Product1 distinct publisher2 min readUpdated
Exploit windows in the Gulf have fallen from days to hours, Check Point says. That breaks patch schedules and phishing training written for a slower adversary, whatever the AI labelling.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
Nine attempts a second [1] is not a figure a duty roster meets directly; it is a filtering budget. Analysts working in shifts have held the line so far, by the council's own account [15], which means the automation in front of them decides what a human ever sees. Escalation thresholds tuned when the inbound rate was a quarter of the current one are now, in practice, a sampling rate rather than a queue.
The phishing side decays quietly. Awareness training teaches staff to notice the tells of a hand-written lure, and the council describes mail that is composed by a model, alongside automated flaw hunting and malware assembly [4]. Palo Alto Networks reports the same drift across the Gulf toward AI-assisted scams, password theft and fake corporate sites [12]. A control that depends on the attacker being careless has a shelf life.
The reporting also contains its own brake. The 800,000 figure in the August 10 statement is the figure Al Kuwaiti had already given in April [4], so four months of public record show a plateau rather than a climb. And the July intrusions at financial firms, assembled from phishing, software flaws and malicious code, were contained with no disruption to services [10]. The attempt rate is where it was in spring; the disruption column is still empty.
Vibin Shaju of Trellix calls the state actors' use of the technology a practical force multiplier rather than a fully autonomous weapon [9], which is the operationally useful framing. Multipliers change tempo and volume, not intent, and intent is where defenders get planning leverage. Haider Pasha of Palo Alto Networks names telecoms, energy and government services as the most tempting targets precisely because taking them down spreads damage past the first victim [11]. That is a target list, and lists can be pre-staged against.
Set against the speed story: the Justice Department's August 18 indictment of 17 Iranians covers a campaign running since 2013 that prosecutors say took research and designs from 144 U.S. universities and 42 companies [6]. Thirteen years [3]. The expensive part of that case was persistence, not tempo. A program re-pointed entirely at the hours-scale window [5] leaves the slow campaign funded by nobody.
The camera intrusions are the detail worth keeping. Check Point traced attempts on internet-connected cameras in the UAE, Qatar, Kuwait and Bahrain to Iranian operators starting February 28, and assessed that they wanted footage to correct missile targeting and estimate damage after strikes [14]. The asset that mattered there sat outside the data centre, and it was not the kind of thing a patch calendar is built around.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
The UAE Cyber Security Council said on August 10 that it had detected and contained coordinated cyberattacks on the aviation, energy and education sectors since February, when fighting began between Iran, Israel and the U.S.
The council said AI is writing the hackers' phishing emails, hunting for flaws in software and building malicious programs faster than the teams guarding those systems can close the gaps.
In July, national teams detected and contained attacks on financial firms involving phishing, software flaws and malicious code, with no disruption to services; the council said the attackers used AI to make the methods more complex.
The council said hackers have made about 800,000 attempts a day since February, four times the prewar level.
Analysts working in shifts have held the line so far.
In April, Cyber Security Council head Mohamed Al Kuwaiti said there were about 800,000 hacking attempts a day on the UAE, up from as many as 200,000 before the war.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single outlet, attributed assertions, no primary data
Every claim traces to one Rest of World report. The strongest anchor is a dated U.S. indictment; the rest are self-reported government statements and three vendor-executive assessments with no methodology, telemetry scope or technical artefacts disclosed. The pivotal operational number — days-to-hours exploitation — rests on one hedged quote, and the headline volume metric leaves 'attempt' undefined.
Concrete incidents and a launched national programme; effects unmeasured
There are dated, specific events on both sides: four disclosed incident waves between February and August, a cross-Gulf camera intrusion campaign attributed by a vendor, a U.S. indictment, and a launched sovereign build programme (Cyber Factory, May 12, with CPX Holding) plus a national operations centre. What is absent is any measured outcome — no patch-cycle change, no capability milestone, no spend figure, and containment claims come from the defender.
AI framing outruns the supporting evidence
The strong framing — AI at every step, defenders being outpaced, 'machine-to-machine cyber conflict' — is asserted by a government agency, a think tank and a vendor without technical substantiation, and the quadrupling headline reuses a figure already public in April. The article does partially self-correct: Trellix explicitly limits AI to a force multiplier with humans still choosing targets and timing, and the exploit-window claim is hedged to 'in some cases'. That internal hedging keeps the gap moderate rather than severe.
Defender-reported metrics plus three commercially interested vendors
Nearly all sourcing has a stake in the conclusion. The Cyber Security Council reports both the threat volume and its own containment success while promoting a sovereign build programme with its national partner CPX Holding, whose CEO is quoted at the launch. The escalation and speed claims come from Check Point, Palo Alto Networks and Trellix, all of which sell regional security products and services. None of these interests is disclosed in the piece.
Directionally plausible, quantitatively unreliable
Confidence is limited by single-publisher sourcing, self-reported and stale metrics, and undisclosed commercial interests. The qualitative direction — faster exploitation, AI-assisted phishing and tooling, Gulf infrastructure under sustained probing — is consistently reported across several independent-of-each-other named sources within the article, which supports moderate confidence in the trend but not in any number.
product
The hearing date is the case: Disney wants a judge before the FCC starts the clock1 distinct publisher
invest
556 wallets, 78,496 bets: Polymarket's insider problem now has a denominator1 distinct publisher
invest
Washington licenses private hacking, and hands the contractor the liability1 distinct publisher
invest
Seoul's economists want capital allocated for survivability, not export volume1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 24, 2026