Topic
Artificial Intelligence
AI in attack, defence and business automation — its risks, opportunities and governance.
43 articles in this topic
Bleeding Llama: Critical Ollama Flaw Leaks AI Server Memory to Unauthenticated Attackers
A critical out-of-bounds read in Ollama's GGUF loader lets attackers siphon API keys, user prompts, and credentials from 300,000+ exposed AI servers — no authentication required.
VulnerabilitiesGoogle Confirms First AI-Generated Zero-Day Exploit by Criminal Hackers
Google's Threat Intelligence Group has confirmed the first-ever detection of a criminal zero-day exploit built with AI assistance — a milestone that reshapes the threat landscape for Saudi financial institutions.
Artificial IntelligenceIMF Warns AI-Powered Cyberattacks Threaten Financial Stability: SAMA Banks Must Act
The IMF issued a stark warning: AI-fueled cyberattacks now threaten financial stability at a systemic level. Here's what Saudi banks under SAMA oversight must do before agentic AI threats outpace their defenses.
VulnerabilitiesVM2 Sandbox Escape (CVE-2026-44008): Node.js Risk for SAMA Banks
A new vm2 sandbox breakout (CVE-2026-44008, CVSS 9.8) gives attackers a clean path from untrusted JavaScript to the host. Here is what SAMA-regulated banks running Node.js fintech APIs and AI agents must do this week.
Artificial IntelligenceIMF Warns AI Cyberattacks Threaten Financial Stability: SAMA Bank Response
The IMF's May 7, 2026 Global Financial Stability assessment identifies AI-fueled cyberattacks as a core systemic risk to the banking sector. Saudi institutions regulated by SAMA CSCC face direct exposure — and must adapt their cyber resilience model now.
Artificial IntelligenceFastGPT SSRF (CVE-2026-44286): AI Agent Risk to SAMA Banks
Two new FastGPT vulnerabilities disclosed May 8, 2026 (CVE-2026-44286 unauthenticated SSRF and CVE-2026-44284 MCP toolset bypass) put Saudi banks experimenting with AI agents at risk of internal network pivoting and metadata theft.
VulnerabilitiesLangflow CVE-2026-33017 RCE: AI Pipeline Threat to SAMA Banks
An unauthenticated RCE in Langflow's public flow endpoint puts AI orchestration pipelines at Saudi financial institutions in the crosshairs. Here is what SAMA-regulated banks must do this week.
VulnerabilitiesMOVEit Automation CVE-2026-4670: Critical Auth Bypass Threatens SAMA Banks
Progress disclosed CVE-2026-4670 — a CVSS 9.8 authentication bypass in MOVEit Automation. Here is what SAMA-regulated banks must do this week to protect interbank file transfers and meet third-party risk obligations.
Cloud & IdentityVercel-Context AI OAuth Breach: Shadow AI Risk Lessons for SAMA Banks
A single Shadow AI tool installed by one Vercel employee triggered an OAuth supply-chain breach exposing API keys, source code, and customer credentials — a textbook warning for SAMA-regulated banks tightening third-party governance under CSCC and ECC.
Supply Chain & Third PartyPyTorch Lightning PyPI Hijack: SAMA Bank AI Supply Chain Risk
On April 30, 2026, attackers pushed malicious PyTorch Lightning packages to PyPI to harvest CI/CD secrets. Here is what SAMA-regulated banks must do under CSCC supply chain controls.
VulnerabilitiesNi8mare CVE-2026-21858: n8n RCE Threatens Saudi Bank AI Workflows
A CVSS 10.0 unauthenticated RCE in n8n webhook handling — dubbed Ni8mare — exposes the AI workflow automation platforms many Saudi banks now run for SOC orchestration and DevSecOps pipelines. Here is the SAMA CSCC patch path.
Artificial IntelligenceAgentic AI Risks for Saudi Banks: Five Eyes Guidance Decoded
On April 30, 2026, six Five Eyes cyber agencies released joint guidance on agentic AI security risks. Saudi banks scaling autonomous AI must align with SAMA CSCC and NCA ECC before granting agents broader authority.