Help AG’s Managed Security Services (MSS) team provides 24x7x365 monitoring across complex enterprise environments, offering continuous visibility into emerging cybersecurity threats across the region.
Espionage Campaign Targets Individuals Across the Middle East
A long-running espionage campaign, active since at least 2022, has targeted journalists, civil society members and other individuals across the Middle East.
The campaign uses spearphishing, fake social media personas, messaging applications and credential theft to target users and deliver spyware.
Android users may be directed to install ProSpy, spyware disguised as legitimate messaging applications such as Signal, ToTok and Botim. Once installed, ProSpy can collect contacts, SMS messages, device information, documents, media, archives and application backups. The collected data can then be transmitted to command-and-control (C2) infrastructure.
Confirmed victims have been identified in Egypt and Lebanon, with evidence of additional targeting activity across other countries in the region.
The campaign has been linked to infrastructure and activity associated with the BITTER advanced persistent threat (APT) group. However, the available evidence does not confirm whether the group is directly responsible for the operation.
Recommendations
- Monitor Android devices for unauthorised Android application package (APK) installations.
- Restrict application installations from unknown or unofficial sources.
- Ensure that Signal, ToTok and Botim are installed only from official application stores.
- Monitor for applications impersonating legitimate secure messaging services.
- Monitor connections to known ProSpy C2 infrastructure.
- Monitor for suspicious Android applications attempting to access contacts, SMS messages, files and device information.
- Monitor for unusual access to messaging application backup files.
- Monitor for unusual outbound transfers of documents, images, videos, archives and other sensitive files from mobile devices.
- Monitor for spearphishing links delivered through social media and messaging applications.
- Verify unexpected video-call, application-update and account-verification links before opening them.
Citrix Releases Fix for High-Severity NetScaler Vulnerability
Citrix has released a security update addressing a high-severity vulnerability, CVE-2026-88779, affecting NetScaler Application Delivery Controller (ADC) and NetScaler Gateway.
The vulnerability affects the following NetScaler ADC versions:
- Version 14.1 prior to 14.1-73.41
- Version 13.1 prior to 13.1-64.28
- Version 14.1 Federal Information Processing Standards (FIPS) prior to 14.1-73.41
- Version 13.1 FIPS prior to 13.1-37.282
NetScaler Gateway versions prior to 14.1-73.41 and 13.1-64.28 are also affected.
Organisations using affected versions are advised to apply the relevant security updates.
Recommendations
- Ensure that all affected systems are patched and updated.
Google Chrome Security Update Addresses Four Vulnerabilities
Google has released a Chrome security update addressing four vulnerabilities, including one critical, one high-severity and two medium-severity flaws.
Successful exploitation could allow attackers to execute malicious code outside the browser’s security sandbox or access data from other websites through specially crafted web pages.
The vulnerabilities include:
- CVE-2026-103624: Use-after-free vulnerability in Contextual Tasks.
- CVE-2026-103626: Authorisation issue in Filesystem.
- CVE-2026-103621: Integer overflow in Compositing.
- CVE-2026-103629: Integer overflow in Skia.
Google Chrome versions earlier than 154.0.8037.97 are affected.
Organisations are advised to update Chrome to the latest available version.
Recommendations
- Ensure that all affected systems are patched and updated.
Microsoft Exchange Server Update Addresses High-Severity Vulnerability
Microsoft has released a security update for CVE-2026-96940, a high-severity privilege escalation vulnerability affecting Microsoft Exchange Server.
The flaw is caused by weak authorisation controls and could allow an authenticated attacker to gain higher-level privileges remotely.
Affected versions include:
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Updates 14 and 15
- Microsoft Exchange Server Subscription Edition Release to Manufacturing (RTM)
Organisations using affected versions are advised to apply the relevant security update as soon as possible.
Recommendations
- Ensure that all affected systems are patched and updated.
REFERENCES
https://security.lookout.com/threat-intelligence/article/bitter-hack-for-hire
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174
https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html
https://issues.chromium.org/issues/561660166
https://issues.chromium.org/issues/553114097
https://issues.chromium.org/issues/556268833
https://issues.chromium.org/issues/562038679
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940









