The Weekly Wire (15-22 June): Showboat Espionage, FortiBleed Escalates, Check Point Zero-Day and More
Week 25 briefing: Showboat Chinese espionage in Middle East telecoms, FortiBleed at 110M credentials, Check Point VPN zero-day, Chrome exploited, SocGholish dismantled, Riyadh named UNITAR cyber HQ, and 20+ stories from a packed week in GCC and global security.

A split image of a security operations centre and a threat intelligence briefing document, representing the MENA Cyber Wire weekly GCC cybersecurity briefing covering 15 to 22 June 2026
Week 25 was one of the densest weeks of 2026 for enterprise cybersecurity across the GCC and globally. Credential theft, state-sponsored espionage, a landmark law enforcement takedown, two CISA-flagged zero-days, mandatory compliance deadlines, and a significant UN announcement in Riyadh all landed in the same seven days. This briefing covers both the stories MENA Cyber Wire published and what happened across the wider threat landscape.
GCC and MENA
A Chinese-linked post-exploitation framework called Showboat was publicly exposed this week after operating undetected for nearly three years inside Middle East telecommunications networks. Black Lotus Labs attributed the Linux-based malware to People's Republic of China-backed threat actors with moderate-to-high confidence.
The United Nations announced that Riyadh will serve as the headquarters for UNITAR's first dedicated cybersecurity office, the first time the UN has established a standalone cybersecurity training and capacity-building facility in the region. The designation positions Saudi Arabia as the Gulf's primary node for international cyber capacity development and aligns directly with the kingdom's Vision 2030 technology sovereignty agenda.
Kuwait's National Cybersecurity Centre formally made its National Basic Cybersecurity Controls mandatory under Decision No. 2 of 2026, giving businesses an 18-month compliance window and adding Kuwait to the list of GCC jurisdictions with binding, deadline-driven cybersecurity obligations.
Oman reported a target of six strategic cybersecurity projects as part of a new national investment push, alongside the Hadatha Centre's talent development programme aimed at growing the country's domestic cybersecurity workforce. The Omani cybersecurity market is projected to reach $214 million, underscoring the Gulf-wide acceleration of security investment beyond the UAE and Saudi Arabia.
Budget Saudi confirmed unauthorised access to customer data through its mobile application, disclosing the breach to the Saudi Exchange on 10 June. No financial data was compromised, but the incident carries direct PDPL notification implications and raises broader questions about mobile application security governance across GCC enterprises.
An IRGC-linked threat group identified as Nimbus Manticore was documented this week targeting aviation sector organisations in Saudi Arabia and the UAE using an AI-built backdoor called MiniFast. The campaign represents a continuation of Iranian-linked cyber activity directed at Gulf critical infrastructure and adds aviation to the list of sectors under active state-sponsored pressure in the region.
The UAE Cyber Security Council confirmed that daily breach attempts against UAE digital infrastructure have surged to between 600,000 and 800,000, up from 90,000 to 200,000 at the start of the year. Saudi Arabia experienced approximately 25 times its normal volume of cyber-relevant activity during the same period.
Critical Vulnerabilities and Patches
A Check Point Security Gateway vulnerability tracked as CVE-2026-50751 was confirmed as actively exploited this week, with the Qilin ransomware group linked to attacks targeting GCC organisations through the flaw. Check Point gateways are widely deployed across Gulf enterprise and government environments. Organisations running Check Point IKEv1 Security Gateway configurations should apply the available patch immediately and audit gateway logs for unauthorised VPN connection attempts.
The Chrome V8 engine zero-day CVE-2026-11645 was confirmed under active exploitation and patched in an emergency Chrome update. The type confusion flaw allows code execution through a crafted web page with no user interaction beyond visiting it. All enterprise Chrome fleets must be updated to version 137.0.7151.55 or later.
F5 patched two critical NGINX Open Source vulnerabilities, both carrying CVSS v4 scores of 9.2, including a use-after-free flaw in the HTTP/3 QUIC module and a heap-based buffer overflow in the HTTP/2 proxy module.
Splunk disclosed a critical CVE in its AI Toolkit carrying a CVSS score of 9.1, allowing admin-level OS command injection with no available detection mechanism. GCC enterprises running Splunk must patch to version 5.7.4.
CISA added the Joomla JCE plugin CVE-2026-48907 to its Known Exploited Vulnerabilities catalogue at CVSS 10.0, with an active exploitation confirmation and a federal patch deadline of 19 June. Attackers are deploying web shells through an unauthenticated PHP upload path.
The Splunk Enterprise pre-authentication RCE CVE-2026-20253 was also added to the CISA KEV catalogue this week, with active exploitation confirmed. This is a separate vulnerability from the AI Toolkit CVE, affecting the core PostgreSQL sidecar service in Splunk Enterprise deployments including AWS-hosted instances.
SolarWinds Serv-U carried a CISA KEV deadline of 19 June for CVE-2026-28318. Serv-U FTP and SFTP servers are deployed across GCC enterprise and government file transfer environments. Organisations still running unpatched Serv-U instances should treat this as an overdue emergency remediation.
Cisco Unified Communications Manager CVE-2026-20230, a server-side request forgery vulnerability with a CVSS score of 8.6, entered active exploitation this week. The flaw allows an unauthenticated attacker to write files to the underlying operating system, with a path to root escalation. Organisations running Cisco Unified CM should apply the patch issued in early June.
GitHub introduced a default security change to its actions/checkout workflow action, blocking pwn request attacks that exploit the pull_request_target trigger to run malicious code with full workflow privileges. The change took effect on 18 June 2026 and will be backported to all supported major versions on 16 July. Enterprise teams maintaining CI/CD pipelines should review their workflow configurations against the new default behaviour.
Threat Intelligence
The FortiBleed credential harvesting campaign was confirmed at a significantly larger scale than initially reported. New intelligence from SOCRadar places the device compromise count at over 430,000 FortiGate firewalls, with more than 110 million credentials harvested through a Golang-based sniffer that uses FortiGate's own native diagnostic commands to capture cleartext authentication traffic across 24 protocols. A dedicated updated article will follow.
Operation Endgame executed a major phase against the SocGholish malware network, seizing 106 servers and 101 domains while remediating nearly 15,000 infected WordPress websites. The operation involved the FBI, Europol, and law enforcement agencies from the Netherlands, Canada, and Germany.
DragonForce ransomware operators were observed this week using a custom Go-based remote access trojan called Backdoor.Turn to conceal command-and-control traffic inside Microsoft Teams relay infrastructure. Symantec and Carbon Black documented the technique against a major US services firm. Microsoft Teams is widely deployed across GCC government and enterprise environments, and this technique represents a new evasion method that bypasses network controls relying on Teams traffic as inherently trusted.
The INC ransomware group was documented at over 800 global victims, using a PowerShell-based technique to extract administrative credentials directly from Veeam backup servers before deploying Rust-compiled cross-platform payloads across Windows and VMware ESXi environments.
Salesforce disabled the Klue Battlecards integration after threat actors used compromised OAuth tokens to extract bulk CRM data through automated Python scripts over a near-24-hour window. The extortion group Icarus confirmed subsequent data exfiltration from affected customers.
Three new ClickFix malware loaders named BabaDeda, Lorem Ipsum, and Potemkin were documented delivering ransomware and remote access trojans through social engineering lures.
Unit 42 disclosed Pickle in the Middle, a bucket-squatting vulnerability in the Vertex AI Python SDK that allowed replacement of uploaded machine learning models with malicious versions and theft of OAuth tokens.
The Stryker cyberattack analysis published this week detailed how Iranian-linked group Handala wiped more than 200,000 enterprise devices in March 2026 using a single compromised Microsoft Intune administrator account.
A Samsung KNOX high-severity use-after-free vulnerability was disclosed this week, affecting Galaxy devices from the S9 through the S25. The flaw carries significant enterprise mobile security implications given the prevalence of Samsung devices across GCC corporate and government fleets. Organisations managing Samsung devices through enterprise mobility management platforms should apply the June security update.
A supply chain attack against the ShapedPlugin WordPress plugin compromised the update delivery mechanism, exposing sites running the plugin to malicious code injection through the standard WordPress update flow. The incident occurred in the same week as the SocGholish takedown and adds to the pattern of WordPress ecosystem supply chain compromises active throughout 2026.
Analysis, Guides and Market Intelligence
Japan's major banks warned this week that AI-enabled cyberattacks have reached a sophistication level that could force ATM and core banking service shutdowns. The warning carries direct relevance for GCC financial institutions operating comparable infrastructure.
Dream, an Israeli AI cybersecurity startup with Gulf government customers and an Abu Dhabi office, raised $260 million at a $3 billion valuation, reinforcing sovereign AI-driven cyber defence as a growing procurement category in the GCC.
A comparative evaluation of Microsoft Defender and CrowdStrike Falcon for GCC enterprise environments was published this week, covering licensing, detection capability, and regional deployment considerations.
A five-control Azure security guide for UAE and Saudi enterprise deployments covering Privileged Identity Management, Microsoft Sentinel, and Defender for Cloud configurations is now available on MENA Cyber Wire.
A GCC penetration testing guide covering 2026 regulatory requirements, vendor selection criteria, and realistic pricing is also available for enterprise security teams planning their assessment cycles for the second half of the year.
Salma Mubarak
Cloud Security & AI Security ContributorSalma is a cloud security architect and AI risk analyst specializing in DevSecOps, SaaS security, and infrastructure protection. She focuses on identifying cloud misconfigurations, AI vulnerabilities, and implementing zero-trust security frameworks for modern organizations.
At MENA Cyber Wire, Salma breaks down complex cybersecurity and AI risk concepts into clear, practical insights for founders, IT managers, and security professionals across the MENA region.