Latest Arabian cybersecurity news covering global cyber threats, ransomware attacks, data breaches, digital espionage, and technology security developments affecting governments, companies and individuals.
Two separate phishing campaigns are hitting organisations with Formbook, a long-running information stealer that continues to adapt its delivery methods to slip past traditional Windows defences. The latest activity shows attackers pairing ordinary email lures with layered obfuscation, trusted system tools and DLL side-loading, giving a familiar malware family fresh room to operate inside corporate environments. Stealthy Formbook waves target Windows users Security researchers tracking the campaigns say each attack chain uses a different infection route, but both are designed to end
A legitimate Intel storage utility has been repurposed in a highly targeted malware campaign that uses a little-known. NET mechanism to run hostile code inside a signed executable, giving attackers a quieter path into corporate networks and making detection far harder for many security products. The operation, identified as PhantomCLR, has been observed against financial institutions and other organisations across the Middle East and the wider EMEA region. At the centre of the intrusion is IAStorHelp. exe, a genuine Intel Rapid
Anthropic’s Model Context Protocol, a fast-growing standard used to connect AI models with external tools and data, has come under intense scrutiny after security researchers disclosed a critical weakness that they say can open the door to arbitrary remote code execution across a broad swathe of the AI software stack. The issue, published on April 15, centres on how MCP implementations handle STDIO-based server configurations and command execution paths. Researchers argue the flaw is not a narrow bug in a single
Anthropic’s Claude Opus has been thrust into a fresh security debate after researcher Mohan Pedhapati said he used the model to help build a working V8 exploit chain that achieved code execution against an outdated Chromium build bundled with Discord. Pedhapati, CTO of Hacktron and known online as s1r1us, said the exercise ran over about a week, consumed 2.3 billion tokens, cost $2,283 in API fees and ended with a proof-of-concept that launched Calculator on an Apple Silicon Mac. The
A leaked Google API key was used to drive more than €54,000 of Gemini compute charges in about 13 hours after attackers exploited an unrestricted Firebase browser key, according to a complaint posted on Google’s own AI developers forum, sharpening concerns over how older public-facing keys can become valid credentials for newer AI services. The affected user said an €80 budget alert and a cost anomaly alert both arrived only after spending had already climbed to about €28,000, with the
A sweeping international law-enforcement campaign has disrupted one of the cybercrime market’s most accessible attack models, with authorities saying Operation PowerOFF warned more than 75,000 suspected users of distributed denial-of-service-for-hire services, took down 53 domains, issued 25 search warrants and made four arrests during a coordinated action week on 13 April. The effort, backed by Europol and involving agencies from 21 countries, targeted both the operators and customers of so-called booter platforms that let users pay to overwhelm websites and
International law enforcement agencies have disrupted dozens of websites linked to paid cyberattack services, arrested four suspects and sent warning notices to more than 75,000 alleged users in one of the broadest crackdowns yet on the market for rented distributed denial-of-service attacks. The coordinated effort, announced on April 16, was carried out under Operation PowerOFF and involved authorities from 21 countries targeting so-called “booter” and “stresser” platforms that let customers pay to knock websites and online services offline. The latest
Hackers are probing older TP-Link home routers in an effort to turn them into Mirai-style botnet nodes, using a known command-injection flaw tracked as CVE-2023-33538. Security researchers say the activity targets discontinued router models and appears to be automated, with scanning and exploit attempts designed to fetch and run malware on exposed devices. The flaw itself is genuine and serious, even though some of the attack traffic observed so far contains coding errors that would stop the infection chain from
Search poisoning aimed at users looking for the open-source recovery utility TestDisk is being used to slip a trojanised installer on to Windows machines, abuse a Microsoft-signed binary for DLL sideloading and install ConnectWise ScreenConnect, giving attackers remote access under the cover of a legitimate administration tool. The campaign centres on a rogue site, testdisk. dev, that imitates the branding and download flow of the genuine TestDisk project while steering victims away from CGSecurity, the real home of the software.
Bluesky suffered a second day of disruption after what the company described as a coordinated distributed denial-of-service attack, leaving many users unable to reliably load feeds, notifications, threads and search results while engineers worked to stabilise the social platform. Bluesky said the trouble began late on April 15 and intensified through April 16, adding that it had found no evidence of unauthorised access to private user data. The outage quickly became a test of Bluesky’s pitch as a more open
OpenClaw’s rapid rise from an open-source personal assistant to a flashpoint in boardroom and regulatory discussions has turned the software into one of the clearest illustrations yet of the cybersecurity dangers surrounding agentic AI. Security specialists, regulators and large technology firms are converging on the same point: the problem is no longer limited to what an AI model can say, but what an AI agent can do once it is given tools, permissions and live access to workplace systems. The
Cookeville Regional Medical Center has begun notifying 337,917 people that personal and medical information was exposed after a ransomware attack discovered on 14 July 2025, a breach that has taken about nine months to fully assess and disclose at scale. The Tennessee hospital said an unauthorised third party accessed or acquired files between 11 July and 14 July 2025, with the compromised data varying by individual and including names, addresses, dates of birth, Social Security numbers, driving licence numbers, financial
Ukrainian municipal authorities and healthcare institutions have come under a coordinated wave of cyberattacks that security officials say was designed to steal sensitive information from web browsers and WhatsApp accounts, widening concern over espionage operations aimed at essential public services during wartime. The campaign, attributed by Ukraine’s Computer Emergency Response Team to threat cluster UAC-0247, struck local government bodies and municipal medical facilities, including clinical and emergency hospitals, over March and April. Investigators say the operation relied on phishing emails crafted
Cyber criminals are pushing a Windows information stealer called NWHStealer through bogus software downloads that masquerade as Proton VPN installers, gaming mods and hardware utilities, in a campaign that security researchers say relies less on classic phishing and more on users searching for tools they believe are legitimate. Malwarebytes said on April 15 that it had identified multiple active distribution chains tied to the stealer, with malicious files turning up on fake websites, code-hosting platforms and file-sharing services. The campaign
Cyber attackers are abusing the low-code automation platform n8n to push malware and track targets through phishing emails, in a campaign that security researchers say gathered pace between October 2025 and March 2026 and reflects a broader shift in how legitimate cloud tools are being repurposed for intrusion activity. Cisco Talos said it observed a sharp increase in emails containing n8n webhook links, with March 2026 volumes about 686 per cent higher than in January 2025. The activity matters because
Attackers are exploiting trust in Adobe’s brand to deliver covert remote access, using a fake Acrobat Reader download page to install ConnectWise ScreenConnect through a fileless, memory-heavy attack chain that is designed to leave few traces on disk and make forensic analysis harder. Security researchers who uncovered the campaign said the operation began with a phishing site made to resemble Adobe’s official software page, where victims were pushed into downloading what looked like a legitimate installer but was in fact
Google’s Discover feed has become the latest battleground in the cybercrime economy after researchers uncovered a large-scale operation that used AI-written articles, fake news hooks and misleading browser prompts to push scam alerts to users’ phones and computers. The campaign, dubbed Pushpaganda, relied on more than 100 bogus domains designed to look like ordinary content sites, then turned visitors into targets for persistent scareware, ad fraud and financial scams. The scheme worked by exploiting a weak point in the way many
Splunk has disclosed a high-severity security flaw that can allow remote code execution in affected Splunk Enterprise and Splunk Cloud Platform deployments, raising concern for organisations that rely on the software to collect, search and analyse machine data for cyber defence, compliance and operations. The issue, tracked as CVE-2026-20204, was published on April 15 and carries a CVSS score of 7.1. Splunk said the weakness affects Splunk Web in several supported product branches and urged customers running on-premises software to
Attackers are exploiting a critical flaw in nginx-ui, an open-source web interface used to manage Nginx servers, exposing organisations to unauthorised server control through a weakness in the product’s Model Context Protocol integration. The bug, tracked as CVE-2026-33032, carries a CVSS severity score of 9.8 and allows an unauthenticated attacker on the network to invoke privileged functions that can rewrite configuration files, reload services and alter how traffic is handled. The vulnerability sits in the /mcp_message endpoint, which was left
A digitally signed software operation tied to Dragon Boss Solutions LLC has been linked to the disabling of antivirus protections on more than 23,000 endpoints worldwide, raising concerns that what had been treated as aggressive adware was operating much closer to a supply-chain style threat. Security researchers said infected machines were found checking in from 124 countries, with affected systems present in education, government, utilities, healthcare and other high-value networks. The activity came to wider attention after Huntress said it investigated
Europe’s cybersecurity agency has moved to strengthen its influence over the global system used to identify and catalogue software flaws, with ENISA no longer merely seeking a bigger role in the Common Vulnerabilities and Exposures programme but already holding Root status in a shift that gives the EU a stronger hand in how vulnerabilities are coordinated across borders. The development matters because the CVE system remains a core reference point for governments, security vendors, researchers and companies managing cyber risk,
More than 30 WordPress plugins tied to the developer Essential Plugin were taken offline after a hidden backdoor was found in code distributed to live websites, exposing site owners to unauthorised access, malware installation and search-spam abuse. The campaign, traced by security researchers to code inserted in August 2025 and activated in April 2026, is being treated as a serious software supply-chain breach rather than an ordinary plugin flaw. At the centre of the case is a portfolio of long-standing
Google has issued an emergency-style security update for Chrome after disclosing 31 vulnerabilities in the desktop browser, including five rated critical, in a release that underlines how quickly memory-safety flaws in widely used software can become a serious risk for consumers, businesses and public institutions. The stable desktop channel moved on April 15 to version 147.0.7727.101/102 for Windows and Mac, and 147.0.7727.101 for Linux, with the rollout set to continue over the coming days and weeks. Several of the most
A sharp jump in brute-force attacks against SonicWall and Fortinet devices has put security teams on alert, after Barracuda said such activity made up more than half of the confirmed incidents its SOC tracked during February and March, with about 88% of the attacking IP addresses geolocated to the Middle East. The company said most attempts failed because they were blocked or aimed at invalid usernames, but the scale of the campaign points to sustained probing of internet-facing network defences.
More than 100 Chrome extensions presented as harmless tools for games, social media sidebars and translation have been tied to a coordinated data-harvesting operation that security researchers say exposed user identities, browser sessions and browsing activity through a shared command-and-control network. The campaign, uncovered by Socket’s Threat Research Team and independently checked in part by BleepingComputer, involved 108 extensions listed under five publisher identities and accounted for about 20,000 installs on the Chrome Web Store when the findings were published
What looked like a nuisance adware issue inside managed IT environments has emerged as a broader cyber-security warning, after Huntress said software signed by Dragon Boss Solutions LLC exposed more than 25,000 endpoints to a supply-chain style compromise through an insecure update mechanism that could have been hijacked for the price of a cheap domain registration. Huntress published its findings on April 14, saying the software was able to fetch and run payloads with SYSTEM-level privileges while also disabling security
MSBuild, a legitimate Microsoft build tool embedded in many Windows and developer environments, is drawing renewed scrutiny after fresh threat research showed how attackers are using it to run malicious code in memory, evade signature-based defences and blend into normal system activity. Security researchers and defenders say the technique is not new, but its continued effectiveness underlines how cyber intrusions are shifting away from obvious malware files and towards the abuse of trusted software already present on a machine. The
Federal investigators in the United States, working with Indonesian police, have dismantled the W3LL phishing network, a cybercrime operation that authorities say enabled the theft of thousands of account credentials and supported more than $20 million in attempted fraud. The action, led by the FBI’s Atlanta field office, included the seizure of infrastructure linked to the service and the detention in Indonesia of an alleged developer identified by authorities as G. L. Officials described W3LL as more than a conventional
A newly disclosed security flaw in Axios, one of the most widely used HTTP client libraries in the JavaScript ecosystem, has raised concern across software and cloud security teams after official advisories warned it could be chained into remote code execution or a broader compromise of cloud infrastructure. The issue, tracked as CVE-2026-40175, affects Axios versions earlier than 1.15.0 and was published through GitHub’s advisory system on April 9, then added to the US National Vulnerability Database on April 10.
GitHub and Jira notification emails are being hijacked by threat actors who have found a way to turn trusted software alerts into convincing phishing lures, using the platforms’ own mail systems to slip past many of the checks that companies rely on to stop malicious messages. Security researchers say the tactic marks a notable shift in email abuse because the messages are not crudely spoofed copies but genuine notifications generated by legitimate SaaS infrastructure. Cisco Talos disclosed on 7 April that
Mirax, an emerging Android banking trojan being marketed as a malware-as-a-service operation, is drawing attention from mobile security researchers after reports that it can do more than steal banking credentials. Analysts say the malware can remotely control infected phones and repurpose them as residential proxy nodes, giving cybercriminals a way to hide malicious traffic behind ordinary consumer devices while pursuing financial fraud across Europe. The threat stands out because it appears to combine several criminal tactics in one package. Researchers
Basic-Fit has disclosed a cyber breach affecting about one million members across several European markets, with roughly 200,000 of those accounts in the Netherlands, exposing a wide range of personal and financial details and sharpening concerns over how consumer-facing digital platforms protect routine lifestyle data. The company said the unauthorised access was detected by internal monitoring systems and halted within minutes, but not before information had been downloaded. Data involved in the breach included bank account details, names, dates of
Iran-linked cyber operatives using the CyberAv3ngers banner are again in the spotlight after U. S. authorities warned on April 7 that Iranian-affiliated hackers have stepped up efforts to compromise programmable logic controllers and supervisory control systems used in water, energy and government facilities, with some intrusions already causing operational disruption and financial loss. The alert marks a sharper phase in a campaign that security officials say has moved beyond propaganda-driven defacements towards attempts that could interfere with the physical functioning
Google has moved to harden Chrome against one of cybercrime’s most effective tactics by making Device Bound Session Credentials publicly available for Windows users in Chrome 146, a step designed to stop attackers reusing stolen session cookies to enter accounts without passwords or multi-factor authentication. The change binds a signed-in web session to the user’s device, meaning a cookie lifted by malware should quickly become unusable on another machine. Google said macOS support is due in a coming release, while