Category: Cybersecurity

Latest Arabian cybersecurity news covering global cyber threats, ransomware attacks, data breaches, digital espionage, and technology security developments affecting governments, companies and individuals.

ADVERTISEMENT
ADVERTISEMENT

 Ukrainian municipal authorities and healthcare institutions have come under a coordinated wave of cyberattacks that security officials say was designed to steal sensitive information from web browsers and WhatsApp accounts, widening concern over espionage operations aimed at essential public services during wartime.The campaign, attributed by Ukraine’s Computer Emergency Response Team to threat cluster UAC-0247, struck local government bodies and municipal medical facilities, including clinical and emergency hospitals, over March and April. Investigators say the operation relied on phishing emails crafted

Cyber criminals are pushing a Windows information stealer called NWHStealer through bogus software downloads that masquerade as Proton VPN installers, gaming mods and hardware utilities, in a campaign that security researchers say relies less on classic phishing and more on users searching for tools they believe are legitimate. Malwarebytes said on April 15 that it had identified multiple active distribution chains tied to the stealer, with malicious files turning up on fake websites, code-hosting platforms and file-sharing services.The campaign

Cyber attackers are abusing the low-code automation platform n8n to push malware and track targets through phishing emails, in a campaign that security researchers say gathered pace between October 2025 and March 2026 and reflects a broader shift in how legitimate cloud tools are being repurposed for intrusion activity. Cisco Talos said it observed a sharp increase in emails containing n8n webhook links, with March 2026 volumes about 686 per cent higher than in January 2025.The activity matters because

Attackers are exploiting trust in Adobe’s brand to deliver covert remote access, using a fake Acrobat Reader download page to install ConnectWise ScreenConnect through a fileless, memory-heavy attack chain that is designed to leave few traces on disk and make forensic analysis harder. Security researchers who uncovered the campaign said the operation began with a phishing site made to resemble Adobe’s official software page, where victims were pushed into downloading what looked like a legitimate installer but was in fact

Google’s Discover feed has become the latest battleground in the cybercrime economy after researchers uncovered a large-scale operation that used AI-written articles, fake news hooks and misleading browser prompts to push scam alerts to users’ phones and computers. The campaign, dubbed Pushpaganda, relied on more than 100 bogus domains designed to look like ordinary content sites, then turned visitors into targets for persistent scareware, ad fraud and financial scams.The scheme worked by exploiting a weak point in the way many

Splunk has disclosed a high-severity security flaw that can allow remote code execution in affected Splunk Enterprise and Splunk Cloud Platform deployments, raising concern for organisations that rely on the software to collect, search and analyse machine data for cyber defence, compliance and operations. The issue, tracked as CVE-2026-20204, was published on April 15 and carries a CVSS score of 7.1. Splunk said the weakness affects Splunk Web in several supported product branches and urged customers running on-premises software to

Attackers are exploiting a critical flaw in nginx-ui, an open-source web interface used to manage Nginx servers, exposing organisations to unauthorised server control through a weakness in the product’s Model Context Protocol integration. The bug, tracked as CVE-2026-33032, carries a CVSS severity score of 9.8 and allows an unauthenticated attacker on the network to invoke privileged functions that can rewrite configuration files, reload services and alter how traffic is handled.The vulnerability sits in the /mcp_message endpoint, which was left

 A digitally signed software operation tied to Dragon Boss Solutions LLC has been linked to the disabling of antivirus protections on more than 23,000 endpoints worldwide, raising concerns that what had been treated as aggressive adware was operating much closer to a supply-chain style threat. Security researchers said infected machines were found checking in from 124 countries, with affected systems present in education, government, utilities, healthcare and other high-value networks.The activity came to wider attention after Huntress said it investigated

Europe’s cybersecurity agency has moved to strengthen its influence over the global system used to identify and catalogue software flaws, with ENISA no longer merely seeking a bigger role in the Common Vulnerabilities and Exposures programme but already holding Root status in a shift that gives the EU a stronger hand in how vulnerabilities are coordinated across borders. The development matters because the CVE system remains a core reference point for governments, security vendors, researchers and companies managing cyber risk,

More than 30 WordPress plugins tied to the developer Essential Plugin were taken offline after a hidden backdoor was found in code distributed to live websites, exposing site owners to unauthorised access, malware installation and search-spam abuse. The campaign, traced by security researchers to code inserted in August 2025 and activated in April 2026, is being treated as a serious software supply-chain breach rather than an ordinary plugin flaw.At the centre of the case is a portfolio of long-standing

Google has issued an emergency-style security update for Chrome after disclosing 31 vulnerabilities in the desktop browser, including five rated critical, in a release that underlines how quickly memory-safety flaws in widely used software can become a serious risk for consumers, businesses and public institutions. The stable desktop channel moved on April 15 to version 147.0.7727.101/102 for Windows and Mac, and 147.0.7727.101 for Linux, with the rollout set to continue over the coming days and weeks.Several of the most

A sharp jump in brute-force attacks against SonicWall and Fortinet devices has put security teams on alert, after Barracuda said such activity made up more than half of the confirmed incidents its SOC tracked during February and March, with about 88% of the attacking IP addresses geolocated to the Middle East. The company said most attempts failed because they were blocked or aimed at invalid usernames, but the scale of the campaign points to sustained probing of internet-facing network defences.

More than 100 Chrome extensions presented as harmless tools for games, social media sidebars and translation have been tied to a coordinated data-harvesting operation that security researchers say exposed user identities, browser sessions and browsing activity through a shared command-and-control network. The campaign, uncovered by Socket’s Threat Research Team and independently checked in part by BleepingComputer, involved 108 extensions listed under five publisher identities and accounted for about 20,000 installs on the Chrome Web Store when the findings were published

What looked like a nuisance adware issue inside managed IT environments has emerged as a broader cyber-security warning, after Huntress said software signed by Dragon Boss Solutions LLC exposed more than 25,000 endpoints to a supply-chain style compromise through an insecure update mechanism that could have been hijacked for the price of a cheap domain registration. Huntress published its findings on April 14, saying the software was able to fetch and run payloads with SYSTEM-level privileges while also disabling security

MSBuild, a legitimate Microsoft build tool embedded in many Windows and developer environments, is drawing renewed scrutiny after fresh threat research showed how attackers are using it to run malicious code in memory, evade signature-based defences and blend into normal system activity. Security researchers and defenders say the technique is not new, but its continued effectiveness underlines how cyber intrusions are shifting away from obvious malware files and towards the abuse of trusted software already present on a machine.The

Federal investigators in the United States, working with Indonesian police, have dismantled the W3LL phishing network, a cybercrime operation that authorities say enabled the theft of thousands of account credentials and supported more than $20 million in attempted fraud. The action, led by the FBI’s Atlanta field office, included the seizure of infrastructure linked to the service and the detention in Indonesia of an alleged developer identified by authorities as G. L.Officials described W3LL as more than a conventional

A newly disclosed security flaw in Axios, one of the most widely used HTTP client libraries in the JavaScript ecosystem, has raised concern across software and cloud security teams after official advisories warned it could be chained into remote code execution or a broader compromise of cloud infrastructure. The issue, tracked as CVE-2026-40175, affects Axios versions earlier than 1.15.0 and was published through GitHub’s advisory system on April 9, then added to the US National Vulnerability Database on April 10.

 GitHub and Jira notification emails are being hijacked by threat actors who have found a way to turn trusted software alerts into convincing phishing lures, using the platforms’ own mail systems to slip past many of the checks that companies rely on to stop malicious messages. Security researchers say the tactic marks a notable shift in email abuse because the messages are not crudely spoofed copies but genuine notifications generated by legitimate SaaS infrastructure.Cisco Talos disclosed on 7 April that

Mirax, an emerging Android banking trojan being marketed as a malware-as-a-service operation, is drawing attention from mobile security researchers after reports that it can do more than steal banking credentials. Analysts say the malware can remotely control infected phones and repurpose them as residential proxy nodes, giving cybercriminals a way to hide malicious traffic behind ordinary consumer devices while pursuing financial fraud across Europe.The threat stands out because it appears to combine several criminal tactics in one package. Researchers

Basic-Fit has disclosed a cyber breach affecting about one million members across several European markets, with roughly 200,000 of those accounts in the Netherlands, exposing a wide range of personal and financial details and sharpening concerns over how consumer-facing digital platforms protect routine lifestyle data. The company said the unauthorised access was detected by internal monitoring systems and halted within minutes, but not before information had been downloaded.Data involved in the breach included bank account details, names, dates of

Iran-linked cyber operatives using the CyberAv3ngers banner are again in the spotlight after U. S. authorities warned on April 7 that Iranian-affiliated hackers have stepped up efforts to compromise programmable logic controllers and supervisory control systems used in water, energy and government facilities, with some intrusions already causing operational disruption and financial loss. The alert marks a sharper phase in a campaign that security officials say has moved beyond propaganda-driven defacements towards attempts that could interfere with the physical functioning

Google has moved to harden Chrome against one of cybercrime’s most effective tactics by making Device Bound Session Credentials publicly available for Windows users in Chrome 146, a step designed to stop attackers reusing stolen session cookies to enter accounts without passwords or multi-factor authentication. The change binds a signed-in web session to the user’s device, meaning a cookie lifted by malware should quickly become unusable on another machine. Google said macOS support is due in a coming release, while

Adobe has issued an emergency update for Acrobat and Reader after confirming that a zero-day vulnerability tracked as CVE-2026-34621 is being exploited in the wild, putting Windows and macOS users on notice to install the patch quickly. The company assigned the update a Priority 1 rating, its most urgent category for product security bulletins, and said successful exploitation could lead to arbitrary code execution. The flaw affects Acrobat DC, Acrobat Reader DC and Acrobat 2024 builds before the newly released

A critical security flaw in the User Registration & Membership plugin for WordPress has exposed thousands of websites to the risk of full administrative takeover, after researchers disclosed that versions up to and including 5.1.2 could allow attackers to gain elevated privileges without valid credentials. The issue, tracked as CVE-2026-1492, stems from improper privilege management during membership registration, creating a path for unauthorised users to register with powerful roles that should never be assignable from the public-facing side of a

Apache Tomcat users are being urged to move quickly after the Apache Software Foundation disclosed a set of security flaws that could let attackers undermine encrypted traffic protections, slip past certificate checks in some scenarios and exploit a defect introduced by an earlier fix. The most urgent concern centres on Tomcat’s EncryptInterceptor, where one vulnerability was followed by a second flaw in the remedy itself, creating a patch-on-patch problem for organisations that believed they had already secured affected systems.At

Pavel Durov, the Telegram founder, has escalated a public attack on WhatsApp, calling its claim of “end-to-end encryption by default” a “giant consumer fraud” and arguing that most private messages still become exposed through cloud backups. The charge, amplified on X amid a fresh US class action dispute over WhatsApp’s privacy promises, has reopened a wider argument about what encrypted messaging apps actually protect, what they leave exposed, and how much ordinary users understand about the difference.WhatsApp’s position is that

Hackers posing as trusted messaging and communications services have mounted a sustained surveillance campaign across the Middle East and North Africa, using fake app pages, phishing domains and a custom Android spyware known as ProSpy to target journalists, activists and political figures, according to a joint body of research published this week by Lookout, Access Now and SMEX. The operation, active since at least 2022 and documented through attacks in 2023, 2024 and 2025, is assessed with moderate confidence to

GitHub Copilot Chat has been shown to carry a serious prompt-injection weakness that allowed a researcher to demonstrate how secrets, private source code and other sensitive repository data could be siphoned out of trusted development workflows without planting malware in the victim’s environment. The issue, dubbed CamoLeak, was disclosed by Legit Security researcher Omer Mayraz after he said he found it in June 2025, reported it through HackerOne and saw GitHub deploy a fix by 14 August 2025. The attack

More than 5,000 Rockwell Automation and Allen-Bradley programmable logic controllers are exposed to the public internet, sharpening concern across United States critical infrastructure as federal agencies warn that Iran-affiliated cyber actors are actively targeting such devices. Security researchers at Censys said they identified 5,219 internet-exposed hosts globally that responded as Rockwell or Allen-Bradley systems, with nearly three quarters of them located in the United States. The warning lands amid an active campaign against operational technology used in water, energy and

Millions of Android users, including a large share of cryptocurrency wallet customers, were exposed to a software supply-chain weakness after a flaw in the widely used EngageSDK library was found to allow hostile apps on the same device to break through normal app boundaries and reach sensitive data. The issue centred on an “intent redirection” vulnerability inside the third-party Android kit, which is used for push notifications and in-app messaging, and whose reach extended far beyond any single wallet provider.

Commercial artificial intelligence tools were used as operational components in a cyber campaign that hit nine Mexican government organisations, according to a full technical report published by Gambit Security, which said the intrusion ran from late December 2025 to mid-February 2026 and exposed hundreds of millions of citizen records. The report says Anthropic’s Claude Code generated about three-quarters of the remote command activity, while OpenAI’s GPT-4.1 was used to analyse harvested data and turn it into structured intelligence.The findings deepen

Three ransomware operations — Qilin, Akira and DragonForce — were behind 40% of the 672 attacks logged worldwide in March, according to Check Point Research, highlighting how a criminal market that still looks fragmented on the surface is being pulled by a smaller group of high-output players. Check Point said Qilin accounted for 20% of published attacks, Akira 12% and DragonForce 8%, while 47 separate groups were still active during the month.The figures point to a concentrated threat environment rather

Google has begun rolling out a new Chrome security feature designed to blunt one of the most effective tools used by cybercriminals to hijack online accounts: stolen session cookies. The protection, called Device Bound Session Credentials, is entering public availability for Windows users in Chrome 146, with expansion to macOS slated for a later release. Google says the system is intended to make stolen authentication cookies far less useful by tying them cryptographically to the user’s device.The move targets

A Microsoft-tracked cybercrime group is using adversary-in-the-middle techniques to hijack Microsoft 365 sessions, bypass multifactor authentication and reroute employee pay into attacker-controlled bank accounts, in what researchers describe as a geographically focused campaign against users in Canada. Microsoft said the actor, tracked as Storm-2755, combined search-result poisoning, fake sign-in pages and session replay to move from account takeover to payroll fraud, causing direct financial loss for at least one victim.What sets this operation apart is the way it turns

Social Media Auto Publish Powered By : XYZScripts.com