Category: Cybersecurity

Latest Arabian cybersecurity news covering global cyber threats, ransomware attacks, data breaches, digital espionage, and technology security developments affecting governments, companies and individuals.

ADVERTISEMENT
ADVERTISEMENT

Cisco has issued urgent security updates to address a critical vulnerability in its Secure Firewall Management Center software that could allow attackers to execute arbitrary code on affected systems without authentication, raising concerns across enterprise and government networks that rely on the platform for threat monitoring and control. The vulnerability, identified as CVE-2026-20131, carries a maximum severity score of 10.0 under the Common Vulnerability Scoring System, indicating a flaw that is both easy to exploit and capable of causing significant

San Francisco played host to a decisive moment for the cybersecurity industry as winners of the 2026 Cybersecurity Excellence Awards were unveiled during the RSA Conference, highlighting a sharp pivot toward artificial intelligence-driven security as the sector’s defining battleground. Organised by Cybersecurity Insiders, the awards recognised companies, technologies and professionals demonstrating leadership across a broad range of categories. This year’s results underscored the growing urgency surrounding AI governance, automated threat detection and protection against machine-led attacks, areas that attracted the highest

Security researchers are raising concerns over a growing wave of browser extensions that covertly capture and transmit users’ interactions with artificial intelligence tools, exposing sensitive prompts and responses without clear consent. Cybersecurity firm Expel highlighted the threat in a detailed analysis published on 24 March, warning that certain extensions operating within Google Chrome can quietly monitor inputs typed into AI platforms and relay them to external servers. The activity, often undetected by users, has prompted fears that confidential business information, proprietary

Banks and cybersecurity teams are confronting a sharp rise in financial fraud linked to the growing use of cloud phone technology, a system that allows users to operate mobile devices remotely through servers housed in data centres. Security analysts warn that the model, originally developed for legitimate testing, automation and business continuity, is now being exploited by fraud networks to bypass safeguards and scale attacks across borders. Cloud phones, sometimes referred to as virtual mobile devices, enable individuals to control multiple

Malicious Google advertisements linked to tax-related searches are being used to distribute a sophisticated attack chain that disables endpoint security tools before granting attackers remote control of compromised systems, according to cybersecurity researchers. The campaign, identified by Huntress, combines social engineering with a “bring your own vulnerable driver” technique to bypass detection systems and establish persistent access. Investigators found that sponsored search results tied to queries such as “W-2 tax form” and “W-9 tax forms 2026” redirected users to convincing websites

Malicious actors are exploiting search engine rankings to distribute trojanised software installers that deploy the AsyncRAT remote access tool, in a campaign that has expanded steadily since October 2025 and now targets more than two dozen widely used applications. Security analysts tracking the operation say attackers are manipulating search optimisation techniques to push fraudulent download portals to the top of results pages, increasing the likelihood that unsuspecting users install compromised versions of legitimate software. The scheme hinges on impersonating trusted brands,

Cybersecurity researchers are tracking an expansion of the MioLab infostealer targeting macOS systems, signalling a shift in cybercrime operations towards Apple devices as their adoption widens across corporate and consumer environments. The malware, also known in underground circles as Nova, is being marketed as a Malware-as-a-Service offering, allowing threat actors with limited technical expertise to deploy sophisticated attacks against macOS users. Analysts describe MioLab as a modular and evolving threat designed to extract sensitive information, including browser credentials, cryptocurrency wallet data,

Organisations faced a steep escalation in cyber threats targeting application programming interfaces, with average daily API attacks per enterprise climbing to 258 in 2025, marking a 113% increase from 121 the previous year, according to industry cybersecurity assessments tracking enterprise network activity. The data underscores a widening attack surface as businesses deepen reliance on APIs to connect cloud services, mobile applications and third-party platforms. Analysts say the growth reflects both the expansion of digital ecosystems and the increasing sophistication of attackers

Remote working has emerged as a key vulnerability in the UAE’s digital landscape, prompting authorities to warn of a sharp rise in cyber attacks targeting individuals operating outside traditional office networks. The UAE Cyber Security Council has called on employees working from home to act as the “first line of defence”, stressing that human error and weak personal security practices are increasingly being exploited by cybercriminals. Officials indicated that phishing attempts, ransomware campaigns and credential theft have all gained traction as

Cheap IP-KVM devices widely used in enterprise environments have been found to contain critical security vulnerabilities that could allow attackers to seize low-level control of entire networks, according to findings from multiple cybersecurity researchers. The flaws, identified across several budget remote management products, enable attackers to bypass standard security protections and gain direct access to connected systems at the BIOS level. Once compromised, a single IP-KVM device can effectively grant full keyboard, video and mouse control over multiple servers, turning what

A new strain of the malware-as-a-service infostealer known as VoidStealer has introduced a technique that allows attackers to extract sensitive data from Google Chrome without relying on privilege escalation or code injection, marking a shift in how browser security defences are being bypassed. Security researchers tracking the campaign say the updated variant leverages a debugger-based method to defeat Chrome’s Application-Bound Encryption, a protection designed to secure stored credentials and cookies. Instead of exploiting system-level vulnerabilities or injecting malicious code into browser

A coordinated supply chain attack targeting the Node Package Manager ecosystem has exposed a new level of automation and persistence, with threat actors hijacking trusted publisher accounts to distribute malicious code across widely used software libraries. Security researchers tracking the campaign, known as “CanisterWorm,” say it relies on stolen access tokens and compromised namespaces to infiltrate development pipelines without immediate detection. The campaign has been linked to a group identified as “TeamPCP,” which has systematically targeted maintainers of popular npm packages.

Sticker prices for website domains are drawing fresh scrutiny after a developer’s account of soaring renewal fees for a. online address highlighted what analysts describe as a structural imbalance in the domain name market, where low entry costs can mask significantly higher long-term expenses. The case centres on a developer who secured a. online domain at a heavily discounted introductory rate, only to face a sharp increase at renewal. While such pricing structures are disclosed in registration terms, the scale of

Hackers leveraged a critical vulnerability in the open-source AI workflow platform Langflow within hours of its disclosure, underscoring a sharp acceleration in cyberattack timelines and raising fresh concerns over the security of rapidly adopted artificial intelligence tools. Security researchers reported that attackers moved to exploit the flaw roughly 20 hours after public details emerged, highlighting how threat actors are monitoring disclosures in real time and deploying automated tools to weaponise weaknesses at unprecedented speed. The incident reflects a broader trend in

A sharp escalation in mobile banking malware attacks targeting more than 1,200 financial brands across 90 countries is altering the global fraud landscape, with security experts warning that user devices have become the primary entry point for cybercriminals. Industry researchers tracking digital fraud patterns say the scale and sophistication of mobile-focused threats have expanded markedly, reflecting a shift away from traditional server-side breaches towards attacks that exploit weaknesses on smartphones. These campaigns are increasingly capable of bypassing conventional safeguards, enabling attackers

Cybersecurity strategies built around prevention are facing renewed scrutiny as organisations grapple with a wave of disruptive attacks targeting cloud infrastructure, exposing weaknesses in how resilience is designed and implemented. Security analysts and industry leaders say the shift to cloud computing has outpaced the evolution of defensive frameworks, leaving many enterprises vulnerable not because they lack protection tools, but because they underestimate the importance of operational continuity under attack. Ransomware campaigns, data exfiltration incidents and large-scale outages have demonstrated that systems

Security weaknesses in Jenkins and a widely used plugin have raised fresh concerns over the resilience of software development pipelines, with researchers warning that attackers could exploit the flaws to gain deep access to enterprise systems. The vulnerabilities, disclosed through an official advisory from the Jenkins project, affect the core automation server as well as the LoadNinja plugin, a tool used for performance testing. Security analysts indicate that the issues could allow malicious actors to create arbitrary files, expose sensitive credentials

A security weakness in Ubuntu Desktop 24.04 and later versions has raised fresh concerns over the resilience of widely used Linux environments, after researchers confirmed that local attackers can exploit the flaw to gain full administrative control. The vulnerability, described as a local privilege escalation issue, allows a user with limited access to elevate permissions and execute commands as the root user, effectively compromising the entire system. Cybersecurity analysts indicate that the flaw affects default installations, making it particularly significant for

  Authorities across multiple jurisdictions have dismantled a vast network of compromised Internet of Things devices linked to some of the largest distributed denial-of-service attacks ever recorded, with traffic surges reaching an estimated 30 terabits per second. The coordinated operation targeted command-and-control infrastructure that enabled four separate botnets to orchestrate high-volume cyber assaults on critical digital services worldwide. Investigators said the infrastructure had been used to overwhelm servers, disrupt platforms and extort organisations by threatening prolonged outages. Law enforcement agencies worked alongside cybersecurity

Navia Benefit Solutions has disclosed a large-scale data breach affecting nearly 2.7 million individuals, raising concerns over the security of sensitive employee benefits data held by third-party administrators across the United States. The company, which manages health savings accounts and other workplace benefit programmes for more than 10,000 employers, said unauthorised actors gained access to parts of its systems, exposing a broad range of personal and health-related information. The incident places it among the more significant breaches involving benefits administrators, a

A zero-day vulnerability in widely deployed Cisco firewall systems has been exploited for months by a ransomware group, with security teams warning that the breach highlights deep gaps in enterprise network defences and patch management practices. Analysis by Amazon Web Services’ security leadership indicates that attackers began abusing the flaw as early as January, gaining unauthorised access to targeted environments before the vulnerability became publicly known. The disclosure has raised concern among corporate security teams, particularly given the scale of Cisco’s

A banking malware strain known as Horabot has re-emerged in Mexico with a more sophisticated infection chain, combining phishing emails, deceptive CAPTCHA prompts and automated email propagation techniques to compromise victims and harvest financial data. Cybersecurity analysts tracking the campaign say the latest iteration marks a significant evolution in both delivery and persistence. The malware is being distributed through carefully crafted phishing emails that appear to originate from legitimate contacts, a tactic that increases the likelihood of user interaction and bypasses

A coordinated cybercrime operation built around a fraudulent cryptocurrency tool branded “ShieldGuard” has been dismantled after investigators confirmed it functioned as a malicious browser extension harvesting user credentials and digital assets. Security researchers say the campaign had been active across multiple platforms, targeting retail crypto investors through deceptive online promotions and fake security assurances. The extension, presented as a protective utility for safeguarding cryptocurrency wallets, was distributed through unofficial browser marketplaces and phishing sites designed to mimic legitimate download portals. Once

A newly identified Android attack technique that alters the operating environment rather than modifying applications has raised fresh concerns over the resilience of mobile payment systems, with researchers warning that conventional app-level protections may no longer be sufficient. Security analysts at CloudSEK have detailed a method that leverages a framework known as LSPosed to manipulate how Android apps behave at runtime. Instead of injecting malicious code directly into banking or payment applications, the technique hooks into the system layer, allowing attackers

Security researchers have identified a technique that could allow attackers to execute malicious code within AI-assisted development environments by manipulating installation links, raising fresh concerns about the integrity of modern coding workflows. The method, termed “CursorJack”, exploits how some AI development tools handle external package installation and repository linking. By redirecting or tampering with these links, attackers can introduce harmful code into a developer’s environment without immediate detection. The vulnerability highlights a growing attack surface as software engineers increasingly rely on

Cybersecurity analysts have uncovered a method that enables attackers to bypass behavioural protections in Palo Alto Networks’ Cortex XDR platform, raising fresh concerns over the resilience of endpoint detection systems widely used by enterprises. The findings centre on the platform’s Behavioural Indicators of Compromise, or BIOC rules, which are designed to identify suspicious activity beyond traditional signature-based detection. Researchers demonstrated that these rules, distributed in encrypted form within the Cortex XDR agent, could be decrypted and examined, allowing adversaries to understand

Gaps between on-premise and cloud identity systems are creating a growing security blind spot, as organisations adopting hybrid Active Directory environments struggle to maintain consistent user credentials across platforms. Security analysts warn that “identity drift” — a condition where user attributes, permissions or credentials fall out of sync between systems — is emerging as a critical vulnerability in enterprise infrastructure. Hybrid identity setups, commonly built around Microsoft’s Active Directory integrated with cloud services such as Azure Active Directory, have become standard

Security researchers have uncovered a vulnerability in Amazon Web Services Bedrock’s code interpreter environment, raising concerns over the robustness of isolation safeguards in generative AI systems and prompting renewed scrutiny of cloud-based development tools used by enterprises. The flaw, identified in Bedrock’s sandboxed execution layer, centres on weaknesses in DNS handling that could allow data exfiltration from supposedly isolated environments. Analysts say the issue highlights structural challenges in how large-scale AI platforms enforce boundaries between user workloads and underlying infrastructure, particularly

A coordinated international law enforcement operation has dismantled SocksEscort, a large malicious proxy service that enabled cybercriminals to hide their identities while carrying out fraud, ransomware attacks and other online crimes. The operation, codenamed Operation Lightning, targeted infrastructure spread across multiple countries and led to the seizure of dozens of domains and servers used to run the network. Authorities said the proxy service relied on malware that infected home and small-business routers, silently turning them into part of a vast

A sophisticated malware operation targeting software developers has expanded its reach by exploiting trusted extension ecosystems, with security researchers uncovering dozens of malicious packages distributed through the Open VSX marketplace. The campaign, known as GlassWorm, now relies on hidden transitive dependencies to introduce malicious code into developer environments, marking a notable shift in tactics within the growing wave of software supply-chain attacks. Security analysts have identified at least 72 malicious extensions linked to the campaign, many of which appear legitimate at

  A sophisticated strain of Android malware capable of diverting real-time payments has emerged as a major cybersecurity concern in Brazil, exploiting the country’s widely used PIX instant payment platform and highlighting the risks attached to rapidly expanding digital payment ecosystems. Cybersecurity researchers say the malware, dubbed PixRevolution, hijacks transactions at the exact moment a user sends money through PIX, redirecting funds to accounts controlled by criminals while the victim sees what appears to be a normal confirmation screen. The technique exploits

Global medical technology manufacturer Stryker has been hit by a major cyberattack claimed by an Iran-linked hacker collective, triggering widespread disruption to corporate systems and raising fresh concerns about cyber warfare spilling into commercial infrastructure. The group, calling itself Handala, said it carried out a destructive operation that wiped data across more than 200,000 company devices while extracting roughly 50 terabytes of information from internal networks. The incident disrupted internal communications, disabled corporate laptops and phones, and forced employees in multiple

  Cybersecurity researchers have uncovered a series of critical vulnerabilities affecting Google’s Looker data analytics platform that could have enabled attackers to execute malicious code, move between cloud environments and extract sensitive corporate data. The flaws highlight growing security concerns surrounding widely used cloud-based analytics tools that sit at the centre of many organisations’ data infrastructure. Security specialists from the cybersecurity firm Tenable identified two major vulnerabilities—collectively dubbed “LookOut”—that could potentially allow attackers to take control of Looker servers or access internal

Cyber-criminals have compromised hundreds of legitimate WordPress websites in a global operation designed to infect unsuspecting visitors with information-stealing malware, raising fresh concerns about the security of widely used web platforms and the increasing sophistication of social-engineering attacks. Threat researchers at cybersecurity firm Rapid7 say attackers infiltrated more than 250 websites across at least 12 countries, including the United Kingdom, United States, Germany, Canada, Australia, Brazil, Israel and India. The infected pages include regional news portals, small business sites and even