🛡️ Cyber Pulse Weekly | 17–23 August 2026 — Threats, CVEs, Attacks & AI Innovations

⚔️ Attack Tracker: Top 10 Cyber Attacks (UAE, Gulf & Global)

Regional evidence gap: Only one UAE/Gulf incident met the required source and date-verification standard for 17–23 August 2026; this edition does not invent additional regional attacks.

  1. UAE critical sectors face coordinated state-aligned intrusions

    Region/Country: United Arab Emirates | Attack Type: Cyber espionage and targeted intrusion | Threat Actor: Not identified in cited source
    Summary: The UAE Cyber Security Council said coordinated attacks reached a limited number of corporate accounts and devices across aviation, energy and education. Authorities contained the activity before attackers reached systems controlling essential services, and the reporting characterized it as state-aligned espionage.

    Source: WIRED Middle East — https://www.wired.me/story/inside-the-ai-powered-cyberattack-on-the-uaes-critical-sectors

  2. GE, Philips and Shell investigate Clop-linked data theft

    Region/Country: Global / United States / Europe | Attack Type: Data-theft extortion | Threat Actor: Clop
    Summary: GE and Philips investigated Clop claims, while Philips confirmed containment of an attempted compromise on a specific enterprise server and no customer-environment impact. Shell separately investigated a potential incident as the campaign targeted internet-facing PTC Windchill and FlexPLM systems.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/

  3. MyDr breach prompts national investigation

    Region/Country: Poland | Attack Type: Healthcare data breach | Threat Actor: Not identified in cited source
    Summary: Unauthorized access to historical MyDr data could affect nearly 19 million people and more than 12,000 medical facilities. The P1 national e-health platform remained secure, while authorities replaced connected-system certificates as a precaution.

    Source: Recorded Future News — https://therecord.media/poland-probes-mydr-healthcare-software-breach

  4. SickKids incident exposes workforce information

    Region/Country: Canada | Attack Type: Third-party data breach | Threat Actor: Not identified in cited source
    Summary: Toronto’s Hospital for Sick Children said an incident exposed personal information belonging to some current and former employees and job applicants. The hospital stated that clinical systems and patient records were not affected.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/sickkids-data-breach-exposes-employee-and-job-applicant-info/

  5. CEVA breach affects Pokémon Center customers

    Region/Country: United Kingdom and Germany | Attack Type: Third-party logistics data breach | Threat Actor: Not identified in cited source
    Summary: Attackers stole Pokémon Center customer and order information after compromising logistics provider CEVA’s servers. Exposed data included names, contact details, addresses and order contents, while payment-card details were not held by CEVA.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/pokemon-center-data-breach-exposes-customer-info-cancels-some-orders/

  6. Sakura Internet reports customer-system intrusion

    Region/Country: Japan | Attack Type: Cloud-provider data breach | Threat Actor: Not identified in cited source
    Summary: Sakura Internet disclosed unauthorized access to its sales-management system containing customer contract and membership data. The provider said the incident could affect information associated with up to 1.36 million accounts.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/sakura-internet-hack-exposes-data-of-up-to-136-million-accounts/

  7. Rust crates poisoned through a maintainer account

    Region/Country: Global | Attack Type: Software supply-chain compromise | Threat Actor: Not conclusively attributed in cited source
    Summary: Malicious releases of arrayref, append-only-vec and internment executed infostealer code during compilation. Researchers observed infrastructure overlap with recent DPRK-linked activity but stopped short of definitive attribution.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/hackers-poison-arrayref-rust-crate-to-push-infostealer-malware/

  8. Vehicle head units conscripted into proxy botnet

    Region/Country: China / Global distribution | Attack Type: Automotive supply-chain attack | Threat Actor: MoYu
    Summary: A legitimate update application for Android car head units delivered malware that turned devices into proxy nodes or supported ad fraud. Kaspersky attributed the operation to MoYu and found no impact on driving or critical vehicle-control systems.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/hackers-infect-android-car-head-units-with-proxy-botnet-malware/

  9. AI-assisted exploitation targets Siemens PLCs

    Region/Country: United States | Attack Type: Critical-infrastructure intrusion and reconnaissance | Threat Actor: Not identified in cited source
    Summary: U.S. agencies warned that ongoing activity uses AI-generated Python scripts against exposed Siemens S7 controllers. The tools can read or alter PLC memory and configuration, creating risks of data theft, downtime, equipment damage and safety incidents.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/us-warns-of-ai-powered-attacks-on-siemens-plcs-in-critical-infrastructure/

  10. Head Mare exploits TrueConf servers

    Region/Country: Russia | Attack Type: Video-conferencing supply-chain compromise | Threat Actor: Head Mare
    Summary: Kaspersky said Head Mare exploited TrueConf Server vulnerabilities to replace legitimate client installers with malicious versions. CISA added CVE-2026-72529 and CVE-2026-72530 to its exploited-vulnerability catalog after attacks across transportation, energy, IT and other sectors.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-trueconf-server-flaws/