◇ SIGN IN

Pipeline reports

17 cases · reverse-chron

Weekly cyber-defense-intel case reports on activity affecting the MENA region — each synthesized from cited sourcing, with an inferred production tier and a deterministic field summary (not an analyst judgment). Switch to Executive for a plain-language view without the technical detail.

inferred ⓘ
REPORT2026-07-28-talos-ir-q2-2026tactical · inferred

Talos IR Q2 2026 — Multi-Threat Quarterly Roundup

Why it mattersUnrated MENA relevance, 1 tracked CVE.
What's next17 follow-on investigations opened from this report.

Talos IR Q2 2026 covers major incident response themes across April–June 2026: adversary-in-the-middle (AitM) M365 phishing-as-a-service (ARToken PhaaS), Warlock and BlackLock ransomware operations exploiting…

Window: 2026-07-24 → 2026-07-31Source: Cisco Talos Incident Response Quarterly Report — Q2 2026
CVE-2026-50522
Useful?
2026-07-28
REPORT2026-07-28-mirage-kitten-nightledgerstrategic · inferred

Mirage Kitten (UNC1549) — NightLedger Implant MENA Targeting

Why it mattersUnrated MENA relevance.
What's next9 follow-on investigations opened from this report.

Mirage Kitten (UNC1549), an Iranian state-sponsored actor, conducted targeted intrusions against aerospace, defense, and technology organizations in Israel, UAE, and wider MENA using the NightLedger implant. The…

Window: 2026-07-24 → 2026-07-31Source: Talos Intelligence — UNC1549 NightLedger campaign analysis
Useful?
2026-07-28
REPORT2026-07-27-checkpoint-weeklytactical · inferred

Check Point Weekly Threat Report — 2026-07-27

Why it mattersUnrated MENA relevance, 2 tracked CVEs.
What's next13 follow-on investigations opened from this report.

Check Point Research's weekly report covers three major themes with MENA-region relevance: (1) CVE-2026-16232 — an unauthenticated token generation vulnerability in Check Point SmartConsole allowing arbitrary…

Window: 2026-07-24 → 2026-07-31Source: Check Point Research Weekly Threat Report — 2026-07-27
CVE-2026-16232CVE-2026-50522
Useful?
2026-07-27
REPORT2026-07-27-cyberav3ngers-mn-waterstrategic · inferred

CyberAv3ngers — ICS/OT Attacks on Minnesota Water Utilities

Why it mattersUnrated MENA relevance.
What's next5 follow-on investigations opened from this report.

CyberAv3ngers, an Iranian IRGC-affiliated threat actor previously responsible for the 2023 Municipal Water Authority of Aliquippa attack, conducted renewed operations against Minnesota water and wastewater utilities in…

Window: 2026-07-24 → 2026-07-31Source: CISA advisory and reporting — CyberAv3ngers OT targeting of US water utilities (Minnesota incidents)
Useful?
2026-07-27
REPORT2026-07-27-teleshim-me-govtsstrategic · inferred

TeleShim — ASUS/GoPro ISO Malware Targeting MENA Governments

Why it mattersUnrated MENA relevance.
What's next5 follow-on investigations opened from this report.

TeleShim is a malware campaign targeting MENA government and defense organizations, delivering implants via ISO files disguised as ASUS software updates or GoPro alert service installers. The ISO contains legitimate…

Window: 2026-07-24 → 2026-07-31Source: Threat intelligence report — TeleShim campaign targeting Middle East government entities
Useful?
2026-07-27
REPORT2026-07-23-mstic-email-q2strategic · inferred

MSTIC Q2 2026 Email Threat Landscape — Teams Vishing Surge and BEC Evolution

Why it mattersUnrated MENA relevance.
What's next9 follow-on investigations opened from this report.

Microsoft MSTIC documented Q2 2026 email threat trends including a 10x surge in Microsoft Teams vishing following the Tycoon2FA infrastructure disruption, automated two-stage BEC using Amazon SES tracking pixels, nested…

Window: 2026-07-17 → 2026-07-24Source: Microsoft Security Blog / MSTIC — "Email threat landscape: Q2 2026 trends and insights"
Useful?
2026-07-23
REPORT2026-07-22-cyberav3ngers-plc-updatetactical · inferred

CyberAv3ngers PLC/ICS Exploitation — CISA Advisory AA26-097A Update

Why it mattersUnrated MENA relevance, 1 tracked CVE.
What's next4 follow-on investigations opened from this report.

CISA updated Advisory AA26-097A to document the CyberAv3ngers group (IRGC Cyber Electronic Command, G1027) actively exploiting internet-exposed programmable logic controllers across US critical infrastructure (water,…

Window: 2026-07-17 → 2026-07-24Source: CISA Advisory AA26-097A — Co-authored by CISA, FBI, NSA, EPA, DOE, USCYBERCOM/CNMF, Treasury, ONCD
CVE-2021-22681
Useful?
2026-07-22
REPORT2026-07-20-checkpoint-weeklytactical · inferred

Check Point Research Weekly — July 20, 2026 Threat Intelligence Compilation

Why it mattersUnrated MENA relevance, 5 tracked CVEs.
What's next9 follow-on investigations opened from this report.

Check Point Research's weekly compilation covers: ShinyHunters (Storm-3138) Salesforce OAuth exfiltration campaign; July 2026 Patch Tuesday CVEs including SharePoint (CVE-2026-56164, CVE-2026-58644) and AD FS…

Window: 2026-07-17 → 2026-07-24Source: Check Point Research — "20th July Threat Intelligence Report" (weekly compilation)
CVE-2026-56164CVE-2026-58644CVE-2026-56155CVE-2026-63030CVE-2026-64600
Useful?
2026-07-20
REPORT2026-07-18-contagious-interview-svgstrategic · inferred

Contagious Interview SVG Steganography — REF9403 (DPRK) Developer Targeting

Why it mattersUnrated MENA relevance.
What's next11 follow-on investigations opened from this report.

Elastic Security Labs documented a new DPRK Contagious Interview campaign delivering malware via SVG files with steganographically embedded ZIP payloads. Targets are developers and tech workers recruited via fake job…

Window: 2026-07-17 → 2026-07-24Source: Elastic Security Labs — "Contagious Interview malware in SVG images: DPRK campaign (REF9403)"
Useful?
2026-07-18
REPORT2026-07-16-acr-stealerstrategic · inferred

ACR Stealer — ClickFix Two-Chain InfoStealer Campaign

Why it mattersUnrated MENA relevance.
What's next10 follow-on investigations opened from this report.
Useful?
2026-07-16
REPORT2026-07-16-uat11795-starland-ratstrategic · inferred

UAT-11795 / Starland RAT — Russian-Speaking ClickFix Crypto-Targeting Campaign

Why it mattersUnrated MENA relevance.
What's next4 follow-on investigations opened from this report.
Useful?
2026-07-16
REPORT2026-07-16-iran-ai-playbookstrategic · inferred

Iran AI Playbook — Iranian State Actors Leverage AI for Enhanced Asymmetric Operations

Why it mattersUnrated MENA relevance.
What's next8 follow-on investigations opened from this report.
Useful?
2026-07-16
REPORT2026-07-14-asyncapi-supply-chainstrategic · inferred

AsyncAPI npm Supply Chain Compromise — Miasma Backdoor via GitHub Actions pwn-request

Why it mattersUnrated MENA relevance.
What's next6 follow-on investigations opened from this report.
Useful?
2026-07-14
REPORT2026-07-14-sonicwall-sma1000strategic · inferred

SonicWall SMA1000 Zero-Day — Chained SSRF + Path Traversal = Unauthenticated Root RCE

Why it mattersUnrated MENA relevance.
What's next6 follow-on investigations opened from this report.
Useful?
2026-07-14
REPORT2026-07-10-cavern-manticorestrategic · inferred

Cavern Manticore — Iran-Linked Modular .NET C2 Framework Targeting Israeli IT/Government

Why it mattersUnrated MENA relevance.
What's next12 follow-on investigations opened from this report.
Useful?
2026-07-10
REPORT2026-07-10-fortibleedstrategic · inferred

FortiBleed — Russian-Speaking IAB Syndicate Mass FortiOS Credential Theft

Why it mattersUnrated MENA relevance.
What's next9 follow-on investigations opened from this report.
Useful?
2026-07-10
REPORT2026-07-10-citrix-cve-2026-8451strategic · inferred

CVE-2026-8451 — Citrix NetScaler SAML Pre-Auth Memory Overread (CitrixBleed 2)

Why it mattersUnrated MENA relevance.
What's next3 follow-on investigations opened from this report.
Useful?
2026-07-10