Newsletter
Jul 3, 2026

The Lumora Security Brief | UAE Edition | June 2026

Welcome to the First ever issue of The Lumora Security Brief | UAE Edition.  

This monthly newsletter is powered by Lumora Security and will run through the threats that have shaped the recent cybersecurity measures, take the biggest one apart in detail, share a thought that businesses can keep in mind for their own cybersecurity operations, and finally close with some upcoming events worth marking on your calendar or a retrospective of the last month’s major conferences.  

June Month's Threat Updates: What Hit UAE and How

Identity security issues led the threat landscape these last few months. The UAE Cybersecurity Council puts more than 75% of breaches in the country down to phishing or fraudulent messages, and the heaviest pressure fell on businesses running Microsoft 365 and Google Workspace, along with the finance and admin teams who handle payments and documents.  

The pace was relentless, with the Council reporting 128 confirmed threat incidents against UAE entities in the first six weeks of the year, with an average of more than two a day.  

A cluster of flaws stood out, most of them exploited before a even patch existed.

  • Microsoft patched a SharePoint Server spoofing flaw, CVE-2026-32201, that attackers had already been using as a zero-day to impersonate trusted internal pages and harvest credentials. CISA added it to its Known Exploited Vulnerabilities catalogue the same day patches dropped, yet more than 1,300 internet-facing SharePoint servers were still unpatched a week later. If you run on-premises SharePoint, apply the April update, then review external sharing and switch off anonymous links. This one affects the on-premises Server product only, so businesses on SharePoint Online inside Microsoft 365 are not exposed to it. A login prompt appearing on a page someone was already signed in to is a useful warning sign.
  • Google shipped an emergency fix for a Chrome flaw in the WebGPU graphics component, CVE-2026-5281, after confirming it was being exploited in the wild. It was the fourth actively exploited Chrome zero-day of 2026. Code can run when someone visits a crafted web page, with no download required, so any laptop that browses is in scope. Set browsers to update automatically and restart them, so the fix applies, and consider browser isolation for staff who routinely open unknown links. The same fix matters for Edge, Brave, and other Chromium-based browsers, which inherit the flaw until they ship their own updates.
  • Adobe issued an out-of-band patch for an Acrobat Reader flaw, CVE-2026-34621, that runs code when a booby-trapped PDF is opened. It carries a CVSS score of 8.6 and had been exploited quietly since late 2025. The lure is usually an attachment dressed up as an invoice, which is what lands it in finance and admin inboxes. CISA gave federal agencies until late April to patch it, a useful benchmark for everyone else. Keep Acrobat patched everywhere, and if you run email security, switch on attachment sandboxing, so a malicious file is caught before it reaches an inbox.
  • Google's threat intelligence team tracked an expansion of ShinyHunters-branded SaaS data theft, where attackers phone staff while posing as IT support, then capture their single sign-on credentials. From there they register their own device for the account's MFA. The group has claimed more than a thousand organisations across its SaaS campaigns, often by stealing OAuth tokens that lie inside connected apps and bypass MFA entirely. Audit the third-party integrations linked to your core systems and revoke unused OAuth permissions and dormant API tokens. These integrations are easy to forget, since a single click during setup can grant broad access that never expires on its own. Vendors rarely tell you promptly when they have been breached, so the review has to be yours to run.
  • Microsoft's April Patch Tuesday was one of the larger ones on record, fixing 167 vulnerabilities including two zero-days. The volume widens the window attackers exploit while small teams catch up, and several fixes addressed the remote code execution that ransomware crews look for. Anything internet-facing comes first. If nobody owns patch timing in your business, that is the gap to close before any of the rest.
  • Remote and hybrid work kept widening the attack surface. The UAE Cybersecurity Council recorded more than 12,000 Wi-Fi breaches in a single year, around 35% of national attacks, alongside a 40% rise in incidents tied to remote work. Home routers and personal devices sit outside most company controls, which makes them an easy way around an otherwise well-run office. Ask staff to update home router firmware and change default passwords and route work access through a managed device or an approved VPN rather than an open network.

What is Device Code Phishing, and Why Won't a Password Reset Stop It?

As discussed earlier, the most prominent threats have been actively threatening UAE-based operations since the beginning of the year. Between February and March, attackers ran a device code phishing campaign that reached more than 340 Microsoft 365 powered organisations across five countries, with the UAE among the regions named.  

Microsoft first flagged the technique in early 2025 as Storm-2372. It is the clearest example this year of an attack that walks past the defences most SMBs rely on.

The trick abuses a real Microsoft sign-in feature, the one for devices without a proper browser. An employee gets a routine-looking message, often posing as IT, and is sent to a real Microsoft page to enter a short code. Because the page is real, it passes every check. Entering the code approves a sign-in on a device the attacker controls.

What they collect is a refresh token, which keeps the session alive after the victim changes their password. That is why Microsoft's guidance is to revoke the user's sign-in sessions rather than rely on a password reset. For weeks, the intruder can read the victim's email and files without tripping a stolen-password alert.

Adding more MFA does not close this gap either, because the sign-in happens on real Microsoft infrastructure, so even a hardware key validates correctly. The fix is to block the device code flow with a Conditional Access policy, then revoke active tokens. Watch for token activity from countries your staff are not in.

Cybersecurity Thought Of the Month

“Strong passwords help, but they are no longer enough to keep accounts and systems safe when used alone.” ~ CISA

Microsoft, after studying its own breach data, found that more than 99.9% of compromised accounts don't have MFA. That single number sits underneath almost everything in this issue.

Most of what hurt businesses recently was not exotic. A login feature was turned against its owner. A reused password opened a door that should have stayed shut. The tools to stop both have existed for years, and they exist inside the Microsoft and Google subscriptions companies already pay for.

That gap, between the protection a business owns and the protection it has switched on, is where we keep landing. Smaller firms are sold the idea that safety comes from buying one more product. This month says otherwise. The businesses that came through clean had turned on multi-factor authentication properly and kept their software patched. They also knew which apps could reach their data.

There is a quieter shift underneath all of this. For a small business, the front door is no longer the office network. It is the identity layer, the set of logins and app permissions that decide who gets to act as your staff for a few minutes. Attackers worked that layer hard these last few months, and they will keep doing it, because it pays and because so many tenants leave it loosely configured.

None of this calls for a bigger budget. What it does call for is attention, and for treating the basics as the main event rather than a box to tick on the way to the next purchase. That is unglamorous advice, but it is also a proven solution.  

If there is one job worth doing before the summer ends, it is sitting down with whoever runs your IT and asking a plain question: what can currently reach our email and files, and who approved it? The answer tends to be longer than anyone expects. Most of the time nobody has looked in months, and a handful of forgotten apps and dormant accounts are quietly holding the keys.

Cybersecurity Events in June

June was a busy month for cybersecurity conversations in the UAE. Across Abu Dhabi and Dubai, the focus was clear: AI-driven threats, cyber resilience, Zero Trust, cloud security, critical infrastructure protection, and the growing role of CISOs in business risk.  

These were just a few major events that showed how cybersecurity in the region is moving beyond tool adoption and becoming a board-level, policy-level, and operational priority.

1. Government Cybersecurity Summit 2026, Abu Dhabi, 9 June
The summit focused on the UAE’s national cybersecurity strategy, AI in cyber defence, cloud and application security, Zero Trust, critical infrastructure protection, and the human factor in government security. It brought together UAE government leaders, regulators, CISOs, cyber vendors, and public-sector security teams, with H.E. Dr. Mohamed Al Kuwaiti listed for the opening keynote on safeguarding the UAE’s digital future.  

2. SHIFT Dubai 2026, Dubai, 17 June

SHIFT Dubai focused on cyber resilience, recovery, AI governance, threat intelligence, and cloud-native security. The event looked closely at how organisations can secure, recover, and scale across multi-cloud environments while preparing for AI-driven threats.

3. 4th Annual 100 CISO Summit & Awards UAE, Dubai, 25 June
This Dubai event centred on “Advancing Cybersecurity Through AI and Strategic Resilience,” with a broader theme around securing the post-AI era, cyber resilience, strategic control, and sovereign risk management. It gathered regional cybersecurity leaders and included discussions on the CISO’s evolving role, practical AI in security, regulatory compliance in the Emirates, critical infrastructure protection, and C-suite cyber resilience.

4. Forbes Middle East Building the Future Summit 2026 2nd Edition, Abu Dhabi, 23-24 June

While not a cybersecurity-only event, the 2nd Edition of the summit became relevant to the cyber conversation because it focused on smart infrastructure, AI, data centers, energy, mobility, and future-ready cities. Dr. Mohamed Al Kuwaiti, Head of Cybersecurity at the UAE Government, also warned at the summit about unsafe AI deployment, weak cyber hygiene, and the risks created when organisations adopt AI without proper standards and safeguards.

Brought to you by Lumora Security

Thanks for reading till the end.  

At Lumora Security, we help SMBs across the UAE find this kind of exposure before an attacker does, whether that is token persistence in a Microsoft 365 tenant or a connected app quietly holding access to your files. Our Essential Security Review maps it in plain language, in a single session, and shows you what to close first.

Never miss an update from The Lumora Security Brief. Subscribe this newsletter on substack or LinkedIn.