Category: Cybersecurity

Latest Arabian cybersecurity news covering global cyber threats, ransomware attacks, data breaches, digital espionage, and technology security developments affecting governments, companies and individuals.

ADVERTISEMENT
ADVERTISEMENT

Ripple Labs is preparing to obtain an Australian Financial Services Licence through the acquisition of payments firm BC Payments, a step aimed at strengthening the company’s regulatory standing and expanding its cross-border services in the country’s financial sector. The blockchain payments company plans to complete the deal on 1 April, allowing it to gain access to the licence framework regulated by the Australian Securities and Investments Commission. Holding an Australian Financial Services Licence, commonly known as AFSL, permits firms to provide

Security vulnerabilities discovered in the open-source Pingora framework have triggered renewed scrutiny of infrastructure software used to route vast volumes of internet traffic, after researchers warned the flaws could allow attackers to manipulate web requests and poison caches in certain deployments. Cloudflare disclosed multiple weaknesses affecting standalone Pingora installations exposed directly to the internet, warning that attackers could exploit them to conduct HTTP request smuggling and cache poisoning attacks. The vulnerabilities, tracked as CVE-2026-2833, CVE-2026-2835 and CVE-2026-2836, arise from flaws in

OpenAI has agreed to acquire Promptfoo, a fast-growing artificial intelligence security platform, in a move aimed at strengthening the safety and reliability of enterprise AI systems as companies accelerate the deployment of autonomous agents and generative models across critical operations. The acquisition will bring Promptfoo’s specialised testing and vulnerability-detection technology into OpenAI’s enterprise environment, known as OpenAI Frontier, a platform designed to help organisations develop and operate AI-powered assistants and agents. Financial terms of the deal have not been disclosed. The

Yoma Fleet, one of Myanmar’s largest fleet management and leasing companies, has adopted a security information and event management platform from AccuKnox in a move aimed at strengthening protection of its digital operations and replacing older monitoring tools. The agreement positions the Menlo Park–based cybersecurity company as a key technology partner for Yoma Fleet, which manages thousands of vehicles across Myanmar for corporate clients, logistics operators and ride-hailing services. Executives say the deployment of AccuKnox’s SIEM system is designed to provide

Cybersecurity researchers have uncovered a malicious software package disguised as a legitimate developer tool that quietly installs an advanced data-stealing program on victims’ machines, raising fresh concerns about software supply-chain attacks targeting programmers and technology companies. Security analysts say a rogue npm package named @openclaw-ai/openclawai impersonates the legitimate OpenClaw command-line interface, a tool designed to help developers manage artificial-intelligence agents and related workflows. The counterfeit package installs a sophisticated infostealer and remote-access trojan that investigators have internally labelled “GhostLoader”, enabling attackers

Cybersecurity researchers have identified a sophisticated espionage campaign linked to China-aligned threat actors that is targeting organisations in Qatar, using malware associated with the PlugX family and exploiting heightened geopolitical tensions in the Middle East to lure victims. Security analysts say the operation demonstrates how advanced persistent threat groups quickly integrate global events into cyber-espionage strategies. The campaign relies on carefully crafted phishing documents and malicious attachments designed to appear relevant to political developments and regional security concerns, increasing the likelihood

Ethereum has drawn a significant influx of stablecoin liquidity, with about $523 million flowing into the network over a short period, strengthening expectations that the digital asset could test a key resistance zone near $2,142 as trading momentum gathers pace across the broader cryptocurrency market. Blockchain data indicates that large transfers of dollar-pegged stablecoins into the Ethereum ecosystem have accelerated trading activity and boosted liquidity conditions on decentralised exchanges and lending platforms. Market participants interpret such inflows as a signal that

Global networks faced more than eight million distributed denial-of-service attacks during the second half of 2025, underscoring a sharp escalation in the scale and coordination of cyber disruption campaigns as attackers deploy increasingly sophisticated techniques to overwhelm digital infrastructure. Findings released by cyber-security firm NETSCOUT Systems indicate that attackers are exploiting automation, botnets and artificial intelligence-assisted tactics to launch large volumes of disruptive traffic against businesses, governments and service providers. The report highlights a surge in complex, multi-vector attacks designed to

Processing an ordinary-looking photograph could silently trigger malicious code on macOS systems due to a newly disclosed vulnerability in widely used metadata software, raising fresh concerns about the security of open-source components embedded in everyday digital workflows. Cybersecurity researchers have identified a flaw in ExifTool, a popular open-source tool used globally to extract, read and edit metadata in images, videos and other digital files. The vulnerability, tracked as CVE-2026-3102, allows attackers to embed harmful commands within an image’s metadata so that

A critical security weakness affecting several surveillance and video management products manufactured by Hikvision has triggered alarm among cybersecurity agencies after authorities confirmed that attackers are exploiting the vulnerability to gain elevated access to targeted systems. Federal cybersecurity officials added the flaw to the Known Exploited Vulnerabilities catalogue maintained by the Cybersecurity and Infrastructure Security Agency, a list used by government and private-sector defenders to prioritise urgent security patches. The entry highlights a vulnerability that allows threat actors to escalate privileges

Security researchers have disclosed a vulnerability affecting a widely used platform that supplies contextual data to artificial intelligence coding assistants, exposing developers to potential malicious instructions embedded in documentation and external resources. The weakness, labelled “ContextCrush,” was identified by researchers at Noma Labs in the Context7 platform operated by Upstash. Context7 is designed to feed documentation and technical material to AI-powered development tools so they can generate or modify software code. Developers commonly use such systems alongside assistants like Cursor, Claude

A coalition of seven Western governments has released a set of cybersecurity guidelines aimed at shaping the development of sixth-generation wireless networks, seeking to embed security principles into the architecture of the technology long before it reaches commercial deployment. Authorities from the United States, United Kingdom, Australia, Canada, Japan, South Korea and Germany jointly issued the framework, outlining how security-by-design practices should guide the evolution of 6G standards. Officials involved in the initiative say the document is intended to influence the

Thousands of internal records linked to digital currency transactions have surfaced online, offering a rare glimpse into how financial networks connected to Iran may have used cryptocurrency platforms to navigate international sanctions. The leaked database, analysed by cybersecurity researchers and blockchain investigators, contains transaction logs, account identifiers and operational notes tied to exchanges and wallet services believed to have facilitated transfers linked to entities operating under restrictions imposed by the United States and other Western governments. Details emerging from the dataset

Heightened cyber activity linked to Tehran is expected to target governments, businesses and infrastructure across several regions, according to a senior cyber-intelligence official at a major technology company, who warned that Iranian-aligned hacking groups are preparing a broader digital campaign that could extend well beyond the Middle East. John Hultquist, a prominent cyber threat analyst who leads intelligence work within Google’s security division, said Iranian operators are likely to expand operations against the United States and its Gulf partners through tactics

Cardano’s cryptocurrency ADA has entered the Swiss retail landscape through a new payment integration allowing customers to spend the digital asset at 137 SPAR supermarkets across Switzerland. The development follows a collaboration between Cardano-linked payment infrastructure and Swiss crypto-finance firm DFX. swiss, enabling ADA transactions at checkout using existing point-of-sale systems. Shoppers at participating SPAR outlets can now pay with ADA through a system that connects Cardano’s blockchain network to the OpenCryptoPay infrastructure operated by DFX. swiss. The integration allows digital

Cryptocurrency exchange OKX has launched a new social trading network called Orbit, integrating discussion and strategy-sharing tools into its platform as exchanges compete to deepen user engagement and transparency in digital-asset markets. Orbit allows traders to share insights, discuss market movements and publish strategies within the OKX mobile application. The feature aims to transform trading activity into a community-driven environment where participants can observe market thinking, compare strategies and track the performance of selected traders. OKX said the initiative is designed to

Chainlink’s derivatives market has contracted sharply as risk appetite across digital assets weakens, with futures open interest tied to the token dropping by about 44 per cent from its earlier peak, signalling a shift in trader sentiment and a pullback in speculative positioning. Market data tracking derivatives activity shows the decline occurring alongside a short-term recovery in Chainlink’s price, a pattern that analysts say reflects a cautious market rather than the return of aggressive bullish momentum. The structure visible on daily

Heavy withdrawals from cryptocurrency exchange-traded funds in the United States interrupted a period of strong investor demand, with both Bitcoin and Ethereum products registering sizeable net outflows after several weeks of steady inflows that had buoyed digital asset markets. Spot Bitcoin exchange-traded funds collectively recorded net outflows of about $227.9 million during the latest trading sessions, while spot Ethereum ETFs saw withdrawals totalling roughly $90.9 million. The reversal followed a sequence of positive inflows that had reflected renewed institutional appetite for

Artificial intelligence is intensifying a growing security challenge inside organisations as employees and malicious insiders exploit powerful digital tools in ways that expose companies to significant operational and financial risk. A new industry analysis warns that the rapid adoption of AI systems across workplaces has transformed insider threats from an IT concern into a wider business risk that senior leadership must address urgently. Security researchers say misuse of generative AI platforms, combined with careless behaviour by employees, has created fresh vulnerabilities

Google has issued an urgent security update for its Chrome browser to address multiple vulnerabilities that could expose users to cyberattacks, including flaws capable of enabling remote code execution or system compromise. The patch, deployed through the Chrome stable channel on March 3, targets ten security weaknesses identified by Google engineers and external researchers. Three of the issues are classified as critical, while seven carry high-severity ratings. Security specialists warn that such flaws, if left unpatched, could allow attackers to manipulate

Cybersecurity researchers have uncovered a coordinated malware campaign that uses fabricated venture capital identities on LinkedIn to target professionals in cryptocurrency and Web3 sectors, employing deceptive CAPTCHA prompts to trick victims into executing malicious commands on their own computers. Security analysts say the operation combines social engineering, phishing and cross-platform malware delivery, focusing on individuals likely to be involved in blockchain startups, token projects and digital asset investment. By posing as venture capital executives seeking partnerships or investment opportunities, the attackers

A high-severity flaw in Google Chrome has raised security concerns after researchers demonstrated that malicious browser extensions could manipulate the Gemini artificial intelligence panel and obtain elevated access to sensitive user permissions, including the camera, microphone and local files. The vulnerability centred on the integration between Chrome extensions and the Gemini AI interface embedded within the browser. Security analysts reported that rogue extensions were able to bypass intended permission boundaries and interact with Gemini’s user interface components, potentially enabling attackers to

Cybersecurity researchers have identified a sharp rise in attempts to compromise internet-connected surveillance cameras across the Middle East, attributing the activity to groups believed to be linked with infrastructure associated with Iran. Analysts say the attacks coincide with heightened geopolitical tensions in the region and appear aimed at gathering intelligence and potentially disrupting critical operations. Security specialists monitoring global network traffic reported that thousands of connected cameras and video recorders have been probed or accessed through automated scanning and exploitation tools.