Weekly cyber-defense-intel case reports on activity affecting the MENA region — each synthesized from cited sourcing, with an inferred production tier and a deterministic field summary (not an analyst judgment). Switch to Executive for a plain-language view without the technical detail.
Mirage Kitten (UNC1549) — NightLedger Implant MENA Targeting
Why it mattersUnrated MENA relevance.
What's next9 follow-on investigations opened from this report.
Mirage Kitten (UNC1549), an Iranian state-sponsored actor, conducted targeted intrusions against aerospace, defense, and technology organizations in Israel, UAE, and wider MENA using the NightLedger implant. The…
Why it mattersUnrated MENA relevance, 2 tracked CVEs.
What's next13 follow-on investigations opened from this report.
Check Point Research's weekly report covers three major themes with MENA-region relevance: (1) CVE-2026-16232 — an unauthenticated token generation vulnerability in Check Point SmartConsole allowing arbitrary…
Window: 2026-07-24 → 2026-07-31Source: Check Point Research Weekly Threat Report — 2026-07-27
CyberAv3ngers — ICS/OT Attacks on Minnesota Water Utilities
Why it mattersUnrated MENA relevance.
What's next5 follow-on investigations opened from this report.
CyberAv3ngers, an Iranian IRGC-affiliated threat actor previously responsible for the 2023 Municipal Water Authority of Aliquippa attack, conducted renewed operations against Minnesota water and wastewater utilities in…
Window: 2026-07-24 → 2026-07-31Source: CISA advisory and reporting — CyberAv3ngers OT targeting of US water utilities (Minnesota incidents)
TeleShim — ASUS/GoPro ISO Malware Targeting MENA Governments
Why it mattersUnrated MENA relevance.
What's next5 follow-on investigations opened from this report.
TeleShim is a malware campaign targeting MENA government and defense organizations, delivering implants via ISO files disguised as ASUS software updates or GoPro alert service installers. The ISO contains legitimate…
Window: 2026-07-24 → 2026-07-31Source: Threat intelligence report — TeleShim campaign targeting Middle East government entities
MSTIC Q2 2026 Email Threat Landscape — Teams Vishing Surge and BEC Evolution
Why it mattersUnrated MENA relevance.
What's next9 follow-on investigations opened from this report.
Microsoft MSTIC documented Q2 2026 email threat trends including a 10x surge in Microsoft Teams vishing following the Tycoon2FA infrastructure disruption, automated two-stage BEC using Amazon SES tracking pixels, nested…
Window: 2026-07-17 → 2026-07-24Source: Microsoft Security Blog / MSTIC — "Email threat landscape: Q2 2026 trends and insights"
Why it mattersUnrated MENA relevance, 1 tracked CVE.
What's next4 follow-on investigations opened from this report.
CISA updated Advisory AA26-097A to document the CyberAv3ngers group (IRGC Cyber Electronic Command, G1027) actively exploiting internet-exposed programmable logic controllers across US critical infrastructure (water,…
Check Point Research Weekly — July 20, 2026 Threat Intelligence Compilation
Why it mattersUnrated MENA relevance, 5 tracked CVEs.
What's next9 follow-on investigations opened from this report.
Check Point Research's weekly compilation covers: ShinyHunters (Storm-3138) Salesforce OAuth exfiltration campaign; July 2026 Patch Tuesday CVEs including SharePoint (CVE-2026-56164, CVE-2026-58644) and AD FS…
Window: 2026-07-17 → 2026-07-24Source: Check Point Research — "20th July Threat Intelligence Report" (weekly compilation)
What's next11 follow-on investigations opened from this report.
Elastic Security Labs documented a new DPRK Contagious Interview campaign delivering malware via SVG files with steganographically embedded ZIP payloads. Targets are developers and tech workers recruited via fake job…