The Weekly Wire (9–15 June): Saudi NCA Rules, Ransomware Trends & Critical Patches

Weekly Briefing (Week 24): Saudi NCA expands mandatory compliance. INTERPOL arrests 201 in Operation Ramz. Critical Veeam CVSS 9.4 flaw found. "The Gentlemen" ransomware gains worm-like speed. MuddyWater exploits Langflow zero-day. Microsoft sets record with 200 fixes. Stay tuned to MENA Cyber Wire.

Salma Mubarak
Cloud Security & AI Security Contributor8 min read
Security operations centre threat dashboards displaying GCC cybersecurity weekly briefing alerts for the week of 9 to 15 June 2026

Security operations centre threat dashboards displaying GCC cybersecurity weekly briefing alerts for the week of 9 to 15 June 2026

Saudi Arabia's NCA extends mandatory cybersecurity compliance to every private sector organisation

The most consequential regulatory development of the week, and arguably of the year so far for GCC enterprise security teams, is the confirmed enforcement of NCNICC-1:2025, the NCA framework that extends mandatory Saudi cybersecurity compliance to every private sector organisation operating in the Kingdom, regardless of critical infrastructure designation. Previously, mandatory NCA requirements applied primarily to CNI operators. Under NCNICC-1, Class A organisations with 250 or more employees or SAR 200 million or more in annual revenue face mandatory independent audits. Class B organisations face proportionate scaled requirements. No private sector entity in Saudi Arabia is now outside mandatory NCA scope.

This operates alongside ECC-2:2024, the updated Essential Cybersecurity Controls published in October 2024, which introduced full-role Cybersecurity Saudization across all cybersecurity positions, not just leadership; mandatory incident reporting portal registration; and new controls addressing supply chain security and post-quantum cryptography.

The NCA simultaneously opened its draft National Framework for Cybersecurity Information Sharing and Incident Response for public consultation on 10 June. Response deadlines as short as one to two hours to NCA requests are proposed. The consultation closes 10 July 2026. Organisations operating in Saudi Arabia that have not begun NCNICC-1 compliance assessments should treat this as an urgent action item. Full compliance guide is in MCW's dedicated NCA ECC-2:2024 analysis.

UAE Government Cybersecurity Summit confirms sovereign security as national mandate

The third UAE Government Cybersecurity Summit took place on 9 June at Conrad Etihad Towers in Abu Dhabi, convened by the UAE Cybersecurity Council with 400-plus delegates from government, critical infrastructure, financial institutions, and global cybersecurity firms. The summit formalised sovereign cloud and AI-driven defence as the UAE's defining cybersecurity priorities for 2026. The backdrop was substantive: the UAE absorbed between 500,000 and 700,000 cyberattack attempts per day during Q1 2026, and 128 confirmed threat incidents targeted UAE entities since the start of the year. Any organisation providing services to UAE government or regulated sectors should expect tightening procurement security requirements aligned with the sovereign architecture framing from the summit.

INTERPOL Operation Ramz: 201 arrests across 13 MENA countries in cybercrime sweep

INTERPOL announced Operation Ramz, the first coordinated cybercrime operation of its kind across the MENA region. Running from October 2025 to February 2026, the operation involved 13 countries: Algeria, Bahrain, Egypt, Iraq, Jordan, Lebanon, Libya, Morocco, Oman, Palestine, Qatar, Tunisia, and the UAE. Outcomes included 201 arrests, 382 additional suspects identified, 3,867 confirmed victims registered, and 53 servers seized. Nearly 8,000 intelligence packages were disseminated among participating countries.

Notable individual actions: a phishing-as-a-service platform was dismantled in Algeria; a financial fraud ring in Jordan was exposed as a human trafficking operation, with 15 Asian workers rescued after being forced into cybercrime; compromised devices in Qatar being used to spread malware were identified and secured; and a vulnerable server in a private residence in Oman containing sensitive data was neutralised. Group-IB contributed intelligence on more than 5,000 compromised accounts including government infrastructure accounts. Kaspersky, The Shadowserver Foundation, Team Cymru, and TrendAI also participated.

Operation Ramz confirms what Help AG's State of the Market Report 2026 established from SOC data: MENA-targeted cybercrime infrastructure is sophisticated, scale-operated, and actively targeting government, financial services, and consumer accounts across the Gulf. The UAE, Qatar, and Oman were all both targets and active enforcement participants.

Veeam Backup and Replication CVE-2026-44963: CVSS 9.4, patch immediately

Veeam released an emergency patch for CVE-2026-44963, a critical remote code execution vulnerability in Backup and Replication rated CVSS 9.4. The flaw allows any authenticated domain user to execute arbitrary code on the backup erver. This means a single compromised account anywhere in a connected domain is enough to gain full control of backup infrastructure. The patch is in version 12.3.2.4466, released 10 June. Veeam protects 82 percent of the Fortune 500 and dominates backup across GCC financial, government, healthcare, and energy environments. Ransomware actors in this region systematically destroy backup systems before deploying encryption. This vulnerability is precisely the mechanism that removes the recovery option. Patch now. Full technical detail in MCW's dedicated Veeam CVE advisory.

Langflow CVE-2026-5027: MuddyWater exploiting AI application platform zero-day

A critical path traversal vulnerability in Langflow, the open-source AI application builder, is being actively exploited with no official patch available. CVE-2026-5027, rated CVSS 8.8, enables an unauthenticated attacker to write files anywhere on the underlying server filesystem and achieve remote code execution without valid credentials. Langflow's default unauthenticated auto-login configuration widens the attack surface to a single HTTP request. Approximately 7,000 Langflow instances are publicly exposed. Threat intelligence links exploitation to MuddyWater, an Iranian state-sponsored group that has consistently targeted GCC government, telecommunications, and critical infrastructure. Three immediate actions: remove Langflow from public internet access entirely, deploy WAF rules blocking path traversal sequences, and review access logs from late May 2026 onwards. There is no patch. Public exposure is the only control variable. Full advisory in MCW's dedicated Langflow CVE-2026-5027 article.

The Gentlemen ransomware surpasses 478 victims and can spread like a worm

Updated analysis from THN on 11 June confirmed that The Gentlemen ransomware group has now claimed 478 published victims since its mid-2025 launch, cementing its position as the second most active ransomware operation globally. A 90/10 affiliate revenue split continues to attract experienced operators from rival RaaS programmes. More significantly, new analysis revealed that The Gentlemen's encryptor includes worm-like propagation capabilities, enabling lateral spread across networks without requiring separate tools or manual operator action after initial access. Entry points remain internet-facing VPN appliances and firewalls, with full network encryption achievable within hours. The GCC exposure is concrete: UAE organisations pay 92 percent of ransomware demands and the worm capability removes any reliance on slow lateral movement, compressing the defensive response window further.

Budget Saudi mobile application data breach

Budget Saudi Arabia disclosed via Tadawul on 10 June that unauthorised access to customer personal data had occurred through its mobile application. No financial or banking data was compromised and all operations continued normally. Under Saudi Arabia's PDPL, SDAIA notification within 72 hours was required. The incident illustrates the persistent application security gap that Mastercard's Cyber Pulse EEMEA report confirmed this week as one of the two most consistently observed cyber health gaps across EEMEA organisations.

Microsoft June 2026 Patch Tuesday: record 200 fixes including three exploited zero-days

Microsoft released nearly 200 security patches in its June 2026 Patch Tuesday, a record for any single monthly cycle. Nearly three dozen were rated Critical. Exploit code for three vulnerabilities is publicly available. CVE-2026-49160, a denial-of-service flaw in IIS, was discovered by OpenAI's Codex. Two further zero-days from researcher Nightmare Eclipse, GreenPlasma (CVE-2026-45586, Windows elevation of privilege) and YellowKey (CVE-2026-50507, BitLocker bypass requiring physical access), also have public exploits. The BitLocker flaw is directly relevant to GCC enterprises running Windows environments under NCA ECC-2:2024 encryption obligations. Apply patches for the three exploited zero-days first. Tenable's Satnam Narang noted that AI-assisted bug discovery is likely making this volume the new normal. A related signal from the week: OpenSSL patched 18 vulnerabilities in a single release, several AI-discovered, covered in MCW's dedicated OpenSSL advisory.

Europol dismantles AudiA6: the ransomware money laundering pipeline that processed EUR 336 million

Europol coordinated the dismantling of AudiA6 on 10 June, a cryptocurrency laundering service that processed more than EUR 336 million in ransomware proceeds between 2022 and 2025 and was linked to more than 15 international ransomware investigations. Two administrators of Ukrainian and Russian nationality were arrested in Georgia. Authorities seized more than 30 servers, took down 25 domains, confiscated 80-plus vehicles and multiple properties, and froze EUR 692,000 in cryptocurrency. AudiA6 marketed itself as a professional mixing service, laundering funds within approximately one hour by routing proceeds through over 6,000 KYC-verified money mule accounts across centralised exchanges. The Dark2Web cybercrime forum, operated by the same administrators, was simultaneously taken down. The AudiA6 disruption removes a key financial infrastructure component from the ransomware economy, though Europol noted that similar services continue to evolve rapidly.

GCC urged to build EU-style cyber collective defence

Writing in AGBI on 11 June, Professor Alan Woodward of the University of Surrey argued that Gulf states need to build a coordinated, operational cyber intelligence sharing architecture comparable to what ENISA and Europol provide in Europe. More than 80 percent of successful attacks still begin with phishing and stolen credentials. Intelligence on these campaigns is highly transferable: what works against a UAE financial institution this week will be attempted against a Saudi government entity the following week. That intelligence is not being systematically shared at the speed needed. Full analysis in MCW's dedicated GCC collective defence article.

Also this week

The Help AG State of the Market 2026 report confirmed DDoS activity rose 857 percent between 2019 and 2025, with the longest single attack lasting 85 consecutive days, and attack completion speed increased 65 percent in Q1 2026 with several GCC compromises reaching full operational impact in under 40 hours. GCC enterprise security teams can review the cloud security implications in depth and the CrowdStrike vs Palo Alto vs Fortinet comparison published this week. The Saudi NCA ECC-2:2024 compliance guide and Zero Trust implementation guide are both available as standalone deep-dives.

Salma Mubarak

Cloud Security & AI Security Contributor

Salma is a cloud security architect and AI risk analyst specializing in DevSecOps, SaaS security, and infrastructure protection. She focuses on identifying cloud misconfigurations, AI vulnerabilities, and implementing zero-trust security frameworks for modern organizations.

At MENA Cyber Wire, Salma breaks down complex cybersecurity and AI risk concepts into clear, practical insights for founders, IT managers, and security professionals across the MENA region.