Tech News
Positive Technologies: companies only have six days to install updates before cybercriminals strike
For five years running, vulnerability exploitation has ranked among the top three most popular attack methods on organizations, according to the study done by Positive Technologies. In 2022–2023, attackers stole confidential data from over 2,700 companies worldwide, exploiting just one vulnerability. This study presents the results of analyzing dark web discussions and statistics on vulnerabilities, along with issues and solutions in organizational vulnerability management.
“Over the past three years, vulnerability exploitation has increasingly attracted cybercriminals, accounting for about one-third of all successful cyberattacks: it accounted for 18% in 2019, and 32% in 2023. On average, an experimental PoC exploit appears within six days of a critical vulnerability disclosure. This PoC, often a code fragment, command list, or program, can be used to attack a vulnerable system. In as few as five days, discussions surrounding this PoC begin on dark web forums, and with them the likelihood of ready-to-use exploits being developed to be used in mass attacks increases,” notes Fedor Chunizhekov, Head of Security Analytics at Positive Technologies.

Positive Technologies has analyzed over 51 million messages across 217 dark web platforms.The most commonly mentioned vulnerabilities are those in WinRAR (CVE-2023-38831), Fortinet products (CVE-2022-40684), and the Java-based Spring Framework (CVE-2022-22965). The vulnerabilities in Linux (CVE-2022-0847) and the Microsoft Support Diagnostic Tool (CVE-2022-30190) have also been objects of hackers’ attention. Messages about remotely exploited vulnerabilities constitute 70% of discussions among cybercriminals on the dark web.
Delaying vulnerability fixes can lead to serious issues for organizations. In May 2023, a mass defacement of websites in the .ru and .рф domains occurred due to the exploitation of the CVE-2022-27228 vulnerability in the 1C-Bitrix web development and content management system. By exploiting the CVE-2023-4966 vulnerability, criminals stole data on 36 million customer accounts from the telecommunications company Xfinity, including password hashes, passwords, and answers to security questions. Ransomware groups have used a flaw in the Microsoft Windows Support Diagnostic Tool (CVE-2022-30190, also known as Follina) to conduct mass ransomware attacks. APT groups have also exploited this vulnerability in their cyberespionage campaigns. Due to the exploitation of a critical vulnerability in Progress MOVEit Transfer (CVE-2023-34362), confidential data from over 2,700 organizations worldwide was compromised.
To prevent the exploitation of vulnerabilities and the occurrence of non-tolerable events, proactive measures must be taken to protect individual services and the entire IT infrastructure. Experts recommend that organizations regularly inventory and classify their assets; prioritize assets based on their importance, as well as the severity and frequency of vulnerabilities; conduct regular security analyses of systems and applications; and monitor the dark web to identify the latest threats. Setting realistic timelines for vulnerability remediation and closely monitoring the patching process are also crucial.
For this, we recommend using modern vulnerability management systems, such as MaxPatrol VM. Using specialized tools allows you to promptly detect and eliminate dangerous vulnerabilities both on the network perimeter and within the infrastructure, with information about current vulnerabilities being delivered to MaxPatrol VM within just 12 hours. Monitoring the status of the target systems and intermediary target systems on a regular basis helps to prevent non-tolerable events associated with the exploitation of vulnerabilities in important assets.
Tech News
FVC and SearchInform Join Forces to Boost Insider Threat Prevention and Data Protection in MENA
FVC, a prominent distributor specialising in innovative technology solutions, is pleased to announce its strategic partnership with SearchInform, a leader in information security and insider threat prevention solutions. Together, they are committed to strengthening organizations’ defenses against data leaks, corporate fraud, human-factor related risks.
K.S. Parag, Managing Director, FVC:
“We are excited to welcome SearchInform to our cybersecurity portfolio. The company offers the most powerful and localized DLP on the MENA market. SearchInform solution stands out from the competition due to a number of advantages. The system can be deployed within a few hours, protects the maximum number of data transfer channels, provides smart content-based blocking for all controlled channels and also use digital watermarks to trace the source of potential leaks. SearchInform DLP supports analysis of data in Arabic and has security policies, tailored for requirements of local organizations, enabling timely detection and prevention of confidential data leaks. The solution leverages AI to monitor atypical data transfer channels, recognize graphic elements, transcribe audio into text, detect attempts to photograph PC screens with smartphones.”
SearchInform offers a range of products, including DCAP, DLP, and SIEM. All the tools are seamlessly integrated. Technical support is provided through a specialist assigned to the company, who has extensive experience thanks to clients from various fields.
Commenting on the Partnership, Artem Volodin, CEO SearchInform MENA, stated:
“We are proud to collaborate with FVC, whose expertise in the Middle Eastern market will strengthen our efforts to combat insider threats and data leaks. The region needs a comprehensive solution that will enable organizations to meet regulatory standards, including SAMA, PDPL, DCC, ECC, UAE Information Assurance (IA) Regulation etc. and global ones, such as GDPR, PCI DSS. SearchInform delivers tools for data protection and risk mitigation across all levels: FileAuditor secures file systems, DLP covers workstations and human risks, Risk Monitor addresses corporate fraud, and SIEM protects IT infrastructure.”
The partners are currently conducting expert training, partner enablement sessions, and are also negotiating the implementation of SearchInform products in local companies.
Tech News
Etihad Salam and AFR-IX telecom Join Forces to Boost Intercontinental Digital Links Across Europe, Middle East, and Africa
Etihad Salam, a premier telecommunications and digital infrastructure company in Saudi Arabia, has entered into a strategic with AFR-IX telecom, an infrastructure and telecom operator and the developer and operator of the Medusa Submarine Cable System.
This collaboration aims to elevate digital connectivity spanning Europe, North Africa, the Middle East, Gulf Cooperation Council (GCC) countries, and Asia. Through this agreement, Etihad Salam becomes the primary landing and interconnection hub for the Medusa system within Saudi Arabia through Aqaba (Jordan), solidifying the Kingdom’s position as a pivotal digital gateway connecting Asia, Europe, and Africa.
The partnership introduces resilient, high-bandwidth, and low-latency pathways from the Mediterranean to the Arabian Peninsula, fostering expansion for hyperscale data centers, cloud service providers, and digital operators throughout the region.
With this partnership, Etihad Salam will deliver terrestrial backhaul services and capacity swapping to seamlessly incorporate Medusa’s network into Saudi Arabia and the broader GCC, and onward to Asia. This initiative represents a significant advancement in Etihad Salam’s global cable strategies and underscores its dedication to Saudi Vision 2030’s goals for digital innovation and economic diversification.
Medusa Submarine Cable System is an 8,760 km undersea cable network linking critical points in the Mediterranean, such as Spain, France, Italy, Malta, Greece, Cyprus, Morocco, Algeria, Tunisia, Libya and Egypt. Engineered for high-speed, reliable data transfer between Europe, North Africa, and the Middle East, Medusa delivers up to 480 Tbps of capacity, serving as a vital conduit for surging intercontinental data flows.
Quote from Salam
“Our partnership with Medusa underscores Salam’s commitment to positioning Saudi Arabia as a central hub for regional connectivity,” stated Amjad Arab, Chief Wholesale and Alliances Officer at Etihad Salam. “By linking the Medusa cable to our robust infrastructure, we’re creating innovative international routes that expand our worldwide presence and meet the surging needs for digital and cloud services in the Kingdom. Through this partnership, we seek to offer enriched connectivity services, experiences and bring the world closer, ultimately empowering businesses to scale and innovative in an increasingly digital landscape.”
Quote from AFR-IX telecom
“We’re excited to collaborate with Etihad Salam, whose expertise and network complement our objective of providing secure, expansive, and high-performance connectivity from the Mediterranean outward,” said Norman Albi, Chief Executive Officer of AFR-IX. “This partnership elevates reliability and coverage for carriers worldwide, driving forward digital advancement across Europe, Africa, and the Middle East.”
Tech News
Infinia Technologies and Satya Retail Launch AI and Blockchain-Powered Retail Transformation at GITEX 2025
- Revolutionizes India’s retail market by empowering merchants with first time real use case of AI and Blockchain
- SAII is a world’s first initiative set to turn millions of low-tech, high-potential neighbourhood retailers into a data-rich, AI-enabled commerce network
Infinia Technologies, a subsidiary of Sirius International Holding, announced a strategic partnership with Satya Retail, a DS Group affiliate, at GITEX Global 2025, the world’s largest technology and innovation event in Dubai. Through this collaboration, Infinia Technologies aims to leverage its advanced AI operating ecosystem to power Satya Retail’s merchant network with AI-driven analytics, blockchain-based invoicing, and digital financial tools, transforming India’s retail landscape.
By combining Infinia Technologies’ AI and blockchain infrastructure with DS Group’s unmatched distribution expertise and Satya Retail’s deep merchant network, this initiative will create an intelligent, scalable, and inclusive retail ecosystem designed to empower millions of small businesses across the country. The official signing took place today at GITEX Global 2025, in the presence of Arif Khan, CEO of Infinia Technologies, along with Ritesh Kumar, Director at DS Group.
The collaboration marks the launch of SAII – Smart AI Integrator, a world’s first initiative that turns millions of low-tech, high-potential neighbourhood retailers into a data-rich, AI-enabled commerce network. Branded as “The Digital Saathi for Merchants,” SAII provides a single platform for all merchant needs; from blockchain-based e-invoicing and micro-financing to insurance, hyperlocal advertising with two-way data transfer for merchants and vendor network.
For the first time, India’s retailers will receive access to powerful digital capabilities at scale through SAII. It will help merchants operate smarter, improve efficiency, and build deeper partnerships across the supply chain.
Commenting on the announcement, Arif Khan, CEO of Infinia Technologies, said: “This partnership represents a defining moment in how AI and Blockchain can drive real-world impact. This collaboration will positively accelerate India’s digital economy. Through SAII, we’re enabling millions of India’s retailers to access intelligent tools and digital services that were once out of reach, while advancing our mission to take advanced AI from Abu Dhabi to the world. This is only the beginning; we plan to extend the SAII model across Asia, the Middle East, and North Africa, with more projects to be announced soon.”

Ritesh Kumar, Director at DS Group added: “Our collaboration with Infinia Technologies brings together the strength of our retail network and their AI innovation to empower small businesses across India. SAII will help local merchants modernize their operations, access financial and digital tools seamlessly, and become part of a larger connected commerce ecosystem. This is a major step toward building a more inclusive and technology-driven retail economy.”
-
Tech News1 year agoDenodo Bolsters Executive Team by Hiring Christophe Culine as its Chief Revenue Officer
-
VAR6 months agoMicrosoft Launches New Surface Copilot+ PCs for Business
-
Tech Interviews2 years agoNavigating the Cybersecurity Landscape in Hybrid Work Environments
-
Tech News3 months agoNothing Launches flagship Nothing Phone (3) and Headphone (1) in theme with the Iconic Museum of the Future in Dubai
-
Tech News2 years agoBrighton College Abu Dhabi and Brighton College Al Ain Donate 954 IT Devices in Support of ‘Donate Your Own Device’ Campaign
-
Editorial11 months agoCelebrating UAE National Day: A Legacy of Leadership and Technological Innovation
-
VAR1 year agoSamsung Galaxy Z Fold6 vs Google Pixel 9 Pro Fold: Clash Of The Folding Phenoms
-
Cover Story8 months agoUnifonic Leading the Future of AI-Driven Customer Engagement


