Threats Affecting United Arab Emirates
View all threats affecting or targeting United Arab Emirates. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting United Arab Emirates
Click on any threat for detailed analysis and mitigation recommendations
The Iranian-linked cyber-espionage group Tortoiseshell has expanded its malware toolkit with a new reverse SSH tunneling utility disguised as wtsapi32.dll and a C++ backdoor similar to TWOSTROKE malware. The SSH tunnel uses the Windows OpenSSH client to connect to command-and-control servers. The backdoor supports executing files, shell commands, in-memory DLL execution, and file manipulation. Infrastructure analysis shows domains linked to multiple countries including the UAE, Saudi Arabia, UK, Belgium, Canada, Australia, Japan, and the United States, indicating broader targeting beyond the Middle East and US defense and military sectors. The group has been active since 2018 and maintains persistent infrastructure despite domain suspensions. No known exploits in the wild or patches are reported. Join the discussion | AlienVault OTX General | 08/26/2026, 17:18:24 UTC Added: 08/26/2026, 18:37:18 UTC |
This report highlights a cyber espionage campaign attributed to the Iranian APT group Charming Kitten, targeting eight countries and eight critical sectors simultaneously. The campaign, dubbed Operation Olalampo, affects Egypt, Saudi Arabia, UAE, Turkey, Hungary, Turkmenistan, Israel, and South America, focusing on government, healthcare, financial services, energy, education, telecommunications, defense, and industrial sectors. The information is sourced from a Reddit post linking to a GitHub repository simulating adversary tactics. No specific vulnerabilities or exploits are detailed, and no affected software versions are identified. CriticalCampaign Join the discussion | Reddit BlueTeam | 08/03/2026, 07:07:43 UTC Added: 08/03/2026, 19:33:10 UTC |
Oracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates. Key Takeaways The third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release. 261 issues (18% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at 410, accounting for 28.3% of all patches Background On July 21, Oracle released its Critical Patch Update (CPU) for July 2026 , the third quarterly update of the year. This CPU contains fixes for 1235 unique CVEs in 1449 security updates across 32 Oracle product families. Out of the 1449 security updates published this quarter, 18% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 52.7%, followed by medium severity patches at 24.7%. This quarter's update includes 261 critical patches across 228 CVEs. Severity Issues Patched CVEs Critical 261 228 High 763 613 Medium 358 332 Low 67 62 Total 1449 1235 Analysis This quarter, the Oracle E-Business Suite product family contained the highest number of patches at 410, accounting for 28.3% of the total patches, followed by Oracle Fusion Middleware at 355 patches, which accounted for 24.5% of the total patches. A full breakdown of the patches for this quarter can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication. Oracle Product Family Number of Patches Remote Exploit without Auth Oracle E-Business Suite 410 45 Oracle Fusion Middleware 355 219 Oracle Communications 168 122 Oracle PeopleSoft 84 45 Oracle MySQL 54 9 Oracle Siebel CRM 45 32 Oracle Commerce 39 26 Oracle Supply Chain 39 16 Oracle Financial Services Applications 31 26 Oracle GoldenGate 27 9 Oracle Enterprise Manager 27 13 Oracle Retail Applications 22 20 Oracle JD Edwards 20 4 Oracle Java SE 19 17 Oracle Virtualization 16 0 Oracle Database Server 15 6 Oracle TimesTen In-Memory Database 14 4 Oracle Utilities Applications 14 10 Oracle Construction and Engineering 7 7 Oracle Analytics 7 5 Oracle Systems 6 0 Oracle SQL Developer 5 5 Oracle Autonomous Health Framework 4 3 Oracle Application Testing Suite 4 4 Oracle Food and Beverage Applications 4 4 Oracle HealthCare Applications 4 4 Oracle APEX 3 2 Oracle Hospitality Applications 2 2 Oracle Essbase 1 1 Oracle Global Lifecycle Management 1 1 Oracle NoSQL Database 1 1 Oracle Spatial Studio 1 1 Solution Customers are advised to apply all relevant patches in this quarter's CPU. Please refer to the July 2026 advisory for full details. Identifying affected systems A list of Tenable plugins to identify these vulnerabilities will appear here as they're released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released. Get more information Oracle Critical Patch Update Advisory - July 2026 Oracle July 2026 Critical Patch Update Risk Matrices Oracle Advisory to CVE Map Join Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats. Learn more about Tenable One , the Exposure Management Platform for the modern attack surface. Join the discussion | Tenable Research | 07/21/2026, 21:07:46 UTC Added: 07/22/2026, 01:54:57 UTC |
Beginning in August 2025, a sophisticated intrusion was discovered where attackers used log poisoning techniques to deploy a web shell on vulnerable phpMyAdmin panels. The threat actors exploited misconfigured web applications to plant China Chopper web shells, controlled via AntSword, before deploying Nezha, an open-source monitoring tool, to facilitate remote command execution. This led to the deployment of Ghost RAT on compromised systems. Analysis revealed over 100 compromised machines, predominantly located in Taiwan, Japan, South Korea, and Hong Kong. The attackers demonstrated technical proficiency through multi-stage operations, utilizing AWS and VPS infrastructure, with indicators pointing to China-nexus threat actors. The campaign highlights increasing abuse of legitimate publicly available tools to achieve malicious objectives while maintaining plausible deniability. Join the discussion | AlienVault OTX General | 07/03/2026, 21:26:02 UTC Added: 07/06/2026, 09:21:27 UTC |
In early 2026, a threat actor targeted SD-WAN infrastructure at a service provider, exploiting a zero-day vulnerability in Cisco Catalyst SD-WAN to escalate privileges. The attacker initially gained access through unauthorized peering connections and manipulated default account passwords. They then exploited CVE-2026-20245, a privilege escalation flaw in the file upload feature, by uploading a malicious CSV file to achieve root-level access. The vulnerability allowed the creation of a privileged user account through manipulation of system password files. Throughout the intrusion, the threat actor employed extensive anti-forensic techniques, systematically deleting malicious files, restoring modified system configurations, and executing validation scripts to ensure removal of indicators. This campaign demonstrates the living off the edge paradigm, where adversaries compromise network appliances to bypass traditional security perimeters and maintain persistent access. CriticalVulnerability Join the discussion | CVE Database V5 | 06/25/2026, 15:21:09 UTC Added: 02/25/2026, 21:47:05 UTC |
India has banned Telegram until June 22 after the app was used to circulate leaked exam papers. CEO Pavel Durov accuses telecom Reliance of BGP hijacking that disrupted the app as far away as the UAE. Here's what happened, and how to get around the block with an MTProto proxy. [...] Join the discussion | Bleeping Computer | 06/17/2026, 13:12:45 UTC Added: 06/17/2026, 13:17:13 UTC |
The Iranian IRGC-affiliated threat actor Nimbus Manticore launched sophisticated cyber operations during Operation Epic Fury, the US military campaign against Iran beginning February 28, 2026. The campaigns targeted organizations in aviation and software sectors across the United States, Europe, and Middle East using career-themed phishing lures. For the first time, the actor employed SEO poisoning techniques and introduced MiniFast, a previously undocumented backdoor showing signs of AI-assisted development. The operations leveraged AppDomain hijacking and abused legitimate Zoom installer execution flows for malware deployment. The actor demonstrated rapid adaptation capabilities during wartime conditions, maintaining high operational availability while expanding targeting to US-based aviation companies. Multiple campaign waves were observed from February through April 2026, with persistent infrastructure and evolving techniques. Join the discussion | AlienVault OTX General | 05/25/2026, 10:09:15 UTC Added: 05/25/2026, 10:24:59 UTC |
Unit 42 researchers identified six new remote access Trojan variants deployed by Iran-nexus APT group Screening Serpens between February and April 2026, coinciding with a regional conflict starting February 28, 2026. The group targeted entities in the U.S., Israel, UAE, and other Middle Eastern locations, primarily focusing on technology sector professionals through highly tailored social engineering using personalized recruitment lures. Two new malware families, MiniUpdate and MiniJunk V2, were discovered featuring advanced techniques including AppDomainManager hijacking that manipulates .NET application initialization to disable security mechanisms. The campaigns demonstrated increased technical capabilities and operational resilience, with each variant using dedicated C2 infrastructure hosted on Azure. The attacks leveraged DLL sideloading, scheduled tasks for persistence, and sophisticated evasion techniques to maintain long-term access for espionage purposes. MediumMalware Join the discussion | AlienVault OTX General | 05/22/2026, 17:33:20 UTC Added: 05/25/2026, 09:54:59 UTC |
The 13-country effort, named Operation Ramz, targeted cyber threats in the Middle East and North Africa region. The post 201 Arrested in Crackdown on Cybercrime in Middle East, North Africa appeared first on SecurityWeek . Join the discussion | SecurityWeek | 05/19/2026, 10:32:14 UTC Added: 05/19/2026, 10:36:37 UTC |
In March 2026, a China-nexus threat actor launched a sophisticated campaign targeting countries in the Arabian Gulf region, exploiting renewed Middle East conflict themes within 24 hours of escalation. The attack utilized Arabic-language lures depicting missile strikes and employed a multi-stage infection chain beginning with weaponized ZIP archives containing malicious LNK and CHM files. The campaign deployed a heavily obfuscated PlugX backdoor variant through DLL sideloading, with components using control flow flattening and mixed boolean arithmetic techniques. The backdoor supports HTTPS command-and-control communications, DNS-over-HTTPS resolution, and multiple plugins for system manipulation. Based on tools, techniques, and procedures including specific RC4 decryption keys and rapid geopolitical weaponization, the activity is attributed with medium confidence to Mustang Panda. Join the discussion | AlienVault OTX General | 04/13/2026, 14:40:01 UTC Added: 04/13/2026, 14:46:50 UTC |
Showing 1 to 10 of 456 results