Latest Arabian cybersecurity news covering global cyber threats, ransomware attacks, data breaches, digital espionage, and technology security developments affecting governments, companies and individuals.
Hackers leveraged a critical vulnerability in the open-source AI workflow platform Langflow within hours of its disclosure, underscoring a sharp acceleration in cyberattack timelines and raising fresh concerns over the security of rapidly adopted artificial intelligence tools.Security researchers reported that attackers moved to exploit the flaw roughly 20 hours after public details emerged, highlighting how threat actors are monitoring disclosures in real time and deploying automated tools to weaponise weaknesses at unprecedented speed. The incident reflects a broader trend in
A sharp escalation in mobile banking malware attacks targeting more than 1,200 financial brands across 90 countries is altering the global fraud landscape, with security experts warning that user devices have become the primary entry point for cybercriminals.Industry researchers tracking digital fraud patterns say the scale and sophistication of mobile-focused threats have expanded markedly, reflecting a shift away from traditional server-side breaches towards attacks that exploit weaknesses on smartphones. These campaigns are increasingly capable of bypassing conventional safeguards, enabling attackers
Cybersecurity strategies built around prevention are facing renewed scrutiny as organisations grapple with a wave of disruptive attacks targeting cloud infrastructure, exposing weaknesses in how resilience is designed and implemented.Security analysts and industry leaders say the shift to cloud computing has outpaced the evolution of defensive frameworks, leaving many enterprises vulnerable not because they lack protection tools, but because they underestimate the importance of operational continuity under attack. Ransomware campaigns, data exfiltration incidents and large-scale outages have demonstrated that systems
Security weaknesses in Jenkins and a widely used plugin have raised fresh concerns over the resilience of software development pipelines, with researchers warning that attackers could exploit the flaws to gain deep access to enterprise systems.The vulnerabilities, disclosed through an official advisory from the Jenkins project, affect the core automation server as well as the LoadNinja plugin, a tool used for performance testing. Security analysts indicate that the issues could allow malicious actors to create arbitrary files, expose sensitive credentials
A security weakness in Ubuntu Desktop 24.04 and later versions has raised fresh concerns over the resilience of widely used Linux environments, after researchers confirmed that local attackers can exploit the flaw to gain full administrative control. The vulnerability, described as a local privilege escalation issue, allows a user with limited access to elevate permissions and execute commands as the root user, effectively compromising the entire system.Cybersecurity analysts indicate that the flaw affects default installations, making it particularly significant for
Authorities across multiple jurisdictions have dismantled a vast network of compromised Internet of Things devices linked to some of the largest distributed denial-of-service attacks ever recorded, with traffic surges reaching an estimated 30 terabits per second.The coordinated operation targeted command-and-control infrastructure that enabled four separate botnets to orchestrate high-volume cyber assaults on critical digital services worldwide. Investigators said the infrastructure had been used to overwhelm servers, disrupt platforms and extort organisations by threatening prolonged outages.Law enforcement agencies worked alongside cybersecurity
Navia Benefit Solutions has disclosed a large-scale data breach affecting nearly 2.7 million individuals, raising concerns over the security of sensitive employee benefits data held by third-party administrators across the United States.The company, which manages health savings accounts and other workplace benefit programmes for more than 10,000 employers, said unauthorised actors gained access to parts of its systems, exposing a broad range of personal and health-related information. The incident places it among the more significant breaches involving benefits administrators, a
A zero-day vulnerability in widely deployed Cisco firewall systems has been exploited for months by a ransomware group, with security teams warning that the breach highlights deep gaps in enterprise network defences and patch management practices.Analysis by Amazon Web Services’ security leadership indicates that attackers began abusing the flaw as early as January, gaining unauthorised access to targeted environments before the vulnerability became publicly known. The disclosure has raised concern among corporate security teams, particularly given the scale of Cisco’s
A banking malware strain known as Horabot has re-emerged in Mexico with a more sophisticated infection chain, combining phishing emails, deceptive CAPTCHA prompts and automated email propagation techniques to compromise victims and harvest financial data.Cybersecurity analysts tracking the campaign say the latest iteration marks a significant evolution in both delivery and persistence. The malware is being distributed through carefully crafted phishing emails that appear to originate from legitimate contacts, a tactic that increases the likelihood of user interaction and bypasses
A coordinated cybercrime operation built around a fraudulent cryptocurrency tool branded “ShieldGuard” has been dismantled after investigators confirmed it functioned as a malicious browser extension harvesting user credentials and digital assets. Security researchers say the campaign had been active across multiple platforms, targeting retail crypto investors through deceptive online promotions and fake security assurances.The extension, presented as a protective utility for safeguarding cryptocurrency wallets, was distributed through unofficial browser marketplaces and phishing sites designed to mimic legitimate download portals. Once
A newly identified Android attack technique that alters the operating environment rather than modifying applications has raised fresh concerns over the resilience of mobile payment systems, with researchers warning that conventional app-level protections may no longer be sufficient.Security analysts at CloudSEK have detailed a method that leverages a framework known as LSPosed to manipulate how Android apps behave at runtime. Instead of injecting malicious code directly into banking or payment applications, the technique hooks into the system layer, allowing attackers
Security researchers have identified a technique that could allow attackers to execute malicious code within AI-assisted development environments by manipulating installation links, raising fresh concerns about the integrity of modern coding workflows.The method, termed “CursorJack”, exploits how some AI development tools handle external package installation and repository linking. By redirecting or tampering with these links, attackers can introduce harmful code into a developer’s environment without immediate detection. The vulnerability highlights a growing attack surface as software engineers increasingly rely on
Cybersecurity analysts have uncovered a method that enables attackers to bypass behavioural protections in Palo Alto Networks’ Cortex XDR platform, raising fresh concerns over the resilience of endpoint detection systems widely used by enterprises.The findings centre on the platform’s Behavioural Indicators of Compromise, or BIOC rules, which are designed to identify suspicious activity beyond traditional signature-based detection. Researchers demonstrated that these rules, distributed in encrypted form within the Cortex XDR agent, could be decrypted and examined, allowing adversaries to understand
Gaps between on-premise and cloud identity systems are creating a growing security blind spot, as organisations adopting hybrid Active Directory environments struggle to maintain consistent user credentials across platforms. Security analysts warn that “identity drift” — a condition where user attributes, permissions or credentials fall out of sync between systems — is emerging as a critical vulnerability in enterprise infrastructure.Hybrid identity setups, commonly built around Microsoft’s Active Directory integrated with cloud services such as Azure Active Directory, have become standard
Security researchers have uncovered a vulnerability in Amazon Web Services Bedrock’s code interpreter environment, raising concerns over the robustness of isolation safeguards in generative AI systems and prompting renewed scrutiny of cloud-based development tools used by enterprises.The flaw, identified in Bedrock’s sandboxed execution layer, centres on weaknesses in DNS handling that could allow data exfiltration from supposedly isolated environments. Analysts say the issue highlights structural challenges in how large-scale AI platforms enforce boundaries between user workloads and underlying infrastructure, particularly
A coordinated international law enforcement operation has dismantled SocksEscort, a large malicious proxy service that enabled cybercriminals to hide their identities while carrying out fraud, ransomware attacks and other online crimes. The operation, codenamed Operation Lightning, targeted infrastructure spread across multiple countries and led to the seizure of dozens of domains and servers used to run the network.Authorities said the proxy service relied on malware that infected home and small-business routers, silently turning them into part of a vast
A sophisticated malware operation targeting software developers has expanded its reach by exploiting trusted extension ecosystems, with security researchers uncovering dozens of malicious packages distributed through the Open VSX marketplace. The campaign, known as GlassWorm, now relies on hidden transitive dependencies to introduce malicious code into developer environments, marking a notable shift in tactics within the growing wave of software supply-chain attacks.Security analysts have identified at least 72 malicious extensions linked to the campaign, many of which appear legitimate at
A sophisticated strain of Android malware capable of diverting real-time payments has emerged as a major cybersecurity concern in Brazil, exploiting the country’s widely used PIX instant payment platform and highlighting the risks attached to rapidly expanding digital payment ecosystems.Cybersecurity researchers say the malware, dubbed PixRevolution, hijacks transactions at the exact moment a user sends money through PIX, redirecting funds to accounts controlled by criminals while the victim sees what appears to be a normal confirmation screen. The technique exploits
Global medical technology manufacturer Stryker has been hit by a major cyberattack claimed by an Iran-linked hacker collective, triggering widespread disruption to corporate systems and raising fresh concerns about cyber warfare spilling into commercial infrastructure.The group, calling itself Handala, said it carried out a destructive operation that wiped data across more than 200,000 company devices while extracting roughly 50 terabytes of information from internal networks. The incident disrupted internal communications, disabled corporate laptops and phones, and forced employees in multiple
Cybersecurity researchers have uncovered a series of critical vulnerabilities affecting Google’s Looker data analytics platform that could have enabled attackers to execute malicious code, move between cloud environments and extract sensitive corporate data. The flaws highlight growing security concerns surrounding widely used cloud-based analytics tools that sit at the centre of many organisations’ data infrastructure.Security specialists from the cybersecurity firm Tenable identified two major vulnerabilities—collectively dubbed “LookOut”—that could potentially allow attackers to take control of Looker servers or access internal
Cyber-criminals have compromised hundreds of legitimate WordPress websites in a global operation designed to infect unsuspecting visitors with information-stealing malware, raising fresh concerns about the security of widely used web platforms and the increasing sophistication of social-engineering attacks.Threat researchers at cybersecurity firm Rapid7 say attackers infiltrated more than 250 websites across at least 12 countries, including the United Kingdom, United States, Germany, Canada, Australia, Brazil, Israel and India. The infected pages include regional news portals, small business sites and even
Ripple Labs is preparing to obtain an Australian Financial Services Licence through the acquisition of payments firm BC Payments, a step aimed at strengthening the company’s regulatory standing and expanding its cross-border services in the country’s financial sector.The blockchain payments company plans to complete the deal on 1 April, allowing it to gain access to the licence framework regulated by the Australian Securities and Investments Commission. Holding an Australian Financial Services Licence, commonly known as AFSL, permits firms to provide
Security vulnerabilities discovered in the open-source Pingora framework have triggered renewed scrutiny of infrastructure software used to route vast volumes of internet traffic, after researchers warned the flaws could allow attackers to manipulate web requests and poison caches in certain deployments.Cloudflare disclosed multiple weaknesses affecting standalone Pingora installations exposed directly to the internet, warning that attackers could exploit them to conduct HTTP request smuggling and cache poisoning attacks. The vulnerabilities, tracked as CVE-2026-2833, CVE-2026-2835 and CVE-2026-2836, arise from flaws in
OpenAI has agreed to acquire Promptfoo, a fast-growing artificial intelligence security platform, in a move aimed at strengthening the safety and reliability of enterprise AI systems as companies accelerate the deployment of autonomous agents and generative models across critical operations.The acquisition will bring Promptfoo’s specialised testing and vulnerability-detection technology into OpenAI’s enterprise environment, known as OpenAI Frontier, a platform designed to help organisations develop and operate AI-powered assistants and agents. Financial terms of the deal have not been disclosed. The
Yoma Fleet, one of Myanmar’s largest fleet management and leasing companies, has adopted a security information and event management platform from AccuKnox in a move aimed at strengthening protection of its digital operations and replacing older monitoring tools.The agreement positions the Menlo Park–based cybersecurity company as a key technology partner for Yoma Fleet, which manages thousands of vehicles across Myanmar for corporate clients, logistics operators and ride-hailing services. Executives say the deployment of AccuKnox’s SIEM system is designed to provide
Cybersecurity researchers have uncovered a malicious software package disguised as a legitimate developer tool that quietly installs an advanced data-stealing program on victims’ machines, raising fresh concerns about software supply-chain attacks targeting programmers and technology companies.Security analysts say a rogue npm package named @openclaw-ai/openclawai impersonates the legitimate OpenClaw command-line interface, a tool designed to help developers manage artificial-intelligence agents and related workflows. The counterfeit package installs a sophisticated infostealer and remote-access trojan that investigators have internally labelled “GhostLoader”, enabling attackers
Cybersecurity researchers have identified a sophisticated espionage campaign linked to China-aligned threat actors that is targeting organisations in Qatar, using malware associated with the PlugX family and exploiting heightened geopolitical tensions in the Middle East to lure victims.Security analysts say the operation demonstrates how advanced persistent threat groups quickly integrate global events into cyber-espionage strategies. The campaign relies on carefully crafted phishing documents and malicious attachments designed to appear relevant to political developments and regional security concerns, increasing the likelihood
Ethereum has drawn a significant influx of stablecoin liquidity, with about $523 million flowing into the network over a short period, strengthening expectations that the digital asset could test a key resistance zone near $2,142 as trading momentum gathers pace across the broader cryptocurrency market.Blockchain data indicates that large transfers of dollar-pegged stablecoins into the Ethereum ecosystem have accelerated trading activity and boosted liquidity conditions on decentralised exchanges and lending platforms. Market participants interpret such inflows as a signal that
Global networks faced more than eight million distributed denial-of-service attacks during the second half of 2025, underscoring a sharp escalation in the scale and coordination of cyber disruption campaigns as attackers deploy increasingly sophisticated techniques to overwhelm digital infrastructure.Findings released by cyber-security firm NETSCOUT Systems indicate that attackers are exploiting automation, botnets and artificial intelligence-assisted tactics to launch large volumes of disruptive traffic against businesses, governments and service providers. The report highlights a surge in complex, multi-vector attacks designed to
Processing an ordinary-looking photograph could silently trigger malicious code on macOS systems due to a newly disclosed vulnerability in widely used metadata software, raising fresh concerns about the security of open-source components embedded in everyday digital workflows.Cybersecurity researchers have identified a flaw in ExifTool, a popular open-source tool used globally to extract, read and edit metadata in images, videos and other digital files. The vulnerability, tracked as CVE-2026-3102, allows attackers to embed harmful commands within an image’s metadata so that
A critical security weakness affecting several surveillance and video management products manufactured by Hikvision has triggered alarm among cybersecurity agencies after authorities confirmed that attackers are exploiting the vulnerability to gain elevated access to targeted systems.Federal cybersecurity officials added the flaw to the Known Exploited Vulnerabilities catalogue maintained by the Cybersecurity and Infrastructure Security Agency, a list used by government and private-sector defenders to prioritise urgent security patches. The entry highlights a vulnerability that allows threat actors to escalate privileges
Security researchers have disclosed a vulnerability affecting a widely used platform that supplies contextual data to artificial intelligence coding assistants, exposing developers to potential malicious instructions embedded in documentation and external resources.The weakness, labelled “ContextCrush,” was identified by researchers at Noma Labs in the Context7 platform operated by Upstash. Context7 is designed to feed documentation and technical material to AI-powered development tools so they can generate or modify software code. Developers commonly use such systems alongside assistants like Cursor, Claude
A coalition of seven Western governments has released a set of cybersecurity guidelines aimed at shaping the development of sixth-generation wireless networks, seeking to embed security principles into the architecture of the technology long before it reaches commercial deployment.Authorities from the United States, United Kingdom, Australia, Canada, Japan, South Korea and Germany jointly issued the framework, outlining how security-by-design practices should guide the evolution of 6G standards. Officials involved in the initiative say the document is intended to influence the
Thousands of internal records linked to digital currency transactions have surfaced online, offering a rare glimpse into how financial networks connected to Iran may have used cryptocurrency platforms to navigate international sanctions. The leaked database, analysed by cybersecurity researchers and blockchain investigators, contains transaction logs, account identifiers and operational notes tied to exchanges and wallet services believed to have facilitated transfers linked to entities operating under restrictions imposed by the United States and other Western governments.Details emerging from the dataset