Qatar’s Digital Boom Has a Blind Spot: What the 2025-26 Threat Data Is Telling Us
Cyble's Qatar Threat Landscape Report 2025-26 finds Qilin dominated local ransomware while access brokers concentrated on Qatari BFSI and retail access sales.
Cyble's Qatar Threat Landscape Report 2025-26 describes a concentrated threat environment where Qilin accounted for essentially all observed ransomware activity in the country in 2025, including an October campaign, with The Gentleman, Everest, Crypto24, and Payload sharing the space in 2026. Access brokers are selling compromised access, with BFSI and retail accounting for more than half of underground listings, while the education sector sees the most breach and leak incidents. Exploitation activity surged for enterprise remote-access products from Microsoft, Fortinet, Ivanti, and Citrix. The report was published ahead of the CYSEC Qatar summit and cites Qatar's data privacy law and National Cyber Security Agency initiatives.
CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign
CISA orders federal agencies to patch exploited Windows Winsock zero-day CVE-2026-68820 by August 25, used by Lazarus in Operation Dream Job.
CISA ordered federal agencies to patch Windows Winsock vulnerability CVE-2026-68820, rated 7/10, by August 25 after confirming exploitation; no workaround exists and a restart is required. Check Point found Lazarus Group hackers impersonated Lockheed Martin and Enveil recruiters on LinkedIn, sent malicious PDFs enabling long-term remote access, then used the zero-day to escalate from limited access to full system control. Targets spanned defense sectors including surveillance, drones and robotics in France, Germany, Brazil and India, as part of Operation Dream Job tracked since 2020.