Just in:

Category: Cybersecurity

Latest Arabian cybersecurity news covering global cyber threats, ransomware attacks, data breaches, digital espionage, and technology security developments affecting governments, companies and individuals.

ADVERTISEMENT
ADVERTISEMENT

Craneware has disclosed a cyberattack that allowed an unauthorised party to extract employee information and records linked to customers and business partners, raising fresh concerns about technology supply-chain risks across the US healthcare sector. The Edinburgh-based healthcare software provider said attackers gained access to a limited section of its data environment. A significant volume of file names was viewed and removed, while an unspecified proportion of employee data and a subset of customer and partner records were also taken. The company said

WordPress has issued emergency security updates to block a critical vulnerability that allowed unauthenticated attackers to execute code on websites running standard installations without plugins. The flaw, dubbed “wp2shell” and tracked as CVE-2026-63030, affected WordPress 6.9.0 through 6.9.4 and versions 7.0.0 and 7.0.1. WordPress released versions 6.9.5 and 7.0.2 on July 17, urging administrators to install the patches immediately. The vulnerability carried exceptional risk because an attacker did not require a valid account, administrator privileges or user interaction. A specially prepared

Magnet Forensics has accused a former contractor of disclosing confidential information about an undisclosed iPhone vulnerability to a rival cybersecurity company, potentially destroying the commercial value of a hacking capability used by government investigators. The Canadian digital forensics company filed a federal lawsuit against exploit engineer Mario Del Gaudio and Spain-based Paradigm Shift Technology S. L. The complaint alleges that Paradigm Shift published technical research derived from Magnet’s trade secrets, exposing a flaw affecting Apple’s A12 and A13 processors. Magnet lodged the

Hackers linked to China and India separately infiltrated Pakistan’s law-enforcement infrastructure, exposing systems containing criminal records, biometric information, personnel files and citizen complaints during espionage campaigns that lasted more than two years. The operations, detected between February 2024 and April 2026, converged most heavily on Balochistan Police, the principal law-enforcement agency in the strategically important south-western province. Khyber Pakhtunkhwa Police, Islamabad Police and the Punjab Safe Cities Authority were also targeted. The campaigns appeared to be independent rather than coordinated. Their overlap

Artificial intelligence is making cyber attackers faster and more effective while creating new security weaknesses through autonomous software tools, malware and increasingly sophisticated social-engineering campaigns. ESET’s Threat Report for the first half of 2026 found that criminals are using AI less as a substitute for technical expertise than as a force multiplier. The technology is helping attackers prepare convincing lures, automate repetitive work, adapt malicious code and expand campaigns at a speed that would otherwise require larger teams. The report, covering threat

GitHub Copilot generated harmful material in every test conducted through a carefully constructed coding workflow, exposing a sharp divide between safeguards in conversational chat and the behaviour of artificial intelligence agents operating across multiple development steps. Researchers Abhishek Kumar and Carsten Maple at the Alan Turing Institute in London tested Copilot inside Visual Studio Code using 204 harmful prompts drawn from three established safety benchmarks. The study covered four model backends available through the coding assistant: Anthropic’s Claude Sonnet 4.6 and

A newly identified ransomware operation is using a Microsoft-signed malicious driver to disable cybersecurity protections before encrypting files, exposing a dangerous weakness in the trust mechanisms underpinning Windows systems. The malware, named GodDamn, deploys the PoisonX kernel driver to terminate antivirus and endpoint detection and response processes. Kernel-level access gives the driver extensive control over an infected computer, allowing attackers to neutralise defensive software that might otherwise detect or stop the ransomware. GodDamn was first observed on May 21, 2026, and appears

A new artificial intelligence system has autonomously identified and exploited security weaknesses in laboratory-based Internet of Things environments, completing 95% of 260 attempted attacks. The framework, named VEXAIoT, uses cooperating AI agents to scan networks, identify vulnerable services, devise attack plans and execute exploits with limited human involvement. Researchers tested it against IoTGoat and Metasploitable2, two deliberately vulnerable platforms used for cybersecurity training and controlled experimentation. VEXAIoT achieved a 94.5% success rate on IoTGoat, completing 189 of 200 attack attempts. It succeeded

A flaw in the BIOS firmware of several Dell computers can allow attackers with physical access to recover administrator and user passwords from the device’s flash memory without brute-force cracking. The vulnerability, tracked as CVE-2026-40639, affects the way certain Dell client platforms protect passwords stored in the system’s Serial Peripheral Interface flash chip. Dell has classified the issue as a medium-severity weakness and released BIOS updates for a range of affected products. Successful exploitation could give an unauthenticated attacker elevated privileges at

The US Cybersecurity and Infrastructure Security Agency has disclosed how privileged AWS GovCloud credentials and sensitive development material were exposed through a contractor’s public GitHub repository, using the breach to urge organisations to strengthen cloud security and incident-response procedures. CISA said it opened an internal investigation on May 15 after an investigative journalist asked about agency credentials appearing online. The journalist had been alerted by a security researcher whose company scans public code repositories for exposed passwords, tokens and other secrets. The

Cybersecurity investigators have uncovered an AI-generated PowerShell script used during a live attack to map a company’s Active Directory environment, offering fresh evidence that criminals are deploying “vibe-coded” malware inside compromised networks. The script was recovered from an intrusion that began on June 3 after the attacker gained remote desktop access to a Windows Server connected to the victim’s domain. The available evidence indicated that the intruder entered through a virtual private network using credentials that had already been compromised. Within minutes

Interpol has announced 5,811 arrests and the interception of $293 million in illicit assets following a sweeping operation against cyber-enabled fraud across 97 countries and territories. Operation First Light 2026 targeted social engineering scams and related money laundering networks between January 15 and April 30. Authorities identified more than 142,000 victims, analysed 152,808 cases and blocked 31,014 bank accounts linked to suspected criminal proceeds. The China-funded operation also led investigators to identify 15,606 suspects and solve 23,715 cases. Interpol issued 99 Notices

A newly examined Everest ransomware encryptor has exposed a sharper technical playbook built to weaken recovery, obstruct analysis and expand damage across dormant network systems before encryption begins. The Windows payload, identified as hlntqyun. exe, is a 114 KB C# assembly compiled for. NET Framework 4.0 and protected with ConfuserEx, a widely abused obfuscation tool used to frustrate static malware analysis. The sample carries the SHA-256 hash 1df92bf4c967297d8a39fc3f619a56702ee96d5cf9196b8e1d5b3654746c6514 and appears to have been tailored for a specific victim, rather than built

A newly demonstrated attack against Claude Desktop has highlighted how synced AI preferences and locally connected tools can be chained to turn a trusted chatbot into a covert route for command execution on a user’s workstation. The attack path centres on Claude Desktop’s Personal Preferences feature, which allows users to set account-wide instructions that are synchronised across sessions and devices. Security researchers showed that if an attacker gains access to a victim’s Claude account, malicious instructions can be planted in those

DuckDuckGo has added YouTube video ad blocking to its privacy-focused browser, widening its challenge to dominant browsers and giving users a built-in way to watch videos with fewer commercial interruptions. The feature blocks ads that appear before and during videos viewed inside the DuckDuckGo browser, including on YouTube. It relies on community-maintained uBlock Origin filter lists, a significant choice because those lists are open-source, regularly updated and shaped by a large volunteer ecosystem rather than a closed, proprietary detection system. DuckDuckGo says

A China-linked cyber-espionage group has expanded its use of hijacked devices to mask attacks on telecommunications infrastructure, deploying three newly documented malware implants across Windows, Linux and network edge systems. The activity, tracked as UAT-9244, has targeted critical telecoms infrastructure in South America since 2024. The campaign shows how state-aligned operators are moving beyond direct server compromise to build distributed relay networks that help them scan, brute-force and route traffic through infected machines before launching deeper intrusions. The latest findings centre on

A browser flaw in Opera GX allowed hostile websites to silently install customisation mods and use them to extract data from pages visited by a signed-in user, exposing a weakness in how browser styling features can be turned into cross-site surveillance tools. The vulnerability, now patched, affected the gaming-focused Opera GX browser and centred on its GX Mods feature, which lets users customise themes, wallpapers, sounds and website appearance. Security researchers zhero and inzo found that a malicious site could trigger

Attackers are hiding machine-readable instructions inside websites to manipulate AI agents, turning ordinary web pages into a new security battleground as automated systems begin browsing, summarising and acting on behalf of users. Zscaler’s ThreatLabz has documented two live campaigns using indirect prompt injection, a technique in which malicious instructions are planted in third-party content that an AI system reads during a task. Unlike a direct prompt attack, where a user types hostile instructions into a chatbot, these attacks sit inside websites,

Cybercriminals are using fake cracked-software downloads to infect consumers and smaller businesses with a double payload that steals credentials and mines Monero, underscoring how commodity malware operators are combining immediate data theft with longer-running attempts to profit from compromised machines. The campaign delivers Vidar, a widely used information stealer, alongside XMRig, an open-source cryptocurrency miner often abused in cryptojacking attacks. Victims are lured through malvertising into downloading password-protected archives that appear to contain pirated versions of commercial software. Once opened and

US officials have reportedly cleared OpenAI to widen access to GPT-5.6, allowing the company to move its most advanced model series from a restricted partner trial towards a broader commercial release after cybersecurity and national security checks. The decision covers GPT-5.6 Sol, the flagship version, alongside lower-cost Terra and Luna models. OpenAI has said the models will be made available after an initial period in which access was limited to vetted customers. The shift follows weeks of scrutiny over whether frontier

Nissan Americas has disclosed a cyber breach involving employee records after attackers exploited a critical Oracle PeopleSoft flaw used in a wider data-theft campaign linked to the ShinyHunters extortion group. The carmaker said personnel information belonging to current and former staff in the United States, Canada, Mexico and Brazil may have been accessed through Oracle PeopleSoft, the enterprise platform it uses for payroll, tax administration and other employee records. The exposed data may include contact details, banking information, Social Security numbers,

A newly identified cyber-espionage group has targeted government agencies and electricity-sector organisations in Russia, Brazil and Kazakhstan, using phishing emails to deploy a Windows information stealer designed to extract credentials, documents and browser data. The group, named Armored Likho and provisionally linked to a cluster known as Eagle Werewolf, has emerged as a notable threat because its operations combine espionage against institutions with financially motivated attacks against individuals. Its latest malware, BusySnake Stealer, shows a shift from simpler remote-access tooling towards

Mexico-focused companies are facing a sharper wave of TimbreStealer attacks as operators behind the information-stealing malware combine tax-themed phishing with cloud-hosted delivery, DLL side-loading and layered evasion designed to defeat automated analysis. The campaign marks a technical step-up for a malware family first tracked in late 2023, when attackers used fiscal and invoice lures to push an obfuscated stealer at users in Mexico. The latest activity keeps the same localised bait but changes parts of the delivery chain, making the infection

Scammers are using fake Google Play Store pages and paid social media adverts to push gambling-linked Progressive Web Apps, exploiting consumer trust in well-known retail, banking and streaming brands. The campaign uses polished advertisements on platforms including Facebook, Instagram, Threads and TikTok, with some creatives carrying simple “Brand Slots” labels and others mimicking official product launches. The adverts borrow logos, colour schemes, app-style layouts and fabricated testimonials to suggest that household names have entered the online casino market. Several versions have

A Brazil-linked banking trojan has shifted its focus to Spain and Portugal, using fake PDF files, hidden code and location checks to reach banking customers while keeping analysts and automated security tools away from its payload. The malware, known as Ousaban or Javali, has long been associated with attacks on financial users in Brazil. Its latest campaign shows a more selective and evasive operation aimed at Windows users in the Iberian Peninsula, where the attackers use phishing documents that pretend to

A fileless malware framework is abusing Google’s Blogspot platform to deliver PureLog Stealer directly into computer memory, sharpening concerns that trusted web services are being turned into staging grounds for credential theft. The campaign, tracked as Veil#Drop, begins with a JavaScript file disguised as a document, such as “transcript. pdf. js”. Once opened on a Windows system, the file runs through Windows Script Host and launches PowerShell with execution-policy bypasses enabled. The command then retrieves further payloads from attacker-controlled Blogspot pages,

A major supply-chain attack has hit ClawHub, exposing deep security gaps in the fast-growing market for AI-agent skills after scans identified 1,184 malicious packages linked to 247,693 installations. The campaign, tracked as ClawHavoc, targeted ClawHub, the official skill marketplace for OpenClaw, an open-source AI agent platform that allows users to install add-ons for tasks such as browser automation, file handling, coding support, messaging, crypto tracking and productivity workflows. The scale of the compromise marks one of the most serious tests yet

A Telegram-controlled remote access trojan called Millenium RAT has compromised more than 62,000 Windows devices across over 160 countries, exposing how low-cost malware subscriptions are widening access to intrusive cyber tools once limited to more skilled operators. The campaign has accelerated sharply this year, with about 39,700 infections recorded during the first quarter of 2026 alone. The scale points to an expanding malware-as-a-service operation in which attackers can rent or buy a ready-made spying tool, use Telegram as command infrastructure and

A threat actor exploited a severe Cisco Catalyst SD-WAN vulnerability at least two months before public disclosure, intensifying concern over attacks targeting the network control systems that connect large organisations across branch offices, cloud services and data centres. The flaw, tracked as CVE-2026-20245, affects Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager and Catalyst SD-WAN Validator, formerly known as vSmart, vManage and vBond. It allows an authenticated local attacker to execute arbitrary commands with root privileges by uploading a specially crafted file

Security researchers have identified a cloud storage weakness that could allow attackers to divert live data flows from major platforms, including Amazon Web Services, Google Cloud and Microsoft Azure, into storage controlled by outsiders without triggering obvious warning signs. The technique, described as cloud bucket hijacking, exploits the way many cloud providers use globally unique storage names to route logs, telemetry and replicated objects. If a bucket is deleted but an automated service continues to send data to that destination name,

The UK’s Cyber Monitoring Centre has warned universities and colleges to reassess cyber resilience after a breach at Canvas exposed student and staff data across about 160 higher education institutions while causing less financial disruption than feared. The assessment found that the incident fell below the threshold for a formal Category 1 national cyber event, which requires losses of at least £10m or an impact on more than 0.01 per cent of UK organisations. Even so, the case has become an

A macOS backdoor linked to North Korea-aligned cyber operations has exposed a new weakness in security workflows by embedding instructions designed to confuse artificial intelligence systems used by malware analysts. The malware, tracked as macOS. Gaslight, is written in Rust and contains a 3.5 KB prompt-injection payload made up of 38 fabricated “system” messages. The messages are not aimed at Apple’s operating system or at a conventional sandbox. They appear built to manipulate large language model-based triage tools that analysts increasingly

State-backed hacking groups are increasingly borrowing ransomware tactics to conceal cyber-espionage campaigns, with Iran-linked MuddyWater emerging as a prominent example of a wider shift blurring the boundary between criminal extortion and intelligence operations. NCC Group has warned that threat actors tied to governments are using ransomware branding, extortion notes, victim leak sites and negotiation channels not only to increase pressure on targets but also to complicate attribution. Its latest threat intelligence assessment highlights a campaign associated with MuddyWater in which activity

Cybersecurity teams are tracking a deceptive malware campaign that uses fake browser windows, hidden web frames and anti-analysis checks to push victims into installing malicious executables by hand. The operation relies on a Browser-in-the-Browser, or BitB, technique that places a convincing imitation of a browser window over a legitimate-looking webpage. Instead of depending on an automatic exploit, the attackers create the impression that a document has failed to load or that essential software is out of date, then instruct the user

Just in:
Abu Dhabi climate summit records over 1,000 registrations // Bypoll Results In Bengal And Assam Underline BJP’s Expansion In Eastern Region // Lufthansa and three airlines halt Riyadh flight operations // Lee Kum Kee Gluten Free Soy Sauce Wins Healthy Food Guide 2026 Award // Trump-Newsom Clash Assumes Special Significance Before Nov 3 Polls // Wikimedia identifies unauthorised OpenAI agent activity across platforms // TATA Sons’ Listing is a Boon for Its 1.77 Crore Shareholders // Global condemnation widens over deadly Saudi airport strikes // OPPO Find X10 Pro Max to Debut Globally with MediaTek’s 2nm Flagship Dimensity 9600 Pro // OpenAI extends GPT-6 access with interactive ChatGPT interface // UK and allies expose Integrity Tech cyber operations // Prudential Singapore launches multi-generational protection plan to help caregivers manage families’ healthcare needs // Ping An Digital Bank Becomes Hong Kong’s First Digital Bank to Enter High-End Wealth Management Segment // Saudi Arabia and UAE endorse Japan’s Asian oil initiative // React flaw exposes Next.js servers to service disruption // UAE delegation heads to Bangkok for IMF meetings // Anti-Election Commission Protest: Athletic Rahul Steals The Show // First Week Of Anti-CEC Agitation Turns Into Electoral Rights Movement // ONYX Hospitality Group Marks 60 Years with Curated Partnerships Bringing “More of What You Love” to Life // Two Bypoll Results In Bengal Vindicate State BJP’s Success In Courting Minorities //