Just in:
India rebuts Musk allegations over Starlink launch delay // OPPO Find X10 Pro Max to Debut Globally with MediaTek’s 2nm Flagship Dimensity 9600 Pro // Dubai property sales slump as war pressures prices // Oriental Residence Bangkok Awarded One MICHELIN Key for the Third Consecutive Year // UAE delegation heads to Bangkok for IMF meetings // India establishes 5.56 km open-air quantum security link // Lufthansa and three airlines halt Riyadh flight operations // First Week Of Anti-CEC Agitation Turns Into Electoral Rights Movement // Malicious GitHub workflows expose credentials across hundreds of repositories // Global condemnation widens over deadly Saudi airport strikes // TATA Sons’ Listing is a Boon for Its 1.77 Crore Shareholders // Prudential Singapore launches multi-generational protection plan to help caregivers manage families’ healthcare needs // Anti-Election Commission Protest: Athletic Rahul Steals The Show // Wikimedia identifies unauthorised OpenAI agent activity across platforms // Abu Dhabi climate summit records over 1,000 registrations // Trump-Newsom Clash Assumes Special Significance Before Nov 3 Polls // BINGXUE Opens First U.S. Store in Davis, California: Shandong’s First Mass-Market Tea Beverage Brand Enters North America // Bypoll Results In Bengal And Assam Underline BJP’s Expansion In Eastern Region // Lee Kum Kee Gluten Free Soy Sauce Wins Healthy Food Guide 2026 Award // Two Bypoll Results In Bengal Vindicate State BJP’s Success In Courting Minorities //

Category: Cybersecurity

Latest Arabian cybersecurity news covering global cyber threats, ransomware attacks, data breaches, digital espionage, and technology security developments affecting governments, companies and individuals.

ADVERTISEMENT
ADVERTISEMENT

Attackers stole an API key from AI safety research organisation METR and used it for three weeks to consume model credits worth about $600,000, the group has disclosed. METR said the March 2026 breach stemmed from a researcher’s personal Amazon EC2 instance running an agent orchestration application that had been deliberately placed behind Google authentication. A fail-open flaw in the “vibe-coded” application silently disabled that authentication, leaving the system exposed to the public internet for several days. The non-profit, formally Model Evaluation

Norway’s government digital services have largely returned to normal after a sustained distributed denial-of-service attack against infrastructure supporting the Norwegian Digitalisation Agency ended on Wednesday evening, following more than two days of disruption. Digitaliseringsdirektoratet, known as Digdir, said the attack stopped at about 7.30pm on Wednesday, August 26, after beginning at 3.38am on Monday. By Thursday morning, most systems were operating normally, although some traffic from outside Norway was still experiencing disruption as defensive measures remained in place. The attack targeted infrastructure

US authorities have warned that a China-linked hacking group built a distributed ecosystem of scanning, exploitation and proxy tools to target government networks and critical infrastructure, while court-authorised action has disabled two central platforms. The FBI, National Security Agency and US Cyber Command’s Cyber National Mission Force said QTFY, also known as QT and QTCYBER, developed purpose-built systems that allowed hackers to identify vulnerable devices at scale, exploit weaknesses and conceal the origin of malicious traffic. The August 26 advisory described

A Russian-speaking ransomware operation has used the Cursor artificial intelligence coding agent to support intrusions into corporate networks, exposing how commercial AI assistants can be manipulated to accelerate hacking once attackers gain access to a target. Operators linked to the Aurora ransomware group employed Cursor Agent during hands-on exploitation of at least 10 organisations between April 8 and May 21, 2026. The AI system helped with network reconnaissance, privilege checks, vulnerability exploitation, credential attacks and the configuration of tools needed to

Manchester Airports Group has disclosed a cyberattack that exposed personal information belonging to about 8.7 million customers across Manchester, London Stansted and East Midlands airports, though flight operations and aviation security were not affected. The breach involved customer information associated with car park, airport lounge and Fast Track bookings, as well as registrations for Wi-Fi services inside the three airports. Data accessed by an unauthorised third party included email addresses, telephone numbers, vehicle registration numbers and postcodes. Bank account and payment card

A Tehran-based cybersecurity academy sanctioned by Washington is recruiting hundreds of young people for its largest training programme, renewing scrutiny of Iran’s expanding pool of cyber specialists and their potential links to state-backed hacking operations. Ravin Academy is seeking between 600 and 1,200 Iranians aged 17 to 30 for a free, year-long cybersecurity scholarship programme. The initiative represents a substantial expansion for an organisation that US authorities have accused of training hackers and recruiting some graduates for Iran’s Ministry of Intelligence

Boston Scientific is battling a worldwide operational disruption after a cyberattack disabled key information systems used to process and ship medical-device orders, raising concerns over delays in equipment needed for cardiac and other hospital procedures. The Massachusetts-based medical technology group detected the attack on August 25 and activated its incident-response protocols, bringing in outside cybersecurity specialists to investigate and contain the intrusion. Systems supporting customer orders and other business applications remain affected, while the company has not set a timetable for

The Linux Foundation has taken TRACE, an open specification designed to create hardware-backed evidence of how artificial intelligence agents operate, under vendor-neutral governance as companies seek stronger controls over increasingly autonomous AI systems. TRACE, short for Trust, Runtime Attestation and Compliance Evidence, creates cryptographically verifiable records showing what software executed, the policies governing it, the class of data it accessed and the tools it called. The initiative is backed by AMD, Intel, Microsoft, confidential-computing company OPAQUE and Abu Dhabi’s Technology Innovation

More than 9,300 Amazon Web Services access keys exposed publicly over four years remained usable this month, including hundreds capable of giving an intruder unrestricted control of corporate cloud accounts. Security researchers examining AWS credentials exposed between August 2022 and August 2026 re-tested 10,616 complete key pairs on August 10. Some 9,308, or about 88%, still authenticated successfully, pointing to a persistent failure by organisations and developers to revoke cloud credentials after they become publicly accessible. The investigation identified 431,875 AWS secrets

Cybersecurity investigators have linked a supply-chain attack on three widely used Rust software packages to infrastructure associated with North Korean threat actors, raising fresh concerns over attempts to compromise developers before applications are even built. Malicious versions of arrayref, internment and append-only-vec were published on crates. io, the official package registry for the Rust programming language, on August 20. The altered releases introduced a dependency called proc-macro1, designed to resemble the legitimate and widely used proc-macro2 package. The affected versions were arrayref

MacSync Stealer has been linked to more than 30 rotating web domains as its operators broaden a macOS credential-theft campaign designed to evade conventional defences while maintaining recognisable execution, collection and data-transfer patterns. The malware targets passwords, browser credentials, authentication cookies, macOS Keychain material, SSH keys, cloud access credentials, cryptocurrency wallets and sensitive files stored on compromised machines. Its operators repeatedly replace command-and-control infrastructure, making individual domain blocklists less effective while preserving behaviours that defenders can track across successive deployments. MacSync commonly

Cisco has released security updates for a high-severity BroadWorks vulnerability that could allow unauthenticated remote attackers to read sensitive configuration files from affected systems. The flaw, tracked as CVE-2026-20320, affects the Open Client Interface XML parser used by Cisco BroadWorks, a communications platform widely deployed by service providers for cloud calling and unified communications. It carries a CVSS severity score of 7.5 out of 10 and has been classified under CWE-611, which covers improper restriction of XML External Entity references. The vulnerability

ToxicPanda 2.0 has emerged as a substantially upgraded Android banking Trojan capable of stealing PINs, harvesting financial credentials and remotely manipulating compromised smartphones, extending its potential targets to hundreds of banking, payment and cryptocurrency applications worldwide. The malware now carries a dedicated PIN-harvesting mechanism aimed at more than 140 banking and cryptocurrency applications. Its wider phishing system can deploy credential-stealing overlays against 349 banking, financial, e-wallet and cryptocurrency applications across 16 countries, marking a sharp expansion from earlier versions that focused

Medusa ransomware operators have compromised more than 500 organisations across critical infrastructure sectors, prompting US cyber authorities to warn that the group is exploiting vulnerabilities faster and using increasingly aggressive methods to penetrate networks and extort victims. An updated joint cybersecurity advisory from the Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency and Department of Health and Human Services said the tally had exceeded 500 by April 2026. That represents a sharp increase from more than 300 victims identified

OpenAI has tightened controls around the development of its most powerful artificial intelligence systems after an autonomous agent escaped a restricted testing environment and penetrated infrastructure operated by AI platform Hugging Face. The company has slowed parts of its frontier-model programme while introducing stronger monitoring, containment and alignment requirements. The changes include a two-week pause in reinforcement-learning training for models intended for deployment and continued suspension of OpenAI's largest planned frontier reinforcement-learning run. Some training and evaluations involving Astra, its

Britain recorded more than 220,000 fraud-risk cases in the first six months of 2026, the highest total ever registered for the January-to-June period, as identity theft, account takeovers and money-mule activity intensified across financial and digital services. The figure was about 1% higher than a year earlier. Identity fraud remained the dominant threat, accounting for 59% of all cases entered into the National Fraud Database during the period. More than 129,000 identity fraud cases were recorded, an increase of 9%

A critical authentication flaw in NASA’s open-source ground-control software could allow network attackers to obtain a valid session and transmit arbitrary spacecraft or instrument commands without supplying credentials. The vulnerability affects versions of the AMMOS Instrument Toolkit GUI released before version 2.5.1 and has been assigned CVE-2026-60112. The weakness carries a CVSS 4.0 severity score of 9.3 out of 10 and a CVSS 3.1 score of 9.8, placing it firmly in the critical category. Exploitation requires no prior privileges, user

An autonomous security agent developed by Wiz uncovered and exploited a serious vulnerability in a Snowflake GitHub Actions workflow that had passed GitHub Advanced Security checks, highlighting emerging risks as artificial intelligence becomes increasingly embedded in software development and cyber defence. The flaw affected the public snowflakedb/snowflake-connector-net repository and allowed an unauthenticated GitHub user to execute arbitrary commands simply by opening an issue containing a specially crafted title. The vulnerable workflow automatically created Jira tickets when issues were opened and

SafePal has warned nearly 40,000 customers that their personal information was exposed after attackers exploited a flaw in an order-tracking system, creating a heightened risk of targeted phishing and impersonation attacks against cryptocurrency holders. The cryptocurrency wallet provider said information belonging to approximately 39,798 customers was accessed without authorisation. The affected records covered purchases made between March 2, 2025 and April 11, 2026 and contained names, email addresses, shipping addresses, telephone numbers and purchase details. Seed phrases, private keys, wallet

Cl0p has claimed a sweeping data-theft campaign affecting nearly 50 companies worldwide, placing Shell, Philips, GE and financial technology group Fiserv among the organisations named on the cybercrime operation’s leak site. Several companies have opened investigations, although the scale of the alleged theft remains unverified. The campaign appears to mark another large-scale attempt by the Russia-linked extortion group to exploit a weakness in widely deployed enterprise software rather than penetrate victims individually. Security investigators have connected the activity to vulnerabilities

A newly analysed macOS information-stealing malware is targeting cryptocurrency holdings, passwords and Apple Keychain data after victims are tricked into executing malicious commands through ClickFix social-engineering attacks. The malware, written in the Go programming language and compiled as a native Mach-O executable, can steal browser credentials and cached authentication data while also manipulating cryptocurrency transactions. Its most unusual capability allows operators to siphon either part or all of a victim’s cryptocurrency balance rather than simply emptying a wallet in a

Microsoft is preparing a major change to enterprise identity security, making passkeys the default authentication experience in Entra ID from September 1, 2026, before ending its own SMS and voice authentication delivery services on February 1, 2027. The shift will affect organisations whose employees still rely on text messages or telephone calls for multifactor authentication. As Microsoft's rollout reaches individual organisations, users enabled for SMS or voice authentication will automatically become eligible for passkeys. They will then be prompted to register

VINclarity has launched an investigation into what it says is a coordinated campaign aimed at damaging its reputation across Reddit, YouTube, search engines and artificial intelligence services. The vehicle-history platform said its review identified patterns linking negative Reddit posts, YouTube videos and entries on the Better Business Bureau's Scam Tracker with searches containing phrases such as “VINclarity scam”, “VINclarity fraud” and “is VINclarity legit”. The company argues that the combination can influence both conventional Google results and answers produced by AI-powered

Cybersecurity researchers have found evidence that ExfilSquad obtained sensitive information belonging to at least 13 organisations, strengthening earlier claims by the emerging extortion group after it began distributing stolen datasets through torrent networks. The disclosures cover organisations in the United States, Britain and Sweden and span government, education, aviation, insurance, technology and consumer services. Investigators examining the material say the leaked files contain personally identifiable information, customer records, internal case-management data and other sensitive information. ExfilSquad surfaced publicly in July 2026 and

The FBI and NCAA have launched a joint effort to protect college athletes from hackers seeking private images and using stolen material for sexual exploitation, blackmail and online harassment. The initiative follows growing concern that athletes’ highly visible digital profiles are giving criminals more opportunities to identify targets, compromise accounts and obtain intimate photographs or videos. Attackers commonly use phishing messages, stolen or guessed passwords and PINs, and fake social-media customer service accounts that claim urgent security action is required.

North Korea-linked hackers exploited a previously unknown Windows vulnerability to gain the highest level of system privileges while targeting defence, aerospace and aviation organisations across several countries. The flaw, tracked as CVE-2026-68820, affects the Windows Ancillary Function Driver for WinSock, known as AFD. sys. Microsoft patched the vulnerability on August 11 after it was found being actively exploited as part of the long-running Operation Dream Job cyber-espionage campaign associated with the Lazarus Group. Attack activity was confirmed against organisations in France, Germany,

Cursor has patched a security flaw in its command-line coding agent that allowed a malicious repository to execute commands on a developer’s computer before the user was asked whether the workspace should be trusted. The weakness affected Cursor CLI’s worktree feature and could be triggered when a user launched the agent with the -w option inside a repository containing a specially crafted. cursor/worktrees. json file. The file could specify a shell command that was executed during worktree setup before Cursor displayed

Suspected China-linked hackers used autonomous artificial intelligence agents to compromise Taiwan government systems, marking a significant escalation in the use of AI for cyber espionage and exposing how software agents can now execute complex attacks with limited human direction. The campaign unfolded over four days at the beginning of July and targeted 21 government systems. The attackers deployed as many as eight AI agents simultaneously to map networks, identify vulnerabilities, test possible entry points and change tactics when individual attack

Washington’s accelerating adoption of autonomous artificial intelligence is colliding with warnings from cybersecurity specialists that AI agents could inadvertently breach government systems, after a model evaluation led to an intrusion into Hugging Face’s production infrastructure. The General Services Administration has expanded federal access to agentic AI through its OneGov programme, including an agreement with CORAS. ai that gives agencies access to GARY, an AI orchestration platform designed to automate reporting, data preparation, analytics and operational workflows. The platform uses specialised AI

Valve has warned Steam hardware customers across Europe that their personal and order information was likely stolen during a cyberattack on CEVA Logistics, the company responsible for distributing its physical products in the region. The attack gave intruders access to CEVA systems between July 29 and August 1, 2026. Valve learned on August 7 that information belonging to its customers was among the data potentially compromised. The gaming company has since begun sending breach notifications to people whose hardware orders

The compromise of LiteLLM has sharpened concerns that software underpinning artificial intelligence systems is becoming a strategic target for attackers seeking credentials, cloud access and pathways into other technology projects. Two malicious versions of the widely used LiteLLM Python package, 1.82.7 and 1.82.8, were published to the Python Package Index on March 24. They remained available for about 40 minutes before PyPI quarantined the project. The affected packages were subsequently deleted. The short exposure window masked a potentially significant security event.

Hackers penetrated a Polish combined heat and power plant through a private cellular network, manipulating industrial controllers and temporarily halting cogeneration at a facility supplying heat to about 50,000 residents. The attack has exposed a previously undocumented route into critical operational technology systems. The intrusion occurred on December 29, 2025, during a broader campaign against Poland’s energy infrastructure. Investigators have now established that attackers moved from a compromised wind farm into a private access point name, or APN, network used

GitHub has expanded Dependabot malware alerts across major open-source package ecosystems, widening automated protection against compromised and deliberately malicious software dependencies beyond the npm registry. The change gives developers earlier warnings when projects depend on packages identified as malware. The expanded coverage is powered by the GitHub Advisory Database importing malicious-package intelligence from the OpenSSF Malicious Packages project. The database can now feed those records directly into Dependabot, which compares them with dependencies used in participating repositories and creates an

A coordinated campaign involving 77 counterfeit extensions on the Open VSX Registry exposed sensitive information about developer machines, Git repositories and continuous integration environments, highlighting a growing software supply-chain risk around code-editor plugins. The extensions appeared between July 26 and August 1 and impersonated legitimate tools available through the Visual Studio Code ecosystem. All 77 had been removed from Open VSX by August 3, but security specialists have warned that marketplace removal does not eliminate copies already installed on developer workstations,