Threat Advisories

Top Middle East Cyber Threats – 22 July 2026

By Help AG

Help AG’s Managed Security Services (MSS) team delivers 24x7x365 monitoring across complex enterprise environments, providing continuous visibility into emerging cybersecurity threats across the region. 

Malicious Recruitment Campaign Targets Developers 

Threat actors linked to the Asia-Pacific (APAC) region are targeting software developers through sophisticated social engineering attacks known as Contagious Interview (tracked as REF9403) 

Posing as recruiters on platforms such as Slack, the attackers invite developers to complete coding assessments that contain malicious code. 

The attackers conceal the OTTERCOOKIE malware inside what appears to be harmless SVG flag images. The malicious code is split into Base64-encoded fragments and hidden within HTML comment blocks before being reconstructed and executed by a JavaScript file (serverValidation.js) when the application starts. Because the malware executes at runtime rather than during installation, it can bypass traditional package manager security controls. 

The malware includes modules capable of stealing browser credentials, cryptocurrency wallets, files, and clipboard data while also providing persistent remote access. A successful compromise could expose browser sessions, source code, cloud credentials, and other sensitive organisational assets. 

Recommendations 
  • Treat unsolicited coding tasks, repositories and software packages as untrusted. 
  • Inspect server start-up files and asset directories for dangerous dynamic code execution, including the use of eval (). 
  • Implement detections for eval () usage within server-side JavaScript and inspect SVG files for suspicious encoded content. 
  • If compromise is suspected, isolate affected systems immediately and rotate API keys, SSH keys, cloud credentials, GitHub/npm tokens and browser-stored credentials. 
  • Monitor or restrict outbound connections to the rightwidth.dev infrastructure. 

 

New Malware Campaign Targets macOS Environments 

Researchers have identified ClickLock Stealer, a new modular information stealer targeting macOS devices through ClickFix social engineering campaigns disguised as Cloudflare verification pages. Victims are convinced into running Terminal commands that install malware. 

Once executed, the malware steals browser credentials, macOS Keychain data, password manager vaults, cryptocurrency wallet information, shell history, and other sensitive data. It also installs a modified GSocket backdoor to establish persistent remote access. 

To obtain additional credentials, the malware repeatedly closes visible applications prompting victims to enter their macOS password or approve Keychain access. The stolen data is then exfiltrated through Telegram infrastructure. Active since May 2026, the campaign has affected at least 100 victims worldwide, including organisations across Europe, North America, the Middle East, and Africa. 

Recommendations 
  • Never execute Terminal commands copied from websites or verification pages unless their source is fully validated. 
  • Educate users about ClickFix and similar paste-based social engineering attacks. 
  • Investigate unexpected macOS password prompts and forced application closures. 
  • Monitor for suspicious osascript execution and fake password dialogues. 
  • Detect rapid pkill or killall activity targeting system processes. 
  • Alert on security find-generic password executed via shell scripts. 
  • Monitor access to browser profiles, Keychain data and cryptocurrency wallets. 
  • Detect outbound connections to the Telegram Bot API and suspicious archive creation. 
  • Block or investigate suspicious curl | bash execution. 
  • Monitor for new LaunchAgents within ~/Library/LaunchAgents/. 

 

Microsoft Addresses Windows USB Audio Driver Vulnerability 

Microsoft has released a security update addressing CVE-2026-58528, a medium-severity information disclosure vulnerability affecting the Windows USB Audio Class driver (usbaudio.sys). 

An attacker with physical access to a vulnerable system could exploit the flaw to disclose sensitive information. The vulnerability affects multiple supported versions of Windows 10, Windows 11 and Windows Server. 

Recommendations 
  • Apply the latest Microsoft security updates across all affected systems. 

 

ServiceNow Releases Security Update for Critical AI Platform Vulnerability 

A critical remote code execution vulnerability (CVE-2026-6875) affecting the ServiceNow AI Platform is currently being exploited in the wild. 

Threat intelligence indicates that attackers are exploiting the vulnerability to execute unauthorised code. Organisations using ServiceNow for AI-enabled workflows and automation may be exposed to full system compromise, data theft and lateral movement if the vulnerability is not addressed 

Because active exploitation has already been observed, organisations should prioritise remediation immediately. 

Recommendations 
  • Apply the latest ServiceNow security patches without delay. 
  • Monitor logs for unauthorised code execution and suspicious service account activity. 
  • Implement network segmentation to limit lateral movement. 
  • Review access controls and audit recent configuration changes. 

 

Critical WordPress Vulnerability Enables Remote Code Execution 

Researchers have disclosed wp2shell (CVE-2026-63030), a critical pre-authentication remote code execution vulnerability affecting WordPress Core. 

The exploit combines a REST API batch-route confusion vulnerability with a SQL injection flaw in the WP_Query class, allowing an unauthenticated attacker to compromise default WordPress installations without requiring plugins or custom configurations. 

Although widespread exploitation had not been confirmed as of 18 July 2026, public proof-of-concept code is available for part of the exploit chain, increasing the likelihood of attacks. Organisations running WordPress 6.9.0–6.9.4 or 7.0.0–7.0.1 should upgrade immediately. 

Recommendations 
  • Upgrade immediately to WordPress 6.9.5, 7.0.2 or later (or 6.8.6 for the 6.8 branch). 
  • Verify that updates have been successfully applied. 
  • Use a web application firewall (WAF) to restrict anonymous access to /wp-json/batch/v1 and ?rest_route=/batch/v1. 
  • Enable a persistent object cache such as Redis or Memcached. 
  • Monitor web server logs for unusual POST requests targeting batch endpoints. 
  • Maintain an accurate inventory of all WordPress instances, including staging environments, and keep plugins and themes fully updated. 

 

REFERENCES 

https://cybersecuritynews.com/north-korean-hackers-ottercookie-malware/ 

https://www.group-ib.com/blog/clicklock-stealer-macos-malware/ 

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58528 

https://www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/ 

https://wp2shell.com/ 

More Resources

Download the Content

I’m interested in the solutions & services from?

(Choose all that apply)

Schedule a Consultation