 67 countries in the latest 12-month assessment period, compared with 260 in the preceding year. The rise reflects not only more aggressive criminal activity, but also the growing value of academic data, research systems
Google Cloud is placing general-purpose Gemini models at the centre of its cybersecurity strategy, betting that broad frontier AI systems paired with specialised agents will outperform narrow models built only for security tasks. The approach, articulated by Francis deSouza, Google Cloud’s chief operating officer and president of security products, signals a deliberate shift in how the company wants enterprises to defend themselves in an era of faster attacks, expanding cloud exposure and AI-enabled threat activity. Rather than building separate cybersecurity-specific language
Phishing emails with no subject line are being used with growing frequency in campaigns aimed at executives and other high-value staff, adding another layer of deception to a threat landscape already shaped by credential theft, business email compromise and AI-assisted social engineering. CyberProof said its threat hunters tracked a marked rise in “null subject” phishing through the first quarter of 2026, with activity climbing from January to March and a further increase projected into April. The tactic is simple but
Google search advertising is being exploited in a widening campaign that lures cryptocurrency users to convincing fake sites, where attackers steal seed phrases, hijack wallet sessions and drain digital assets within minutes. Security researchers tracking the operation say the abuse is no longer sporadic but part of a sustained and technically refined effort that targets people searching for DeFi services, wallet tools and other crypto platforms. What makes the campaign especially dangerous is the use of Google’s own trusted web properties
A newly disclosed cyberattack using destructive malware known as Lotus Wiper has put Venezuela’s energy and utilities sector under sharper scrutiny, highlighting how digital sabotage is moving beyond theft and extortion towards permanent operational damage. Security researchers say the malware was designed to erase data, cripple recovery options and leave affected systems unusable, signalling a far more aggressive intent than the ransomware campaigns that have dominated critical infrastructure attacks in past years. The attack chain, uncovered in malware samples uploaded
A critical security weakness in Atlassian Bamboo Data Center and Server has exposed a fresh risk for organisations that rely on automated software build and deployment systems, after Atlassian disclosed that an authenticated attacker could remotely execute operating system commands on affected installations. The flaw, tracked as CVE-2026-21571, carries a CVSS 4.0 score of 9.4 and was published in Atlassian’s April 21 security bulletin, which covered dozens of patched vulnerabilities across its product line. The issue affects multiple Bamboo release
A software platform traced to Belarus has been identified as a key enabler of a sprawling SIM-farm ecosystem that investigators say is helping cybercriminal operations run at scale across multiple continents. The platform, known as ProxySmart, was linked to at least 94 SIM-farm locations in 17 countries, with researchers identifying 87 exposed instances of its control panel across 24 proxy providers and 35 mobile carriers. The findings cast fresh light on how mobile proxy services have evolved from a niche
Britain is confronting what its cyber defence chief has described as a “perfect storm”, with fast-moving technological change colliding with rising geopolitical tension and exposing companies, public bodies and critical infrastructure to a more dangerous class of digital attack. The warning, delivered at the CYBERUK 2026 conference in Glasgow, signals a sharper threat environment in which ransomware remains widespread but the gravest strategic risks are increasingly tied to hostile states and conflict-driven disruption. Richard Horne, chief executive of the National Cyber
Unauthorized access to Anthropic’s tightly restricted Claude Mythos Preview has sharpened concerns over how even limited-release cybersecurity AI can slip beyond its intended perimeter, raising fresh questions about vendor oversight, access governance and the pace at which powerful offensive-capable tools are entering real-world environments. Anthropic announced Mythos on 7 April as part of a controlled programme for defensive cybersecurity use, and the company is now investigating claims that a small group reached the model through a third-party vendor environment. The episode
The Gentlemen ransomware operation is building momentum across the cybercrime market, drawing in more affiliates, broadening its toolset and sharpening its focus on corporate targets as security researchers trace a faster pace of attacks through the opening months of 2026. Check Point said the group has publicly claimed more than 320 victims, with about 240 of those listed this year, a pattern that points to rapid affiliate uptake rather than a small crew acting alone. That expansion matters because The
Unchecked AI agents are triggering cybersecurity incidents across a broad swathe of companies, with data exposure, disrupted operations and direct financial damage now emerging as common consequences of a fast-moving corporate shift towards autonomous software. A new industry survey found that 65% of organisations suffered at least one AI agent-related incident over the past 12 months, while 82% said they had discovered previously unknown AI agents operating inside their environments. Among those reporting incidents, 61% cited data exposure, 43% operational
Cyber criminals are using a tampered Android app to steal payment card data and PINs in a campaign that marks a more aggressive phase in near-field communication fraud, with the latest NGate malware variant targeting users in Brazil and enabling both unauthorised payments and cash withdrawals at contactless ATMs. The newly identified strain hides inside a doctored version of HandyPay, a legitimate NFC relay application, and appears to have been active since November 2025. The operation represents a notable shift in
Lovable, the fast-growing AI app builder used by startups and large corporate teams alike, is facing scrutiny after security researchers said an API authorisation flaw exposed sensitive data from projects created before November 2025, including source code, credentials, chat histories and customer records. The company has disputed the characterisation of the incident as a data breach, arguing that some of the visibility tied to public projects reflected product design and unclear documentation rather than unauthorised intrusion. The disclosure has drawn
Grinex, a Kyrgyzstan-based cryptocurrency exchange under Western sanctions, has suspended operations after losing about one billion roubles, or roughly $13.1 million, in what it described as a highly organised cyber attack. The platform said the breach was a targeted operation and alleged that intelligence services from “unfriendly” Western states were behind it, though it did not provide public evidence to support that claim. The theft has drawn attention because Grinex sits at the intersection of cybercrime, sanctions evasion and Russia’s
Windows users are facing a sharper cyber threat after researchers identified a campaign that pairs the long-running Gh0st remote access trojan with CloverPlus adware, giving attackers a mix of covert control and instant income from poisoned web traffic. The operation uses a single obfuscated loader to unpack both payloads, turning one infection into a dual-purpose compromise that can spy, persist and monetise at the same time. Two payloads, one foothold marks the campaign as more than a routine adware outbreak.