Latest Arabian cybersecurity news covering global cyber threats, ransomware attacks, data breaches, digital espionage, and technology security developments affecting governments, companies and individuals.
Google has moved to harden Chrome against one of cybercrime’s most effective tactics by making Device Bound Session Credentials publicly available for Windows users in Chrome 146, a step designed to stop attackers reusing stolen session cookies to enter accounts without passwords or multi-factor authentication. The change binds a signed-in web session to the user’s device, meaning a cookie lifted by malware should quickly become unusable on another machine. Google said macOS support is due in a coming release, while
Adobe has issued an emergency update for Acrobat and Reader after confirming that a zero-day vulnerability tracked as CVE-2026-34621 is being exploited in the wild, putting Windows and macOS users on notice to install the patch quickly. The company assigned the update a Priority 1 rating, its most urgent category for product security bulletins, and said successful exploitation could lead to arbitrary code execution. The flaw affects Acrobat DC, Acrobat Reader DC and Acrobat 2024 builds before the newly released
A critical security flaw in the User Registration & Membership plugin for WordPress has exposed thousands of websites to the risk of full administrative takeover, after researchers disclosed that versions up to and including 5.1.2 could allow attackers to gain elevated privileges without valid credentials. The issue, tracked as CVE-2026-1492, stems from improper privilege management during membership registration, creating a path for unauthorised users to register with powerful roles that should never be assignable from the public-facing side of a
Apache Tomcat users are being urged to move quickly after the Apache Software Foundation disclosed a set of security flaws that could let attackers undermine encrypted traffic protections, slip past certificate checks in some scenarios and exploit a defect introduced by an earlier fix. The most urgent concern centres on Tomcat’s EncryptInterceptor, where one vulnerability was followed by a second flaw in the remedy itself, creating a patch-on-patch problem for organisations that believed they had already secured affected systems. At
Pavel Durov, the Telegram founder, has escalated a public attack on WhatsApp, calling its claim of “end-to-end encryption by default” a “giant consumer fraud” and arguing that most private messages still become exposed through cloud backups. The charge, amplified on X amid a fresh US class action dispute over WhatsApp’s privacy promises, has reopened a wider argument about what encrypted messaging apps actually protect, what they leave exposed, and how much ordinary users understand about the difference. WhatsApp’s position is that
Hackers posing as trusted messaging and communications services have mounted a sustained surveillance campaign across the Middle East and North Africa, using fake app pages, phishing domains and a custom Android spyware known as ProSpy to target journalists, activists and political figures, according to a joint body of research published this week by Lookout, Access Now and SMEX. The operation, active since at least 2022 and documented through attacks in 2023, 2024 and 2025, is assessed with moderate confidence to
GitHub Copilot Chat has been shown to carry a serious prompt-injection weakness that allowed a researcher to demonstrate how secrets, private source code and other sensitive repository data could be siphoned out of trusted development workflows without planting malware in the victim’s environment. The issue, dubbed CamoLeak, was disclosed by Legit Security researcher Omer Mayraz after he said he found it in June 2025, reported it through HackerOne and saw GitHub deploy a fix by 14 August 2025. The attack
More than 5,000 Rockwell Automation and Allen-Bradley programmable logic controllers are exposed to the public internet, sharpening concern across United States critical infrastructure as federal agencies warn that Iran-affiliated cyber actors are actively targeting such devices. Security researchers at Censys said they identified 5,219 internet-exposed hosts globally that responded as Rockwell or Allen-Bradley systems, with nearly three quarters of them located in the United States. The warning lands amid an active campaign against operational technology used in water, energy and
Millions of Android users, including a large share of cryptocurrency wallet customers, were exposed to a software supply-chain weakness after a flaw in the widely used EngageSDK library was found to allow hostile apps on the same device to break through normal app boundaries and reach sensitive data. The issue centred on an “intent redirection” vulnerability inside the third-party Android kit, which is used for push notifications and in-app messaging, and whose reach extended far beyond any single wallet provider.
Commercial artificial intelligence tools were used as operational components in a cyber campaign that hit nine Mexican government organisations, according to a full technical report published by Gambit Security, which said the intrusion ran from late December 2025 to mid-February 2026 and exposed hundreds of millions of citizen records. The report says Anthropic’s Claude Code generated about three-quarters of the remote command activity, while OpenAI’s GPT-4.1 was used to analyse harvested data and turn it into structured intelligence. The findings deepen
Three ransomware operations — Qilin, Akira and DragonForce — were behind 40% of the 672 attacks logged worldwide in March, according to Check Point Research, highlighting how a criminal market that still looks fragmented on the surface is being pulled by a smaller group of high-output players. Check Point said Qilin accounted for 20% of published attacks, Akira 12% and DragonForce 8%, while 47 separate groups were still active during the month. The figures point to a concentrated threat environment rather
Google has begun rolling out a new Chrome security feature designed to blunt one of the most effective tools used by cybercriminals to hijack online accounts: stolen session cookies. The protection, called Device Bound Session Credentials, is entering public availability for Windows users in Chrome 146, with expansion to macOS slated for a later release. Google says the system is intended to make stolen authentication cookies far less useful by tying them cryptographically to the user’s device. The move targets
A Microsoft-tracked cybercrime group is using adversary-in-the-middle techniques to hijack Microsoft 365 sessions, bypass multifactor authentication and reroute employee pay into attacker-controlled bank accounts, in what researchers describe as a geographically focused campaign against users in Canada. Microsoft said the actor, tracked as Storm-2755, combined search-result poisoning, fake sign-in pages and session replay to move from account takeover to payroll fraud, causing direct financial loss for at least one victim. What sets this operation apart is the way it turns
A newly disclosed technique dubbed “sockpuppeting” has sharpened concerns over how easily some artificial intelligence systems can be pushed past their safety controls, after researchers showed that a short output-prefix prompt inserted through an application programming interface can drive several leading open-weight models to produce harmful material they would normally refuse. The work, published in January by researchers at the University of Amsterdam, describes the method as a low-cost jailbreak requiring no optimisation and as little as a single line
A critical security flaw in the Ninja Forms File Uploads add-on has put thousands of WordPress sites at risk, with researchers warning that attackers can exploit the bug without logging in and, in the worst case, gain remote code execution on a vulnerable server. The issue affects all versions up to and including 3.3.26, while version 3.3.27 has been identified as the fully patched release after an earlier partial fix in 3.3.25. The vulnerability, tracked as CVE-2026-0740, carries a critical
Amazon Web Services has patched three high-severity vulnerabilities in its open-source Research and Engineering Studio platform, closing weaknesses that could have allowed authenticated users to run commands on key systems or gain broader permissions inside cloud environments used for scientific and engineering work. The flaws affected AWS Research and Engineering Studio, known as RES, a web-based portal that helps administrators build and manage controlled research and engineering environments on AWS. In a security bulletin published on 6 April, AWS said the
A cross-border espionage campaign that targeted journalists, civil society figures and some government-linked entities across the Middle East and North Africa between 2023 and 2024 has been tied by researchers to BITTER, a long-tracked South Asian threat actor, marking what investigators describe as the first documented case linking the group to attacks on civil society in the region. The attribution remains qualified rather than definitive: Lookout said it had reached its assessment with moderate confidence, while Access Now said the
Google has warned that a financially motivated cyber group tracked as UNC6783 is targeting business process outsourcers and corporate helpdesks in a campaign aimed at stealing sensitive data from large companies and then using that access for extortion. The group, which Google says may be tied to the “Raccoon” persona, has targeted several dozen high-value organisations across multiple sectors, shifting attention to a weak point that many large enterprises share: outsourced support operations and internal service desks. The warning came
STX RAT, a newly identified remote access trojan, has drawn attention in the cyber-security sector after researchers tied it to an attempted intrusion against a financial-services environment and linked it to broader opportunistic delivery campaigns that include trojanised software and script-based loaders. The malware stands out because it combines hidden remote control with data theft, while delaying some of its most suspicious behaviour until it has an active connection to its command server. Researchers said the malware was first observed
Attackers have planted a stealthy Magecart credit-card skimmer on nearly 100 Magento-based online shops by hiding the malicious code inside an invisible SVG image, according to incident findings published this week, in what security specialists describe as another sign that payment-page attacks are becoming harder for merchants and scanners to detect. The operation was identified on April 7 and affected 99 stores, with stolen payment data sent to six attacker-controlled domains. What makes the campaign stand out is the way
Atomic Stealer operators have opened a fresh lane into Apple computers by shifting a popular ClickFix scam away from Terminal and into Script Editor, a built-in macOS tool that many users would regard as less suspicious. The change matters because Apple moved in March to add stronger friction around Terminal-based copy-and-paste attacks in macOS Tahoe 26.4, and threat researchers now say attackers have adapted within weeks rather than abandoning the technique. Researchers at Jamf Threat Labs said the campaign uses
U. S. authorities have dismantled the domestic arm of a cyber-espionage network that officials say was run by APT28, the Russian military intelligence hacking group also known as Fancy Bear and Forest Blizzard, after it hijacked vulnerable internet routers to redirect traffic, steal credentials and sift victims for higher-value targets. The Justice Department said the FBI used a court-authorised technical operation to identify compromised routers on U. S. soil, collect evidence, sever the hackers’ access and restore the devices to
GitLab has issued a security update covering multiple vulnerabilities in its Community Edition and Enterprise Edition products, with the latest patch aimed at denial-of-service weaknesses and an Enterprise-only code injection issue that could expose users’ IP addresses through maliciously crafted Code Quality reports. The company said self-managed customers should upgrade immediately to versions 18.10.3, 18.9.5 or 18.8.9, while GitLab. com is already running the patched release and GitLab Dedicated customers do not need to act. At the centre of the 8
Google’s handling of API keys has come under fresh scrutiny after security researchers said Android applications are exposing credentials that can now unlock parts of the Gemini AI platform, potentially allowing unauthorised access to files, cached data and billable AI services. The latest warning, published by CloudSEK on April 7, says 32 hardcoded Google API keys were found across 22 popular Android apps and that the issue stems from how older Google Cloud keys can gain Gemini permissions when the
Palo Alto Networks has issued a high-priority security update for a flaw in its Cortex XSOAR and Cortex XSIAM platforms that could allow an unauthenticated attacker to access and alter protected resources through the Microsoft Teams integration, adding fresh pressure on security teams to review third-party connectors that sit inside core incident response systems. The vulnerability, tracked as CVE-2026-0234, was published on April 8 and affects Microsoft Teams Marketplace integration versions from 1.5.0 up to, but not including, 1.5.52. The
Iran-affiliated cyber actors are targeting internet-facing industrial control equipment used by parts of the United States’ critical infrastructure, with federal agencies warning that the campaign has already caused operational disruption and financial loss in some cases. The alert, published on April 7, said the activity was focused on operational technology devices, including programmable logic controllers, or PLCs, made by Rockwell Automation’s Allen-Bradley line. The warning matters because PLCs sit close to physical operations. They help control pumps, motors, valves and other
Fresh academic work is pushing back against some of the louder claims surrounding quantum computers and Bitcoin, arguing that one feared route of attack — using a quantum machine to dominate mining — remains so physically demanding that it would require energy on an astronomical scale. A separate paper has cast doubt on headline-grabbing “quantum factoring breakthroughs”, arguing with deliberate sarcasm that many such claims can be reproduced with primitive classical hardware and even a dog, underscoring how far the
What used to be dismissed as internet oddity is moving into the mainstream of fraud prevention, platform regulation and organised crime analysis: the distinction between sock-puppet accounts and catfishing is no longer academic. Authorities, platforms and researchers are increasingly treating fake digital personas as a wider security and financial risk, particularly as artificial intelligence makes them cheaper to create, easier to scale and harder for ordinary users to detect. At the centre of the debate is a simple but important difference.
Hackers are exploiting internet-exposed ComfyUI servers in a monetisation campaign that turns poorly secured AI image-generation systems into cryptocurrency mining machines and proxy infrastructure, according to multiple security findings published this week. Researchers say more than 1,000 exposed ComfyUI instances remain reachable online after honeypots are filtered out, giving attackers a narrow but valuable pool of GPU-equipped targets spread across cloud environments. The activity centres on unauthenticated ComfyUI deployments and the platform’s custom node ecosystem, which lets users add third-party
Russian military-linked hackers have hijacked vulnerable internet routers to steal passwords, authentication tokens and other sensitive data, according to a new warning from the UK’s National Cyber Security Centre, which said the activity was tied to APT28, a group long associated with Moscow’s GRU military intelligence unit 26165. British officials said the campaign worked by altering router settings so internet traffic could be redirected through malicious Domain Name System servers controlled by the attackers, opening the way for adversary-in-the-middle attacks
Microsoft has warned that a threat actor it tracks as Storm-1175 is exploiting vulnerabilities in internet-facing systems at high speed to deliver Medusa ransomware, in some cases moving from initial access to data theft and encryption within 24 hours. The alert points to a pattern that security teams have feared for months: a shrinking window between vulnerability disclosure, exploitation and full-scale ransomware deployment. The group, described by Microsoft as financially motivated, is said to focus on web-facing assets that remain exposed
Iran-linked hackers mounted a coordinated password-spraying operation against Microsoft 365 tenants across the Middle East in March, with Israel and the United Arab Emirates emerging as the main targets in a campaign that cyber researchers say shows how regional conflict is increasingly being mirrored in the cloud. Check Point Research said the activity came in three waves on March 3, March 13 and March 23, hitting more than 300 organisations in Israel and over 25 in the UAE, while smaller
Security leaders are being told to treat “vibe coding” as a governance issue, not merely a productivity trend, as AI assistants move deeper into software development and expose organisations to flaws ranging from insecure dependencies to credential leakage and command injection. Guidance from standards bodies and security groups now points towards a simple principle: code produced with AI should be handled as untrusted until it has passed the same scrutiny as any high-risk software change. That shift is gaining force as
A Python package presented as a privacy-first shortcut to AI models has been unmasked as a supply-chain threat that quietly captures user prompts, leans on a private university service without authorisation and repurposes proprietary Claude material to make the deception look convincing. Security researchers said the package, hermes-px, was uploaded to PyPI as a supposed “Secure AI Inference Proxy” offering OpenAI-compatible access over Tor and claiming users did not need their own API keys. Analysis by JFrog, published on April