Latest Arabian cybersecurity news covering global cyber threats, ransomware attacks, data breaches, digital espionage, and technology security developments affecting governments, companies and individuals.
Fake software downloads promoted through YouTube are being used to infect corporate employees with Vidar, an information-stealing malware that harvests passwords, browser data, session cookies and cryptocurrency wallet files before stolen credentials are traded through Russian-language cybercrime markets.The campaign shows how threat actors are shifting from noisy phishing emails to search-driven lures that exploit ordinary workplace behaviour. Employees looking for software tutorials, installers or utilities on video platforms are being pushed towards links placed in video descriptions, where apparently legitimate
Cybercriminals are exploiting tax-season anxiety by circulating fake Income Tax Department notices that push taxpayers and companies towards malware-laden downloads disguised as assessment orders and compliance documents.The campaign uses official-looking emails and cloned tax portals to make recipients believe they are facing scrutiny over alleged violations, including concealment of income or inaccurate filings. Victims are directed to external websites that imitate government communication, where buttons labelled as assessment order downloads trigger malicious files instead of official documents.Security researchers tracking the
A targeted malware campaign aimed at Pakistan’s government-linked security infrastructure has exposed how threat actors are combining social engineering, obfuscated code and trusted online services to evade conventional cyber defences.The attack was directed at employees of the Punjab Safe Cities Authority and PPIC3, using a spear-phishing email that impersonated an internal consultant and referred to the Safe Jail Project, a theme designed to appear relevant to public-security operations. The message was marked as high priority and included a read-receipt request,
Anthropic’s Claude Desktop application for macOS is facing scrutiny after a cybersecurity researcher reported that the app installs a Native Messaging bridge into multiple Chromium-based browsers without a clear consent prompt, widening concern over how AI desktop agents gain access to local systems and browser sessions.Privacy researcher Alexander Hanff published his findings on 18 April 2026 after identifying a manifest file named com. anthropic. claudebrowserextension. json on a Mac where he said he had not knowingly authorised such browser integration.
OpenAI has opened a GPT-5.5 Bio Bug Bounty programme that invites selected researchers to test whether the company’s latest model can be pushed past safeguards designed to block dangerous biological guidance.The initiative offers a reward of up to $25,000 for the first verified “universal jailbreak” capable of defeating a five-question biosafety challenge from a clean chat without triggering moderation. The model in scope is GPT-5.5 in Codex Desktop, narrowing the exercise to a defined environment while giving external specialists a
Hackers have turned a critical React Server Components flaw into a structured exploitation operation, using Telegram bots, automated scanners and AI-assisted tooling to track more than 900 confirmed compromises across internet-facing applications.The campaign centres on React2Shell, tracked as CVE-2025-55182, a maximum-severity remote code execution vulnerability disclosed in December 2025. The flaw affects React 19.0, 19.1.0, 19.1.1 and 19.2.0 through packages including react-server-dom-webpack, react-server-dom-parcel and react-server-dom-turbopack, and can allow unauthenticated attackers to execute commands on vulnerable servers through crafted HTTP requests.Fresh
Cybersecurity teams running local artificial intelligence models are facing a high-risk exposure after a flaw in Ollama’s model-processing system was found to allow attackers to extract sensitive server memory through a malicious model file.Tracked as CVE-2026-5757, the vulnerability affects the model quantisation engine used by Ollama, an open-source platform widely adopted by developers and enterprises to run large language models on personal computers, workstations and servers. The flaw enables an unauthenticated attacker with access to the model upload function to
Cyber-attacks on higher and further education institutions jumped 63 per cent over a year, exposing universities and colleges to a sharper wave of ransomware, data theft, hacktivism and state-linked intrusion as digital learning systems become central to academic life.The findings point to 425 recorded incidents across 67 countries in the latest 12-month assessment period, compared with 260 in the preceding year. The rise reflects not only more aggressive criminal activity, but also the growing value of academic data, research systems
Google Cloud is placing general-purpose Gemini models at the centre of its cybersecurity strategy, betting that broad frontier AI systems paired with specialised agents will outperform narrow models built only for security tasks.The approach, articulated by Francis deSouza, Google Cloud’s chief operating officer and president of security products, signals a deliberate shift in how the company wants enterprises to defend themselves in an era of faster attacks, expanding cloud exposure and AI-enabled threat activity. Rather than building separate cybersecurity-specific language
Phishing emails with no subject line are being used with growing frequency in campaigns aimed at executives and other high-value staff, adding another layer of deception to a threat landscape already shaped by credential theft, business email compromise and AI-assisted social engineering. CyberProof said its threat hunters tracked a marked rise in “null subject” phishing through the first quarter of 2026, with activity climbing from January to March and a further increase projected into April.The tactic is simple but
Google search advertising is being exploited in a widening campaign that lures cryptocurrency users to convincing fake sites, where attackers steal seed phrases, hijack wallet sessions and drain digital assets within minutes. Security researchers tracking the operation say the abuse is no longer sporadic but part of a sustained and technically refined effort that targets people searching for DeFi services, wallet tools and other crypto platforms.What makes the campaign especially dangerous is the use of Google’s own trusted web properties
A newly disclosed cyberattack using destructive malware known as Lotus Wiper has put Venezuela’s energy and utilities sector under sharper scrutiny, highlighting how digital sabotage is moving beyond theft and extortion towards permanent operational damage. Security researchers say the malware was designed to erase data, cripple recovery options and leave affected systems unusable, signalling a far more aggressive intent than the ransomware campaigns that have dominated critical infrastructure attacks in past years.The attack chain, uncovered in malware samples uploaded
A critical security weakness in Atlassian Bamboo Data Center and Server has exposed a fresh risk for organisations that rely on automated software build and deployment systems, after Atlassian disclosed that an authenticated attacker could remotely execute operating system commands on affected installations. The flaw, tracked as CVE-2026-21571, carries a CVSS 4.0 score of 9.4 and was published in Atlassian’s April 21 security bulletin, which covered dozens of patched vulnerabilities across its product line.The issue affects multiple Bamboo release
A software platform traced to Belarus has been identified as a key enabler of a sprawling SIM-farm ecosystem that investigators say is helping cybercriminal operations run at scale across multiple continents. The platform, known as ProxySmart, was linked to at least 94 SIM-farm locations in 17 countries, with researchers identifying 87 exposed instances of its control panel across 24 proxy providers and 35 mobile carriers.The findings cast fresh light on how mobile proxy services have evolved from a niche
Britain is confronting what its cyber defence chief has described as a “perfect storm”, with fast-moving technological change colliding with rising geopolitical tension and exposing companies, public bodies and critical infrastructure to a more dangerous class of digital attack. The warning, delivered at the CYBERUK 2026 conference in Glasgow, signals a sharper threat environment in which ransomware remains widespread but the gravest strategic risks are increasingly tied to hostile states and conflict-driven disruption.Richard Horne, chief executive of the National Cyber
Unauthorized access to Anthropic’s tightly restricted Claude Mythos Preview has sharpened concerns over how even limited-release cybersecurity AI can slip beyond its intended perimeter, raising fresh questions about vendor oversight, access governance and the pace at which powerful offensive-capable tools are entering real-world environments. Anthropic announced Mythos on 7 April as part of a controlled programme for defensive cybersecurity use, and the company is now investigating claims that a small group reached the model through a third-party vendor environment.The episode
The Gentlemen ransomware operation is building momentum across the cybercrime market, drawing in more affiliates, broadening its toolset and sharpening its focus on corporate targets as security researchers trace a faster pace of attacks through the opening months of 2026. Check Point said the group has publicly claimed more than 320 victims, with about 240 of those listed this year, a pattern that points to rapid affiliate uptake rather than a small crew acting alone.That expansion matters because The
Unchecked AI agents are triggering cybersecurity incidents across a broad swathe of companies, with data exposure, disrupted operations and direct financial damage now emerging as common consequences of a fast-moving corporate shift towards autonomous software. A new industry survey found that 65% of organisations suffered at least one AI agent-related incident over the past 12 months, while 82% said they had discovered previously unknown AI agents operating inside their environments. Among those reporting incidents, 61% cited data exposure, 43% operational
Cyber criminals are using a tampered Android app to steal payment card data and PINs in a campaign that marks a more aggressive phase in near-field communication fraud, with the latest NGate malware variant targeting users in Brazil and enabling both unauthorised payments and cash withdrawals at contactless ATMs. The newly identified strain hides inside a doctored version of HandyPay, a legitimate NFC relay application, and appears to have been active since November 2025.The operation represents a notable shift in
Lovable, the fast-growing AI app builder used by startups and large corporate teams alike, is facing scrutiny after security researchers said an API authorisation flaw exposed sensitive data from projects created before November 2025, including source code, credentials, chat histories and customer records. The company has disputed the characterisation of the incident as a data breach, arguing that some of the visibility tied to public projects reflected product design and unclear documentation rather than unauthorised intrusion.The disclosure has drawn
Grinex, a Kyrgyzstan-based cryptocurrency exchange under Western sanctions, has suspended operations after losing about one billion roubles, or roughly $13.1 million, in what it described as a highly organised cyber attack. The platform said the breach was a targeted operation and alleged that intelligence services from “unfriendly” Western states were behind it, though it did not provide public evidence to support that claim.The theft has drawn attention because Grinex sits at the intersection of cybercrime, sanctions evasion and Russia’s
Windows users are facing a sharper cyber threat after researchers identified a campaign that pairs the long-running Gh0st remote access trojan with CloverPlus adware, giving attackers a mix of covert control and instant income from poisoned web traffic. The operation uses a single obfuscated loader to unpack both payloads, turning one infection into a dual-purpose compromise that can spy, persist and monetise at the same time.Two payloads, one foothold marks the campaign as more than a routine adware outbreak.
Two separate phishing campaigns are hitting organisations with Formbook, a long-running information stealer that continues to adapt its delivery methods to slip past traditional Windows defences. The latest activity shows attackers pairing ordinary email lures with layered obfuscation, trusted system tools and DLL side-loading, giving a familiar malware family fresh room to operate inside corporate environments.Stealthy Formbook waves target Windows usersSecurity researchers tracking the campaigns say each attack chain uses a different infection route, but both are designed to end
A legitimate Intel storage utility has been repurposed in a highly targeted malware campaign that uses a little-known. NET mechanism to run hostile code inside a signed executable, giving attackers a quieter path into corporate networks and making detection far harder for many security products. The operation, identified as PhantomCLR, has been observed against financial institutions and other organisations across the Middle East and the wider EMEA region.At the centre of the intrusion is IAStorHelp. exe, a genuine Intel Rapid
Anthropic’s Model Context Protocol, a fast-growing standard used to connect AI models with external tools and data, has come under intense scrutiny after security researchers disclosed a critical weakness that they say can open the door to arbitrary remote code execution across a broad swathe of the AI software stack.The issue, published on April 15, centres on how MCP implementations handle STDIO-based server configurations and command execution paths. Researchers argue the flaw is not a narrow bug in a single
Anthropic’s Claude Opus has been thrust into a fresh security debate after researcher Mohan Pedhapati said he used the model to help build a working V8 exploit chain that achieved code execution against an outdated Chromium build bundled with Discord. Pedhapati, CTO of Hacktron and known online as s1r1us, said the exercise ran over about a week, consumed 2.3 billion tokens, cost $2,283 in API fees and ended with a proof-of-concept that launched Calculator on an Apple Silicon Mac.The
A leaked Google API key was used to drive more than €54,000 of Gemini compute charges in about 13 hours after attackers exploited an unrestricted Firebase browser key, according to a complaint posted on Google’s own AI developers forum, sharpening concerns over how older public-facing keys can become valid credentials for newer AI services. The affected user said an €80 budget alert and a cost anomaly alert both arrived only after spending had already climbed to about €28,000, with the
A sweeping international law-enforcement campaign has disrupted one of the cybercrime market’s most accessible attack models, with authorities saying Operation PowerOFF warned more than 75,000 suspected users of distributed denial-of-service-for-hire services, took down 53 domains, issued 25 search warrants and made four arrests during a coordinated action week on 13 April. The effort, backed by Europol and involving agencies from 21 countries, targeted both the operators and customers of so-called booter platforms that let users pay to overwhelm websites and
International law enforcement agencies have disrupted dozens of websites linked to paid cyberattack services, arrested four suspects and sent warning notices to more than 75,000 alleged users in one of the broadest crackdowns yet on the market for rented distributed denial-of-service attacks. The coordinated effort, announced on April 16, was carried out under Operation PowerOFF and involved authorities from 21 countries targeting so-called “booter” and “stresser” platforms that let customers pay to knock websites and online services offline.The latest
Hackers are probing older TP-Link home routers in an effort to turn them into Mirai-style botnet nodes, using a known command-injection flaw tracked as CVE-2023-33538. Security researchers say the activity targets discontinued router models and appears to be automated, with scanning and exploit attempts designed to fetch and run malware on exposed devices. The flaw itself is genuine and serious, even though some of the attack traffic observed so far contains coding errors that would stop the infection chain from
Search poisoning aimed at users looking for the open-source recovery utility TestDisk is being used to slip a trojanised installer on to Windows machines, abuse a Microsoft-signed binary for DLL sideloading and install ConnectWise ScreenConnect, giving attackers remote access under the cover of a legitimate administration tool. The campaign centres on a rogue site, testdisk. dev, that imitates the branding and download flow of the genuine TestDisk project while steering victims away from CGSecurity, the real home of the software.
Bluesky suffered a second day of disruption after what the company described as a coordinated distributed denial-of-service attack, leaving many users unable to reliably load feeds, notifications, threads and search results while engineers worked to stabilise the social platform. Bluesky said the trouble began late on April 15 and intensified through April 16, adding that it had found no evidence of unauthorised access to private user data.The outage quickly became a test of Bluesky’s pitch as a more open
OpenClaw’s rapid rise from an open-source personal assistant to a flashpoint in boardroom and regulatory discussions has turned the software into one of the clearest illustrations yet of the cybersecurity dangers surrounding agentic AI. Security specialists, regulators and large technology firms are converging on the same point: the problem is no longer limited to what an AI model can say, but what an AI agent can do once it is given tools, permissions and live access to workplace systems.The
Cookeville Regional Medical Center has begun notifying 337,917 people that personal and medical information was exposed after a ransomware attack discovered on 14 July 2025, a breach that has taken about nine months to fully assess and disclose at scale. The Tennessee hospital said an unauthorised third party accessed or acquired files between 11 July and 14 July 2025, with the compromised data varying by individual and including names, addresses, dates of birth, Social Security numbers, driving licence numbers, financial