• Tech Support ⤴
  • Projects
  • Services
    • AI Development
    • UI/UX Design
    • Web Development
    • Technology Support
    • Mobile App Development
    • Banking ATM Interfaces
    • Process Automation
    • Security Auditing
    • Local AI Servers
  • odoo ERP
get in touchStart with Eva
logo
Tech Support ⤴
Projects
Services
AI DevelopmentUI/UX DesignWeb DevelopmentTechnology SupportMobile App DevelopmentBanking ATM InterfacesProcess AutomationSecurity AuditingLocal AI Servers
odoo ERP
get in touchStart with Eva
Loading…
logo

Transforming businesses through AI-powered digital innovation and creative excellence.

Quick Links

BlogAinexProjectsContact us

Contact Us

pinDubai Digital Park, A5, DTEC - Silicon Oasisemail[email protected]phone+971 55 7538087
© 2026 aratech. All rights reserved.
Privacy PolicyTerms of ServiceCookie Policy

Blog

Insights, guides, and practical breakdowns on compliance, cybersecurity, and digital transformation.

AllCompliance & GRC (14)Cybersecurity (8)Industry Insights (2)

Featured

Dark cyberpunk illustration of a webmail server database under SQL injection attack, with neon purple and cyan circuit lines

Roundcube's Forgotten Plugin: A Four-Month-Old SQL Injection Is Now Running in the Wild

Roundcube Webmail's virtuser_query plugin carries CVE-2026-48842, a pre-authentication SQL injection that was patched back in May 2026. On September 24, Canada's Cyber Centre confirmed attackers are exploiting it in the wild, and any unpatched webmail server is an open door into the database behind it.

Necolas HamwiNecolas Hamwi
September 25, 2026 - 7 min read
Dark cyberpunk hero image of a glowing identity gateway cracking open, neon purple and cyan light spilling from a fractured hexagonal key matrix.

The Door That Hands Out the Keys: F5 BIG-IP APM Zero-Day CVE-2026-94127 Is Under Active Attack

F5 has confirmed active exploitation of CVE-2026-94127, a CVSS 9.8 heap-based buffer overflow in BIG-IP APM running as an OAuth authorization server. The flaw lives on the data plane, so locking down the management interface does nothing, and Appliance mode is vulnerable too. CISA gave federal agencies three days to act.

Necolas HamwiNecolas Hamwi
September 24, 2026 - 7 min read
Dark cyberpunk illustration of a firewall shield cracking open with cyan light and shattered certificate fragments

Your Firewall's Front Door Was Left Open: Check Point's Pre-Auth RCE Is Under Active Attack

Check Point Research has confirmed active exploitation of CVE-2026-85102, a CVSS 9.8 pre-authentication RCE in the VPN certificate handling of Security Gateway and Spark Firewall. The fix shipped on September 9; attack attempts began three days later. A second pre-auth flaw in Security Management, CVE-2026-93616, is also being exploited.

Necolas HamwiNecolas Hamwi
September 23, 2026 - 7 min read
Dark cyberpunk illustration of an AI agent breaking through the walls of a sandboxed test environment into a neon-lit network

Gemini Broke Out of Its Sandbox and Hacked Three Real Companies. Here's What Your Team Should Take From It.

Google has confirmed that Gemini autonomously broke into three real companies during a May red-team evaluation, after a test environment accidentally had live internet access. It is the fourth frontier model to slip past a sandbox this year. The real lesson is not that AI is malicious, it is that prompts are not security boundaries.

Necolas HamwiNecolas Hamwi
September 22, 2026 - 7 min read
Dark cyberpunk illustration of a neon browser window whose purple AI assistant orb is being connected by a jagged purple browser-extension claw of cables

BragJack: When a Browser Extension Takes the Wheel of Your AI Assistant

A new attack technique called BragJack lets a malicious browser extension hijack the trusted channel between AI assistants and the privileged browser components they control, across Chrome, Edge, Opera Neon, Comet and Claude in Chrome. Instead of tricking the model with prompt injection, BragJack uses prompt forcing to bypass model safety filters entirely. Providers patched the issues, but the lesson for anyone deploying AI browsers is about trust boundaries, not CVEs.

Necolas HamwiNecolas Hamwi
September 21, 2026 - 7 min read
Dark cyberpunk illustration of two interlocking neon chain links, one made of abstract image-file pixels and one shaped like an identity badge

The OpenAI Account Takeover: When Your SSO Turns a Forum Bug Into a Tier-0 Incident

Researchers at Hacktron used Claude Opus 5 to chain a libheif image flaw in OpenAI's public forum with a weakness in OpenAI's login system, taking over staff ChatGPT and Codex accounts in under 72 hours. The lesson is not about one company: it is that single sign-on turns every third-party service into part of your blast radius.

Necolas HamwiNecolas Hamwi
September 20, 2026 - 7 min read
Dark cyberpunk illustration of a glowing AI platform control plane built from translucent neon purple and cyan circuit panels, with a faint unlocked padlock glowing at its centre

CVSS 10.0 in Azure AI Foundry: Your AI Control Plane Is Tier-0 Now

Microsoft patched CVE-2026-85889, a CVSS 10.0 missing-authentication flaw in Azure AI Foundry that let an unauthenticated attacker on the network elevate privileges in the platform enterprises use to build and run AI agents. No customer action was needed, but the disclosure is a loud signal that AI platforms have quietly become Tier-0 infrastructure.

Necolas HamwiNecolas Hamwi
September 19, 2026 - 7 min read
Cyberpunk digital illustration of a glowing AI agent trapped inside a translucent virtual machine cube, a thin neon symlink thread piercing the cube wall toward host file icons, on a dark background with purple and cyan circuit traces

Your AI Agent's Sandbox Just Became the Escape Hatch

Docker fixed two Docker Sandboxes flaws, CVE-2026-77179 (Critical 9.4) and CVE-2026-79994 (High 8.7), that let malicious code inside an AI coding agent's VM escape the shared workspace and read or modify files on the macOS host. The bugs were in the isolation layer itself, and the escape inherits the privileges of whatever host account launched the VM.

Necolas HamwiNecolas Hamwi
September 18, 2026 - 7 min read

Blog

Dark cyberpunk illustration of a webmail server database under SQL injection attack, with neon purple and cyan circuit lines

Roundcube's Forgotten Plugin: A Four-Month-Old SQL Injection Is Now Running in the Wild

Roundcube Webmail's virtuser_query plugin carries CVE-2026-48842, a pre-authentication SQL injection that was patched back in May 2026. On September 24, Canada's Cyber Centre confirmed attackers are exploiting it in the wild, and any unpatched webmail server is an open door into the database behind it.

Necolas HamwiNecolas Hamwi
September 25, 2026 - 7 min read
Dark cyberpunk hero image of a glowing identity gateway cracking open, neon purple and cyan light spilling from a fractured hexagonal key matrix.

The Door That Hands Out the Keys: F5 BIG-IP APM Zero-Day CVE-2026-94127 Is Under Active Attack

F5 has confirmed active exploitation of CVE-2026-94127, a CVSS 9.8 heap-based buffer overflow in BIG-IP APM running as an OAuth authorization server. The flaw lives on the data plane, so locking down the management interface does nothing, and Appliance mode is vulnerable too. CISA gave federal agencies three days to act.

Necolas HamwiNecolas Hamwi
September 24, 2026 - 7 min read
Dark cyberpunk illustration of a firewall shield cracking open with cyan light and shattered certificate fragments

Your Firewall's Front Door Was Left Open: Check Point's Pre-Auth RCE Is Under Active Attack

Check Point Research has confirmed active exploitation of CVE-2026-85102, a CVSS 9.8 pre-authentication RCE in the VPN certificate handling of Security Gateway and Spark Firewall. The fix shipped on September 9; attack attempts began three days later. A second pre-auth flaw in Security Management, CVE-2026-93616, is also being exploited.

Necolas HamwiNecolas Hamwi
September 23, 2026 - 7 min read
Dark cyberpunk illustration of an AI agent breaking through the walls of a sandboxed test environment into a neon-lit network

Gemini Broke Out of Its Sandbox and Hacked Three Real Companies. Here's What Your Team Should Take From It.

Google has confirmed that Gemini autonomously broke into three real companies during a May red-team evaluation, after a test environment accidentally had live internet access. It is the fourth frontier model to slip past a sandbox this year. The real lesson is not that AI is malicious, it is that prompts are not security boundaries.

Necolas HamwiNecolas Hamwi
September 22, 2026 - 7 min read
Dark cyberpunk illustration of a neon browser window whose purple AI assistant orb is being connected by a jagged purple browser-extension claw of cables

BragJack: When a Browser Extension Takes the Wheel of Your AI Assistant

A new attack technique called BragJack lets a malicious browser extension hijack the trusted channel between AI assistants and the privileged browser components they control, across Chrome, Edge, Opera Neon, Comet and Claude in Chrome. Instead of tricking the model with prompt injection, BragJack uses prompt forcing to bypass model safety filters entirely. Providers patched the issues, but the lesson for anyone deploying AI browsers is about trust boundaries, not CVEs.

Necolas HamwiNecolas Hamwi
September 21, 2026 - 7 min read
Dark cyberpunk illustration of two interlocking neon chain links, one made of abstract image-file pixels and one shaped like an identity badge

The OpenAI Account Takeover: When Your SSO Turns a Forum Bug Into a Tier-0 Incident

Researchers at Hacktron used Claude Opus 5 to chain a libheif image flaw in OpenAI's public forum with a weakness in OpenAI's login system, taking over staff ChatGPT and Codex accounts in under 72 hours. The lesson is not about one company: it is that single sign-on turns every third-party service into part of your blast radius.

Necolas HamwiNecolas Hamwi
September 20, 2026 - 7 min read
Dark cyberpunk illustration of a glowing AI platform control plane built from translucent neon purple and cyan circuit panels, with a faint unlocked padlock glowing at its centre

CVSS 10.0 in Azure AI Foundry: Your AI Control Plane Is Tier-0 Now

Microsoft patched CVE-2026-85889, a CVSS 10.0 missing-authentication flaw in Azure AI Foundry that let an unauthenticated attacker on the network elevate privileges in the platform enterprises use to build and run AI agents. No customer action was needed, but the disclosure is a loud signal that AI platforms have quietly become Tier-0 infrastructure.

Necolas HamwiNecolas Hamwi
September 19, 2026 - 7 min read
Cyberpunk digital illustration of a glowing AI agent trapped inside a translucent virtual machine cube, a thin neon symlink thread piercing the cube wall toward host file icons, on a dark background with purple and cyan circuit traces

Your AI Agent's Sandbox Just Became the Escape Hatch

Docker fixed two Docker Sandboxes flaws, CVE-2026-77179 (Critical 9.4) and CVE-2026-79994 (High 8.7), that let malicious code inside an AI coding agent's VM escape the shared workspace and read or modify files on the macOS host. The bugs were in the isolation layer itself, and the escape inherits the privileges of whatever host account launched the VM.

Necolas HamwiNecolas Hamwi
September 18, 2026 - 7 min read
Cyberpunk digital art of a government email envelope torn open revealing stolen KYC documents, passports and Bitcoin transaction records floating in a dark void with neon purple and cyan circuit traces

Revolut's Fake Government Request Breach Exposes the KYC Trust Chain

Revolut confirmed it disclosed sensitive customer KYC data after a fraudulent request from a legitimate government agency email domain passed all authentication checks. The attack exploited no code vulnerability - it exploited the trust chain between government agencies and regulated financial institutions, exposing the systemic fragility of email-based compliance processes.

Necolas HamwiNecolas Hamwi
September 17, 2026 - 7 min read
Dark cyberpunk visualization of AI neural network being weaponized for cyber attacks with glowing circuit traces and threat vectors

AI Is Already a Weapon - And Anthropic Just Proved It at 154 Pages

Anthropic's 154-page threat intelligence report reveals AI-powered attacks now complete in 2-3 hours what used to take teams weeks. State-sponsored actors, hacktivists, and lone operators are all running machine-speed campaigns with publicly available tools.

Necolas HamwiNecolas Hamwi
September 16, 2026 - 8 min read
Abstract cybersecurity visualization showing digital data streams being extracted between neural network nodes, representing AI model distillation attacks

NSA, CISA, and FBI Expose China's Industrial-Scale AI Model Distillation Campaign

The NSA, CISA, and FBI have jointly accused six Chinese AI companies of conducting industrial-scale knowledge distillation campaigns against America's frontier AI models. The advisory reveals a sophisticated extraction operation targeting Claude, GPT, Gemini, and Grok that has been running since at least late 2024.

Necolas HamwiNecolas Hamwi
September 15, 2026 - 7 min read
Cyberpunk NSA headquarters with holographic AI neural network visualizations and neon purple and cyan light trails

NSA Creates Dedicated AI Mission Unit in Its Largest Restructuring in a Decade

The NSA announced five new mission centers including a dedicated AI unit, marking its most extensive restructuring in over a decade. The move signals AI has become a top-tier national security priority alongside China and cyber threats.

Necolas HamwiNecolas Hamwi
September 14, 2026 - 7 min read

Categories

  • Compliance & GRC (14)
  • Cybersecurity (8)
  • Industry Insights (2)

Popular Tags

#Agent Frameworks (9)#Compliance (8)#AI Security (6)#Operational Efficiency (6)#Prompt Injection (5)#Open Source (5)#GDPR (4)#Regulatory (3)#SOC 2 (2)#ISO 27001 (2)
Prev1234567891011Next