Three Hundred Organizations in the Gulf episode artwork

EPISODE · Jun 1, 2026

Three Hundred Organizations in the Gulf

from CyberPulse · host Tushar Vartak

A state intelligence-linked threat actor is conducting an active password-spraying campaign against Microsoft 365 environments across the Gulf, impacting 300+ organizations in three distinct attack waves on March 3, 13, and 23 — each separated by exactly 10 days. Targets include government, municipalities, technology, transportation, and energy. A state-sponsored actor deployed BRICKSTORM kernel implants and passive backdoors targeting VMware vSphere/vCenter/ESXi for long-term espionage below the guest OS layer. The Coruna iOS exploit kit was confirmed to contain an updated kernel exploit from the Operation Triangulation campaign. Apple expanded DarkSword patches to iOS 18.7.7 for older devices. Malicious npm packages masquerading as Strapi community plugins were identified across four sock puppet accounts.

Episode metadata supplied by the publisher feed · Published Jun 1, 2026

Embed this episode

NOW PLAYING

Three Hundred Organizations in the Gulf

0:00 0:00

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this CyberPulse episode published?

This episode was published on June 1, 2026.

Can I download this CyberPulse episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!