Latest Arabian cybersecurity news covering global cyber threats, ransomware attacks, data breaches, digital espionage, and technology security developments affecting governments, companies and individuals.
Five alleged leaders of the Cape Town branch of the Black Axe network have appeared in a New Jersey federal court after being extradited from South Africa to face charges over internet fraud and money laundering schemes that prosecutors say targeted victims in the United States. Perry Osagiede, 57, Franklyn Edosa Osagiede, 42, Osariemen Eric Clement, 40, Collins Owhofasa Otughwor, 42, and Musa Mudashiru, 38, were extradited on September 11 and were due before US District Judge Michael A. Shipp
The US National Institute of Standards and Technology has finalised new guidance aimed at reducing theft, forgery and misuse of digital tokens that underpin single sign-on, cloud federation and API access. NIST Interagency Report 8587, released on September 15, sets out implementation recommendations for federal agencies and cloud service providers handling identity tokens, access tokens and assertions. The document focuses on how organisations should protect signing keys, verify tokens, manage their lifecycles and limit the damage if credentials are stolen or
Swiss Bitcoin Pay has taken its servers offline after detecting what it described as likely unauthorised access to internal systems, while warning that customer contact, banking and transaction data may have been exposed. The Switzerland-based Bitcoin payments provider disclosed the incident on September 14 and said it was investigating the intrusion and securing its infrastructure before restoring service. It has not announced a date for reopening. Swiss Bitcoin Pay said the information potentially accessed includes customer email addresses, Bitcoin addresses, International Bank
A skilled human attacker exploited a critical Marimo notebook flaw and moved from an exposed WebSocket session to authenticated access on an SSH bastion host in eight seconds, Sysdig’s Threat Research Team has documented. The operation centred on CVE-2026-39987, a pre-authentication remote code execution vulnerability affecting the Marimo Python notebook platform. Sysdig said the attacker used a hand-built Python toolkit rather than an AI agent, chaining initial shell access, cloud credential use and retrieval of an SSH private key with machine-like
A browser extension used by nearly 31,000 Twitch viewers has been found forwarding live OAuth session tokens to proxy infrastructure controlled by the operator of a Russian-language commercial bot service, exposing credentials that can grant access to account functions without requiring passwords or two-factor authentication. Security company Socket said the extension, “Twitch Enhanced Viewer | JeetBot”, was available through both the Chrome Web Store and Mozilla’s Firefox Add-ons marketplace when its findings were published on September 11. Socket counted about
A Casbaneiro banking Trojan campaign targeting users in Latin America is using geofenced phishing, staged malware delivery and separate command-and-control servers to make malicious activity harder to detect and analyse, according to security research published this month. FortiGuard Labs said it observed the campaign in August, with activity focused on Argentina, Peru, Colombia and Mexico. Victims are approached through phishing emails and PDF documents disguised as invoices, legal notices or purported court-related communications, often incorporating the recipient’s email address to make
A phishing campaign active since June is abusing Microsoft’s legitimate mshta. exe utility to run malicious HTML Application files, profile infected Windows systems and deliver follow-on malware capable of stealing credentials and other local secrets, security researchers have found. Fortra Intelligence and Research Experts, known as FIRE, said the operation remains active and is primarily targeting Spanish-speaking users at global organisations. The attackers use Spanish-language invoice and judicial-notice lures to persuade recipients to follow malicious links, while continually changing samples and
Cybercriminals abusing Microsoft 365’s Direct Send feature concentrated malicious email activity around US Eastern business hours, according to a new analysis of a large phishing campaign tracked during July and August. KnowBe4 Threat Lab said it identified tens of thousands of confirmed phishing messages sent through Direct Send, a legitimate Exchange Online delivery method intended for devices and applications that need to send mail without a dedicated Microsoft 365 mailbox. The researchers said the timing showed a pronounced weekday pattern, with
China-linked threat actors have been caught chaining two Google Chrome flaws with a Windows kernel vulnerability to compromise selected targets, including non-governmental organisations, in espionage campaigns detected this month. Cybersecurity firm Volexity said the activity involved two separate groups it tracks as UTA0560 and JungleBamboo, the latter also known as APT31, Violet Typhoon and TA412. Both used the same core browser-to-kernel exploit chain, but installed different post-exploitation tools after gaining access to victims’ systems. The campaigns were detected on September 1. Phishing
cPanel has urged server administrators to update ConfigServer Security & Firewall after disclosure of a critical command-injection vulnerability that can let unauthenticated remote attackers run arbitrary commands on affected systems under specific service configurations. The flaw, tracked as CVE-2026-65638, affects cPanel’s WebPros-maintained CSF versions 14.00 through 16.29 and was addressed in version 16.30 and later. cPanel said administrators should move to the latest available release as soon as possible, while those unable to update should disable the vulnerable MESSENGER service. The vulnerability
Two newly disclosed vulnerabilities affecting VLC media player 3.0.0 through 3.0.23 can corrupt heap memory or expose data when users open a malicious PNG image or connect to an attacker-controlled RealRTSP server, security records published this week show. The more serious issue, CVE-2026-56711, is an integer-overflow flaw in VLC’s picture-allocation logic that can lead to a heap out-of-bounds write. The vulnerability carries a CVSS v4 score of 8.6 and a CVSS v3.1 score of 8.8, placing it in the high-severity range. The
GitLab has issued emergency security updates for self-managed installations after fixing two critical vulnerabilities, including a maximum-severity flaw now listed by US authorities as actively exploited. The company released GitLab Community Edition and Enterprise Edition versions 19.3.2, 19.2.6 and 19.1.8 on September 10, urging administrators running affected versions to upgrade immediately. GitLab. com is already operating the patched release, while GitLab Dedicated customers do not need to take action. The most serious flaw, CVE-2026-85706, carries a CVSS score of 10.0 and affects
Cisco has warned that attackers are actively exploiting two vulnerabilities in its Secure Firewall Management Center software, with intrusions leading to root-level access, credential theft, reconnaissance and malware deployment on compromised systems. Cisco Talos said on September 9 that it had identified three clusters of post-compromise activity involving CVE-2026-20079 and CVE-2026-20316. The first flaw, rated a maximum 10.0 on the CVSS scale, can let an unauthenticated remote attacker bypass authentication and execute scripts and commands as root. The second involves static
A newly documented Android malware strain called MantaxOtax combines ransomware, spyware and remote-control functions, enabling attackers to encrypt files, steal sensitive communications and obstruct victims from using infected phones. Mobile security researchers at Zimperium’s zLabs detailed the malware on September 9, saying analysed samples were linked through language indicators and recovered victim material to threat actors operating in Indonesia. Some samples were distributed as standalone Android application packages on third-party file-sharing services, suggesting victims were persuaded to sideload the malware outside
Cybercriminals behind the Gigabud Android banking trojan are using a weaponised app-cloning tool to isolate fraudulent banking activity from malware alerts, according to research published by Group-IB on September 9. The cybersecurity company said Gigabud is being paired with Vwork, a modified fork of the open-source Android application Shelter, to create a separate Work Profile and place banking applications inside it. Group-IB attributed both Gigabud and Vwork to the financially motivated threat group it tracks as GoldFactory. Android Work Profiles are designed
Cybercriminals are distributing fake Grand Theft Auto VI downloads that install remote-access trojans, an information stealer and destructive ransomware, putting gamers’ passwords, Discord accounts and cryptocurrency data at risk. Cybersecurity firm Huntress said it identified malicious optical-disc image files masquerading as leaked copies of Rockstar Games’ forthcoming title across search results, gaming forums, social media and torrent sites. Some files exceed 100GB, but researchers found much of the size was junk data intended to make the download resemble a genuine blockbuster
The US Treasury has sanctioned Xinbi Guarantee, a Chinese-language illicit marketplace accused of connecting Southeast Asian scam centres and transnational crime groups with money launderers, technology providers and other criminal-service vendors. The Office of Foreign Assets Control designated Xinbi Guarantee on September 9 as a significant transnational criminal organisation, while also sanctioning Singapore-based SafeW Technology Co Ltd and Cambodia-based Anwen Technology Co Ltd for providing technological and financial support to the platform. The action was coordinated with the Justice Department’s Scam Center
Anthropic has disclosed a fourth cybersecurity testing incident in which a pre-release Claude model gained unauthorised access to a real third-party system, prompting the company to broaden its investigation and reassess earlier conclusions about the models’ behaviour. The latest disclosure, published on September 9, concerns an early checkpoint of Claude Opus 4.6 tested in January. Anthropic said the model was running a capture-the-flag exercise in an environment that should have been isolated from the public internet but was left connected because
Coin Center research director Laz Pieper has called for a shift away from identity-verification systems that routinely collect and retain full copies of personal documents, arguing that privacy-preserving technology could reduce the large stores of sensitive data now targeted by cybercriminals. The warning follows an FBI investigation into claims that a dark-web service offered access to more than 153 million US and Canadian driver’s-licence records, along with other identity documents. The source and scale of the material have not been publicly
Cybercriminals are combining fake Google CAPTCHA prompts, WebDAV-hosted DLLs, malicious Cloudflare Workers and BNB Smart Chain contracts in a multi-stage operation that deploys the Amatera information stealer and other payloads, according to new research from Cisco Talos. The investigation began after Talos identified unusual endpoint activity at a Ukrainian government organisation in April 2026. A remote file disguised as “verification. google” was executed from a WebDAV path through the 32-bit version of Windows rundll32. exe, while the Windows WebClient service was
A ClickFix campaign is manipulating cryptocurrency users into injecting malicious JavaScript directly into their browsers, allowing attackers to replace legitimate wallet addresses and divert transfers, Cisco Talos has disclosed. The campaign marks a shift from familiar ClickFix attacks that persuade victims to run PowerShell, Terminal or other operating-system commands. Instead, targets are instructed to paste code into Chrome’s address bar or install it through the legitimate Tampermonkey browser extension, which can reload the malicious script whenever a targeted cryptocurrency site is
Security researchers have disclosed a zero-click worm capable of hijacking WeChat accounts through incoming calls on both iPhones and Android phones, although the exploit has been mitigated before public release. California-based security firm Calif said its WeWorm demonstration exploited a memory-corruption flaw in WeChat’s voice-over-IP stack, allowing a compromised account to call another user and seize control of that account within seconds without the target answering or touching the phone. The researchers said Tencent, which operates WeChat, had mitigated the exploit for
Security researchers have detailed a stealthy Linux implant, dubbed PoisonedRefresh, that backdoors compromised F5 BIG-IP Access Policy Manager systems by injecting PHP web shells directly into server memory while leaving legitimate files on disk unchanged. The malware has been associated with exploitation of CVE-2025-53521, a critical unauthenticated remote code execution vulnerability in BIG-IP APM when an access policy is configured on a virtual server. F5 has confirmed exploitation of the flaw and has linked the related compromise activity to a cluster
CrowdStrike is investigating a publicly released proof-of-concept exploit that a security researcher says can elevate local privileges to SYSTEM level on Windows machines running its Falcon endpoint sensor. The exploit, dubbed FalconFlank, was published on GitHub on September 3 by a researcher using the names Nightmare Eclipse, Chaotic Eclipse and MSNightmare. The researcher described it as a zero-day privilege-escalation flaw that abuses Falcon Sensor's Microsoft Office malicious-macro remediation function. CrowdStrike has not publicly confirmed the underlying vulnerability. The company said it was
IDScan. net is facing a growing wave of proposed class action lawsuits in Louisiana over allegations that its identity-verification systems were connected to a massive exposure of driver's licence and other government-issued identification records. At least eight federal complaints had been filed against the New Orleans-based company by September 4 in the US District Court for the Eastern District of Louisiana, court dockets show. Plaintiffs include Marc Rioux, Jared Greenbaum, Martha Sealy, Matthew Bunch, Nicholas Layman, David Wagner, Charles Eddie Buckles,
Artificial intelligence is pushing cyber resilience from a technical concern into a boardroom test of whether organisations can withstand disruption, protect trust and restore operations when attacks strike. The pressure intensified after Financial Stability Board chair Andrew Bailey warned G20 finance ministers and central bank governors on August 31 that frontier AI could materially alter the speed, scale and economics of cyber risk. Bailey said its potential impact was the most immediate concern for the financial system and called for robust
Used-car marketplace CARS24 has complained to cybercrime police that confidential information linked to about 3,100 customers was unlawfully taken and passed to a competing business and outside vehicle dealers, with individual sales leads allegedly offered for roughly ₹1,000 each. The company has estimated the resulting commercial loss at about ₹5.70 crore, according to details of the complaint. The figure is CARS24's assessment of business damage and should not be read as a police finding or a confirmed valuation of the information
A Russian state-linked cyber-espionage group has deployed a newly documented Windows backdoor, HOOKEDGE, against government, diplomatic and defence-related organisations in Romania, Spain and Türkiye, according to threat intelligence published in late August. Researchers at Recorded Future’s Insikt Group said the activity ran from late September 2025 to early April 2026 and was attributed with moderate confidence to BlueDelta, a cluster that overlaps with APT28, Fancy Bear and Forest Blizzard. Western security agencies have linked APT28 to Russia’s GRU military intelligence service. HOOKEDGE
Threat actors are exploiting leaked Amazon Web Services credentials to hijack costly generative AI models on Amazon Bedrock, turning compromised cloud identities into a route for unauthorised inference and potentially large charges against victim accounts. FortiGuard Labs disclosed on September 3 that it had analysed an AWS account compromise involving a long-lived Identity and Access Management access key carrying AdministratorAccess permissions. The stolen credential was used to create a new IAM user, subscribe to foundation models through AWS Marketplace and invoke
Cybercrime group Toy Ghouls has deployed two custom Windows backdoors that use HiveMQ and the Matrix-based Element messaging system for command-and-control, marking a shift towards purpose-built malware. Security researchers said the tools, identified as mqtt-bird-agent 0.1.0 and matrix-bird-agent 0.1.0, were first observed in early July. Toy Ghouls, also tracked as Bearlyfy, Laboo. boo and Feral Wolf, has targeted organisations in Russia and is assessed to be financially motivated. The HiveMQ variant uses the public broker at broker. hivemq. com to exchange information
OpenAI has committed $1 billion to subsidise access to its Daybreak cybersecurity programme, targeting essential-service operators and other under-resourced defenders as artificial intelligence rapidly reshapes both cyber attacks and cyber defence. The company said the funding will support subsidised access to Daybreak models and products, training, technical assistance and partnerships, with the initial focus on the United States. OpenAI said it expects the commitment to be consumed over the next six months before the model is expanded to partner countries. Priority recipients
A Russian national accused of helping infect about 80,000 freelance workers with malware has been extradited to the United States and placed in federal custody after appearing in court in San Francisco. Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025 and extradited on August 28, 2026, the US Department of Justice said. He made his initial appearance in federal court on August 31, where he was remanded in custody. A federal grand jury indictment, filed on June 1, 2021
Nutex Health has confirmed that an unauthorised third party stole sensitive patient, employee, provider, business and financial information from its computer network and threatened to publish the data externally. The Houston-based healthcare provider disclosed the findings in an August 31 filing with the US Securities and Exchange Commission, upgrading its earlier notification of the intrusion to a report under the regulator’s category for material cybersecurity incidents. The company said its investigation remained under way and that it was still assessing the
A Chinese-speaking cybercrime group has compromised government and education websites across Brazil and turned trusted domains into infrastructure for a search-engine optimisation fraud operation, security researchers disclosed on Wednesday. Check Point Research said the campaign, active since mid-2025, uses malicious Apache modules installed on breached web servers to redirect visitors and search crawlers towards attacker-controlled gambling and sports-betting pages while retaining the legitimate website address in the browser. The company has named the cluster Gambling Goblin and assessed with medium-to-high confidence that