GCC Cyber Briefing Week of 2–8 June 2026: Meta AI Hijack, FIFA Fraud, Dashlane, Oracle KEV, Magecart Stripe and More
Major threats this week: Meta AI chatbot flaw hijacked IG accounts; FIFA World Cup fraud wave active with 4,300+ sites; Dashlane 2FA bypass; Oracle WebLogic actively exploited. Beware Stripe API Magecart & Chinese LinkedIn recruitment ops. Prioritize patching WebLogic & Cisco SD-WAN.

Security operations centre analyst monitoring multiple threat dashboards
Meta AI chatbot logic flaw exploited to hijack Instagram accounts
A logic flaw in Meta's AI-powered account recovery chatbot was confirmed to have been exploited to take over verified and high-follower Instagram accounts without knowledge of the account password. The attack abused the chatbot's identity verification workflow: by framing the request as a recovery scenario and spoofing the victim's geographic location via VPN, attackers persuaded the AI system to link the target account to an attacker-controlled email address, bypassing Meta's fraud detection entirely. Meta patched the flaw following disclosure.
This incident represents a distinct category of risk that traditional credential security controls do not address. Multi-factor authentication and phishing awareness training provide no protection against an attacker who convinces a trusted AI intermediary to hand over account access without requesting a credential. Enterprise security teams managing corporate Instagram accounts or integrating AI-assisted access workflows should treat AI-mediated account recovery as a distinct risk category requiring specific verification controls, separate from standard endpoint and identity security programmes.
Dashlane: encrypted vault copies downloaded after 2FA bypass
Dashlane disclosed on 4 June that a brute-force attack against its device registration API on 31 May bypassed two-factor authentication protections for fewer than 20 personal plan users, allowing an attacker to download encrypted vault copies. Dashlane's zero-knowledge architecture means vaults require the master password to decrypt, but accounts with weak master passwords face ongoing offline cracking risk. Enterprise plan accounts were not affected. Organisations across the GCC using Dashlane on personal plans for work credentials should verify whether affected accounts overlap with corporate access. Hardware security keys as a second factor, rather than numeric TOTP codes, provide substantially stronger protection against this class of brute-force 2FA bypass attack.
CISA confirms active exploitation of Oracle WebLogic CVE-2024-21182
CISA added Oracle WebLogic Server CVE-2024-21182 to its Known Exploited Vulnerabilities catalogue on 1 June, confirming that a flaw patched by Oracle in July 2024 remains under active attack nearly two years later. The vulnerability, rated CVSS 7.5, allows unauthenticated attackers to achieve full server compromise via T3 and IIOP protocols. The FCEB remediation deadline of 4 June has now passed for US federal agencies; the risk for non-federal organisations including those across GCC banking, government, and critical infrastructure remains active. Oracle WebLogic is one of the most widely deployed enterprise Java platforms across the Gulf. Organisations that have not applied the July 2024 Critical Patch Update should treat this as an immediate patching priority.
OpenAI launches ChatGPT Lockdown Mode to block prompt injection data exfiltration
OpenAI began rolling out an optional security setting for ChatGPT called Lockdown Mode, available across Free, Plus, Pro, and Business plans. When enabled, it restricts outbound network connections within ChatGPT to limit data exfiltration risk arising from prompt injection attacks, at the cost of disabling or reducing web-connected features. The feature is explicitly positioned for organisations and individuals processing sensitive data. This development coincides with the Meta AI chatbot incident confirmed this same week, reinforcing a consistent pattern: AI systems deployed as trusted intermediaries introduce data exfiltration attack surfaces that standard endpoint controls do not address. Enterprise CISOs should evaluate whether Lockdown Mode aligns with their AI governance policies, particularly for teams processing classified, client-confidential, or personally identifiable information.
FIFA World Cup 2026 fraud wave already active ahead of June 11 kickoff
Security researchers and the FBI have confirmed a coordinated wave of FIFA World Cup 2026 fraud is already live, with more than 4,300 fraudulent FIFA-themed domains registered since August 2025. At the centre of the campaign is GHOST STADIUM, a Chinese-speaking financially motivated threat group constructing lookalike FIFA ticketing and registration sites designed to harvest payment credentials. The scale of legitimate demand creates ideal fraud conditions: FIFA received more than 150 million ticket requests in the first 15 days of sales, leaving the event approximately 30 times oversubscribed.
Banking malware hidden inside pirate streaming applications represents a separate risk vector. Unofficial apps marketed to fans seeking free World Cup broadcasts have been confirmed to carry credential-harvesting code targeting financial accounts. A third operation has been documented creating replica FIFA login pages accurate enough to capture real FIFA.com credentials and linked payment methods.
For GCC enterprises, the risk is direct. The Gulf region has a large, high-spending football fanbase with significant travel to the United States planned across June and July. IT and security teams should issue staff guidance covering verification of purchases only through official FIFA channels, avoidance of unofficial streaming applications, and mandatory VPN use on public networks at tournament venues. Corporate mobile device policies should be enforced for all employees travelling to the event.
Cisco Catalyst SD-WAN zero-day actively exploited with no patch available
CVE-2026-20245 in Cisco Catalyst SD-WAN Manager is under active exploitation with no patch available, with real-world cases confirmed of configuration changes being pushed to connected edge devices across all deployment types. Full detail and GCC mitigation steps are in MCW's dedicated Cisco SD-WAN advisory.
Asin Android spyware targets Arabic-speaking users across MENA
ESET confirmed a new Android spyware campaign targeting Arabic-speaking users across the MENA region through fake government, PDF, and mapping applications, with samples linked to Turkiye and Syria from late 2025. Full analysis is in MCW's dedicated Asin spyware coverage.
CISA adds SolarWinds Serv-U CVE-2026-28318 to KEV catalogue
CISA added CVE-2026-28318, an unauthenticated denial-of-service flaw in SolarWinds Serv-U managed file transfer software, to its KEV catalogue on 5 June. The flaw allows an attacker to crash the Serv-U service without credentials by sending a specially crafted HTTP POST request using the Content-Encoding: deflate header. A hotfix is available in Serv-U version 15.5.4 HF1, with the FCEB remediation deadline set at 19 June 2026. Organisations running Serv-U in GCC banking or government file transfer environments should apply the hotfix promptly given Serv-U's history as a high-value exploitation target.
Android June 2026 patch fixes actively exploited zero-day
Google's June 2026 Android update patches 124 vulnerabilities including one actively exploited zero-day. Given this week's separate Asin spyware disclosure targeting MENA users specifically, the update should be treated as an immediate deployment priority across GCC managed device fleets. Full coverage is in MCW's dedicated Android patch analysis.
HTTP/2 Bomb disclosed across 880,000 exposed servers
The HTTP/2 Bomb vulnerability (CVE-2026-49975) affecting NGINX, Apache, IIS, Envoy, and Cloudflare Pingora was publicly disclosed on 3 June, with NGINX and Apache patched and three platforms still unpatched at time of writing. Full technical detail and mitigation guidance is in MCW's dedicated HTTP/2 Bomb coverage.
Miasma worm reaches Microsoft Azure GitHub repositories
The self-replicating Miasma worm disabled 73 Microsoft Azure and GitHub repositories on 5 June, triggering CI/CD disruption globally and exposing enterprise development teams to credential-harvesting payloads firing on repository open. Full technical detail and GCC action guidance is in MCW's dedicated Miasma coverage.
Also this week
The Linux kernel privilege escalation flaw CVE-2022-0492, exploitable via cgroups v1, was added to the CISA KEV catalogue with a now-passed federal deadline of 5 June. A zero-day in VS Code for Web was confirmed to allow GitHub token theft via malicious Jupyter notebook files, granting full read and write access to private repositories; the researcher disclosed without vendor coordination following prior disputes with Microsoft over attribution. Palo Alto Networks PAN-OS GlobalProtect CVE-2026-0257, which allows forged VPN cookies to bypass authentication on GlobalProtect portals and gateways, continued to see active exploitation first confirmed in late May. Magento plugin vulnerability CVE-2026-45247, a CVSS 9.8 deserialization remote code execution flaw in the Mirasvit Cache Warmer extension, was added to the CISA KEV catalogue on 3 June. A Redis critical RCE flaw, CVE-2026-23479, enabling authenticated users to execute arbitrary OS commands on the host machine, was confirmed through AI-assisted autonomous vulnerability research. Research by Include Security confirmed that free apps on Samsung, LG, and Roku smart TVs embedding the Bright Data SDK silently enrol home devices into a residential proxy exit node network without clear user disclosure.
ShinyHunters published a 234 GB archive of data allegedly stolen from DentaQuest, a US-based Medicaid dental benefits administrator serving 32 million patients, exposing records belonging to approximately 2.6 million individuals including email addresses, full names, phone numbers, government-issued IDs, Medicaid enrolment files, and health insurance information. DentaQuest confirmed a cybersecurity incident involving unauthorised access to a portion of its network. ShinyHunters had listed the company on its extortion site on 23 May and released the data in full after the ransom deadline passed without confirmed payment, adding to a 2026 tally that already includes Canvas, Charter Communications, and Carnival Corporation.
A new Magecart campaign was confirmed using Stripe's legitimate API infrastructure to host credit card-skimming payloads, making malicious exfiltration requests appear to originate from a trusted Stripe endpoint and bypassing most payment security monitoring tools that whitelist Stripe as a trusted third-party domain. This is directly relevant to GCC e-commerce and fintech organisations processing card-not-present transactions across UAE and Saudi Arabia platforms.
Five Eyes agencies issue joint advisory on Chinese LinkedIn recruitment operations
Five Eyes agencies issued a joint advisory on 4 June warning that Chinese military intelligence is using fake recruitment profiles on LinkedIn, Indeed, and Upwork to target government employees, military personnel, and security clearance holders. Posing as consultants and HR professionals, operators ask targets to write analytical reports on defence, trade, or foreign policy topics before escalating to requests for non-public information via encrypted messaging platforms. The advisory represents a direct operational risk for GCC organisations with government contracts, defence-sector exposure, or employees holding security clearances across the Gulf. Security and HR teams should issue updated guidance on unsolicited third-party research requests received via professional networking platforms, and review policies on employee engagement with unknown recruiters requesting work on sensitive topics outside formal channels.
Salma Mubarak
Cloud Security & AI Security ContributorSalma is a cloud security architect and AI risk analyst specializing in DevSecOps, SaaS security, and infrastructure protection. She focuses on identifying cloud misconfigurations, AI vulnerabilities, and implementing zero-trust security frameworks for modern organizations.
At MENA Cyber Wire, Salma breaks down complex cybersecurity and AI risk concepts into clear, practical insights for founders, IT managers, and security professionals across the MENA region.