HIGH: Russian APT29 targets NATO infrastructure with novel backdoor
Cyber Resources
Authoritative sources across the globe and the Arab world — from US government agencies and compliance frameworks to regional regulators and national CERTs. All in one place.
MENA & Arab Cybersecurity Authorities
Official regulators, national CERTs, and cybersecurity bodies across Saudi Arabia, UAE, Qatar, Kuwait, Bahrain, Egypt, Jordan, Morocco, Tunisia, Oman, and Iraq.
National Cybersecurity Authority
Kingdom's supreme cybersecurity authority. Governs ECC, CSCC, and CCC frameworks for all critical sectors.
Communications, Space & Technology Commission
Regulates ICT sector security in Saudi Arabia, including telecom and internet.
Central Bank of UAE — Cyber Risk
Mandates cyber resilience for all licensed financial institutions in the UAE.
Telecommunications & Digital Government Regulatory Authority
UAE telecom regulator driving national cybersecurity strategy and incident response.
Qatar Computer Emergency Response Team
Qatar national CERT under Ministry of Transport and Communications. Threat advisories for Qatari entities.
Communication and Information Technology Regulatory Authority
Kuwait ICT security regulator overseeing national cyber policy and compliance.
Telecommunications Regulatory Authority
Bahrain's national authority for ICT and cybersecurity regulatory frameworks.
Ministry of Communications & Information Technology
Egypt national CERT and digital transformation authority — major regional cyber hub.
National Information Technology Center
Jordan government's main ICT security and digital infrastructure body.
Direction Générale de la Sécurité des Systèmes d'Information
Moroccan cybersecurity directorate — national strategy, CERT, and incident coordination.
Agence Nationale de la Sécurité Informatique
Tunisia's national cybersecurity agency managing CERT-TCC and national incidents.
Information Technology Authority
Oman national authority for cybersecurity, digital government, and ICT policy.
National Cyber Security Center
Iraq's national cybersecurity authority responsible for critical infrastructure protection, incident response, and cyber threat intelligence.
US Government Cyber Agencies
Primary US federal bodies publishing real-time advisories, threat intelligence, and vulnerability data relevant to global cybersecurity operations.
Cybersecurity & Infrastructure Security Agency
US national cyber defense agency — advisories, alerts, and ICS security updates.
National Institute of Standards & Technology
Home of the NIST Cybersecurity Framework (CSF), SP 800-53, and cryptographic standards.
National Security Agency
Technical cybersecurity guidance, advisories, and hardening guides from NSA.
Internet Crime Complaint Center
FBI portal for reporting cybercrime and tracking trending threat actor campaigns.
United States Computer Emergency Readiness Team
Technical alerts, vulnerability notes, and incident response coordination.
Adversarial Tactics, Techniques & Common Knowledge
The global standard knowledge base for adversary behavior and TTPs.
Common Vulnerabilities and Exposures
Official CVE database — track and reference disclosed vulnerabilities.
Compliance Frameworks & Standards
International standards and compliance frameworks that organizations across the Arab world must align with for certification, partnership, and regulatory approval.
International Organization for Standardization
The international ISMS standard. Widely required across GCC enterprises.
Payment Card Industry Data Security Standard
Mandatory for any org handling card payments. Critical for GCC fintech and retail.
Service Organization Control 2
Trust services criteria for cloud and SaaS providers operating in the region.
General Data Protection Regulation
EU law with extraterritorial reach — relevant for Arab companies doing business with Europe.
Center for Internet Security
18 prioritized security controls adopted widely across MENA governments.
SysAdmin, Audit, Network, Security
World-class cybersecurity training, research, and policy resources.
Open Web Application Security Project
Application security best practices, Top 10 vulnerabilities, and secure coding guides.
National Vulnerability Database
US government repository of vulnerability management data using CVSS scoring.
Defense & Cybersecurity Companies
Key defense contractors, threat intelligence firms, and cybersecurity vendors shaping global and MENA-region security posture — from Lockheed Martin to CrowdStrike.
Lockheed Martin Corporation
World's largest defense contractor. Operates global cyber threat intelligence and advanced persistent threat (APT) defense programs for government and military clients.
Raytheon Technologies — Cybersecurity
Provides cyber mission systems, network defense, and intelligence solutions to the US DoD and allied nations including Gulf partners.
BAE Systems Digital Intelligence
UK-based defense giant with a major cyber division. Active partner with GCC governments on national cyber defense programs.
Booz Allen Hamilton Cyber
Top US government cyber consultancy — supports NSA, DHS, and DoD cyber operations; advises Gulf states on national cyber strategy.
CrowdStrike Holdings
Industry-leading endpoint detection & response (EDR) platform. Tracks nation-state APT groups including Russian, Chinese, Iranian, and North Korean actors.
Palo Alto Networks
Global cybersecurity leader in SASE, firewalls, and threat intelligence. Major presence across UAE, Saudi Arabia, and MENA enterprise deployments.
Mandiant — Google Cloud Security
Premier incident response and threat intelligence firm. First responder to major global breaches; publishes landmark APT attribution reports.
Recorded Future
Real-time threat intelligence platform tracking nation-state actors, ransomware groups, and geopolitical cyber threats across all regions.
MITRE Corporation
Non-profit operator of federally-funded R&D centers. Authors of ATT&CK, CVE, and D3FEND frameworks widely used in Arab government security programs.
Cisco Talos Intelligence Group
One of the world's largest commercial threat intelligence teams — publishes real-time malware, vulnerability, and campaign research.
Darktrace AI Cybersecurity
AI-powered cyber defense platform with growing MENA presence. Detects insider threats and novel attacks using unsupervised machine learning.
Kaspersky Global Research & Analysis Team
Russia-based but globally respected threat research team. Authors of landmark reports on Stuxnet, Flame, and Middle East APT campaigns.
Companies Under Attack
Real-time tracking of active breaches, ransomware attacks, and APT campaigns targeting organizations worldwide — including defense contractors, critical infrastructure, and MENA entities.
The threat actor Breeze Comet has launched a series of aggressive cyberattacks targeting financial infrastructure in Brazil and globally. The campaign demonstrates advanced capabilities in infiltrating secure financial networks.
Zero-day vulnerabilities in SonicWall SMA 1000 series devices were identified, allowing for unauthenticated remote code execution. These flaws are being actively exploited to gain unauthorized access to corporate networks.
A new attack kit called NovaCookies is being sold to facilitate the theft of Microsoft 365 session tokens. This allows attackers to bypass multi-factor authentication and hijack active user sessions.
The medical technology company Stryker was targeted by a wiper attack designed to destroy data. The incident has been linked to Iranian-affiliated threat actors.
The personal email account of the FBI Director was reportedly breached by state-sponsored actors. The incident highlights ongoing espionage efforts targeting high-level U.S. officials.
The Belarus-aligned group Ghostwriter targeted Ukrainian government entities using geofenced PDF phishing lures. The campaign utilized Cobalt Strike beacons to establish persistent access.
Pro-Ukrainian hacktivist group PhantomCore exploited vulnerabilities in TrueConf video conferencing software to breach Russian networks. The attack focused on disrupting internal communications infrastructure.
Approximately 1TB of sensitive data was exposed following the compromise of an employee email account. The breach resulted in unauthorized access to internal banking records.
A public-sector campaign targeted the UK's PNLD, resulting in the exposure of approximately 135,000 records. The breach involved unauthorized access to sensitive legal and police-related data.
A ransomware attack forced the temporary halt of production at fairlife facilities. Attackers successfully exfiltrated corporate data before encrypting systems.
Iranian-linked actors have been conducting sophisticated spear-phishing campaigns against critical infrastructure in the U.S. and allied nations. The attacks focus on credential harvesting and long-term espionage.
State-sponsored actors have intensified cyber-espionage efforts against Israeli energy and utility providers. The campaigns utilize advanced persistent threat tactics to map and probe industrial control systems.
Cybersecurity Events
Upcoming conferences, summits, expos, and training events worldwide — with special focus on MENA-relevant gatherings for Arab security professionals.
Loading global events calendar...
