Threats Affecting Lebanon
View all threats affecting or targeting Lebanon. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Lebanon
Click on any threat for detailed analysis and mitigation recommendations
A thriving gray market has emerged offering discounted access to AI models through fraudulent account registrations that exploit free trials and startup credits. Services like Poison Claude and Ecomagent offer 70-90% discounts by creating fake accounts on platforms such as AWS Bedrock and Google Cloud, then reselling access through custom API endpoints. The demand is driven by cost considerations, access restrictions in regions like China, and desire for anonymity. Fraudulent registration campaigns targeting AI video services show over 105,000 brute-force signup attempts using bots, VPNs, and disposable email domains. The operations leverage residential proxies to evade detection and accept cryptocurrency payments. These services operate through sophisticated AI gateways and are advertised on underground forums and messaging platforms, particularly in Chinese-language markets, representing a significant platform abuse challenge for AI service providers. MediumCampaign Join the discussion | AlienVault OTX General | 08/05/2026, 18:54:29 UTC Added: 08/06/2026, 08:56:14 UTC |
The 13-country effort, named Operation Ramz, targeted cyber threats in the Middle East and North Africa region. The post 201 Arrested in Crackdown on Cybercrime in Middle East, North Africa appeared first on SecurityWeek . Join the discussion | SecurityWeek | 05/19/2026, 10:32:14 UTC Added: 05/19/2026, 10:36:37 UTC |
The ongoing conflict involving Iran has led to increased cyber espionage activities targeting Middle Eastern governments. Multiple state-sponsored threat actors, including those from China, Belarus, Pakistan, and Hamas, have been observed conducting campaigns using the conflict as a lure. These actors are employing various tactics such as credential phishing, malware delivery, and compromised accounts to target government and diplomatic organizations. The campaigns often use war-themed content to engage targets and gather intelligence on the conflict's trajectory and geopolitical implications. Iranian threat actors continue their traditional espionage efforts alongside disruptive campaigns in support of war efforts. This heightened activity reflects both opportunistic use of topical lures and shifts in intelligence collection priorities for various state-aligned groups. Join the discussion | AlienVault OTX General | 03/11/2026, 15:24:24 UTC Added: 03/16/2026, 09:50:06 UTC |
The ongoing Middle East crisis has given rise to opportunistic online fraudulent activities. Two main strands have been observed: confirmed government-impersonation fraud and suspicious evacuation-themed websites. Fraudsters are exploiting the confusion and urgency surrounding the crisis to launch phishing campaigns and create deceptive websites. A notable example includes an email impersonating UAE authorities, urging recipients to complete a mandatory emergency registration form. Additionally, several newly registered websites offering evacuation services from Dubai and the Gulf region have emerged, displaying characteristics commonly associated with scams. These sites use crisis-related domain names, employ urgent messaging, lack verifiable operator details, and often request unconventional payment methods. The situation highlights the need for increased vigilance and proactive monitoring of emerging digital threats during geopolitical crises. Join the discussion | AlienVault OTX General | 03/11/2026, 11:10:32 UTC Added: 03/17/2026, 10:57:44 UTC |
The ongoing conflict in the Middle East has triggered a surge in cybercriminal activity. Over 8,000 newly registered domains with conflict-related keywords have been identified, many of which may be weaponized in future campaigns. Multiple cases of malicious activity have been observed, including targeted attacks using conflict-themed lures, deployment of the LOTUSLITE backdoor, fake news blogs leading to StealC malware, phishing sites impersonating government portals, donation scams, fraudulent storefronts, and meme-coin pump-and-dump schemes. Threat actors are leveraging various techniques such as DLL sideloading, shellcode execution, and social engineering to compromise victims. The campaigns demonstrate the opportunistic nature of cybercriminals in exploiting geopolitical events for malicious purposes. Join the discussion | AlienVault OTX General | 03/06/2026, 19:39:15 UTC Added: 03/09/2026, 10:36:50 UTC |
Key Findings Introduction As highlighted in the Cyber Security Report 2026, cyber operations have increasingly become an additional tool in interstate conflicts, used both to support military operations and to enable ongoing battle damage assessment (BDA). During the 12-day conflict between Israel and Iran in June 2025, the compromise of cameras was likely used to support […] The post Interplay between Iranian Targeting of IP Cameras and Physical Warfare in the Middle East appeared first on Check Point Research . Join the discussion | Check Point Research | 03/04/2026, 03:16:44 UTC Added: 03/05/2026, 00:12:36 UTC |
MuddyWater APT has launched Operation Olalampo, targeting organizations in the MENA region. The campaign involves new malware variants, including a Rust backdoor called CHAR, downloaders GhostFetch and HTTP_VIP, and an advanced backdoor GhostBackDoor. Notably, the group is using Telegram bots for command-and-control, revealing insights into their post-exploitation tactics. The operation, first observed on January 26, 2026, shows tactical and technical overlaps with previous MuddyWater activities. Key discoveries include potential AI-assisted malware development and infrastructure reuse dating back to October 2025. The campaign aligns with ongoing geopolitical tensions and provides valuable information on the threat actor's evolving techniques. Join the discussion | AlienVault OTX General | 02/23/2026, 10:13:38 UTC Added: 02/23/2026, 10:16:19 UTC |
This report analyzes the recent activities of the MuddyWater APT group, which primarily targets organizations in the Middle East. The group employs sophisticated spear-phishing techniques, often impersonating legitimate entities and using malicious documents to gain initial access. Their attacks focus on long-term infiltration and intelligence gathering rather than immediate disruption. The report details several attack cases from 2019 to 2026, highlighting the group's evolving tactics, including the abuse of legitimate remote management tools and the use of Rust-based malware. The analysis emphasizes the importance of endpoint detection and response (EDR) solutions in identifying and mitigating these threats, as traditional perimeter-based security measures prove insufficient against such advanced persistent threats. Join the discussion | AlienVault OTX General | 02/23/2026, 09:34:57 UTC Added: 02/23/2026, 10:01:19 UTC |
0 A vulnerability in the password reset workflow of the Touch Lebanon Mobile App 2.20.2 allows an attacker to bypass the OTP reset password mechanism. By manipulating the reset process, an unauthorized user may be able to reset the password and gain access to the account without needing to provide a legitimate authentication factor, such as an OTP. This compromises account security and allows for potential unauthorized access to user data. Join the discussion | CVE Database V5 | 08/20/2025, 00:00:00 UTC Added: 08/20/2025, 13:32:47 UTC |
Showing 1 to 9 of 9 results