
Welcome to the First ever issue of The Lumora Security Brief | UAE Edition.
This monthly newsletter is powered by Lumora Security and will run through the threats that have shaped the recent cybersecurity measures, take the biggest one apart in detail, share a thought that businesses can keep in mind for their own cybersecurity operations, and finally close with some upcoming events worth marking on your calendar or a retrospective of the last month’s major conferences.
Identity security issues led the threat landscape these last few months. The UAE Cybersecurity Council puts more than 75% of breaches in the country down to phishing or fraudulent messages, and the heaviest pressure fell on businesses running Microsoft 365 and Google Workspace, along with the finance and admin teams who handle payments and documents.
The pace was relentless, with the Council reporting 128 confirmed threat incidents against UAE entities in the first six weeks of the year, with an average of more than two a day.
A cluster of flaws stood out, most of them exploited before a even patch existed.
As discussed earlier, the most prominent threats have been actively threatening UAE-based operations since the beginning of the year. Between February and March, attackers ran a device code phishing campaign that reached more than 340 Microsoft 365 powered organisations across five countries, with the UAE among the regions named.
Microsoft first flagged the technique in early 2025 as Storm-2372. It is the clearest example this year of an attack that walks past the defences most SMBs rely on.
The trick abuses a real Microsoft sign-in feature, the one for devices without a proper browser. An employee gets a routine-looking message, often posing as IT, and is sent to a real Microsoft page to enter a short code. Because the page is real, it passes every check. Entering the code approves a sign-in on a device the attacker controls.
What they collect is a refresh token, which keeps the session alive after the victim changes their password. That is why Microsoft's guidance is to revoke the user's sign-in sessions rather than rely on a password reset. For weeks, the intruder can read the victim's email and files without tripping a stolen-password alert.
Adding more MFA does not close this gap either, because the sign-in happens on real Microsoft infrastructure, so even a hardware key validates correctly. The fix is to block the device code flow with a Conditional Access policy, then revoke active tokens. Watch for token activity from countries your staff are not in.
“Strong passwords help, but they are no longer enough to keep accounts and systems safe when used alone.” ~ CISA
Microsoft, after studying its own breach data, found that more than 99.9% of compromised accounts don't have MFA. That single number sits underneath almost everything in this issue.
Most of what hurt businesses recently was not exotic. A login feature was turned against its owner. A reused password opened a door that should have stayed shut. The tools to stop both have existed for years, and they exist inside the Microsoft and Google subscriptions companies already pay for.
That gap, between the protection a business owns and the protection it has switched on, is where we keep landing. Smaller firms are sold the idea that safety comes from buying one more product. This month says otherwise. The businesses that came through clean had turned on multi-factor authentication properly and kept their software patched. They also knew which apps could reach their data.
There is a quieter shift underneath all of this. For a small business, the front door is no longer the office network. It is the identity layer, the set of logins and app permissions that decide who gets to act as your staff for a few minutes. Attackers worked that layer hard these last few months, and they will keep doing it, because it pays and because so many tenants leave it loosely configured.
None of this calls for a bigger budget. What it does call for is attention, and for treating the basics as the main event rather than a box to tick on the way to the next purchase. That is unglamorous advice, but it is also a proven solution.
If there is one job worth doing before the summer ends, it is sitting down with whoever runs your IT and asking a plain question: what can currently reach our email and files, and who approved it? The answer tends to be longer than anyone expects. Most of the time nobody has looked in months, and a handful of forgotten apps and dormant accounts are quietly holding the keys.
June was a busy month for cybersecurity conversations in the UAE. Across Abu Dhabi and Dubai, the focus was clear: AI-driven threats, cyber resilience, Zero Trust, cloud security, critical infrastructure protection, and the growing role of CISOs in business risk.
These were just a few major events that showed how cybersecurity in the region is moving beyond tool adoption and becoming a board-level, policy-level, and operational priority.
1. Government Cybersecurity Summit 2026, Abu Dhabi, 9 June
The summit focused on the UAE’s national cybersecurity strategy, AI in cyber defence, cloud and application security, Zero Trust, critical infrastructure protection, and the human factor in government security. It brought together UAE government leaders, regulators, CISOs, cyber vendors, and public-sector security teams, with H.E. Dr. Mohamed Al Kuwaiti listed for the opening keynote on safeguarding the UAE’s digital future.
2. SHIFT Dubai 2026, Dubai, 17 June
SHIFT Dubai focused on cyber resilience, recovery, AI governance, threat intelligence, and cloud-native security. The event looked closely at how organisations can secure, recover, and scale across multi-cloud environments while preparing for AI-driven threats.
3. 4th Annual 100 CISO Summit & Awards UAE, Dubai, 25 June
This Dubai event centred on “Advancing Cybersecurity Through AI and Strategic Resilience,” with a broader theme around securing the post-AI era, cyber resilience, strategic control, and sovereign risk management. It gathered regional cybersecurity leaders and included discussions on the CISO’s evolving role, practical AI in security, regulatory compliance in the Emirates, critical infrastructure protection, and C-suite cyber resilience.
4. Forbes Middle East Building the Future Summit 2026 2nd Edition, Abu Dhabi, 23-24 June
While not a cybersecurity-only event, the 2nd Edition of the summit became relevant to the cyber conversation because it focused on smart infrastructure, AI, data centers, energy, mobility, and future-ready cities. Dr. Mohamed Al Kuwaiti, Head of Cybersecurity at the UAE Government, also warned at the summit about unsafe AI deployment, weak cyber hygiene, and the risks created when organisations adopt AI without proper standards and safeguards.
Thanks for reading till the end.
At Lumora Security, we help SMBs across the UAE find this kind of exposure before an attacker does, whether that is token persistence in a Microsoft 365 tenant or a connected app quietly holding access to your files. Our Essential Security Review maps it in plain language, in a single session, and shows you what to close first.
Never miss an update from The Lumora Security Brief. Subscribe this newsletter on substack or LinkedIn.