Topic

Artificial Intelligence

AI in attack, defence and business automation — its risks, opportunities and governance.

43 articles in this topic

Vulnerabilities

Bleeding Llama: Critical Ollama Flaw Leaks AI Server Memory to Unauthenticated Attackers

A critical out-of-bounds read in Ollama's GGUF loader lets attackers siphon API keys, user prompts, and credentials from 300,000+ exposed AI servers — no authentication required.

12 May 2026 6 min
Vulnerabilities

Google Confirms First AI-Generated Zero-Day Exploit by Criminal Hackers

Google's Threat Intelligence Group has confirmed the first-ever detection of a criminal zero-day exploit built with AI assistance — a milestone that reshapes the threat landscape for Saudi financial institutions.

12 May 2026 5 min
Artificial Intelligence

IMF Warns AI-Powered Cyberattacks Threaten Financial Stability: SAMA Banks Must Act

The IMF issued a stark warning: AI-fueled cyberattacks now threaten financial stability at a systemic level. Here's what Saudi banks under SAMA oversight must do before agentic AI threats outpace their defenses.

11 May 2026 5 min
Vulnerabilities

VM2 Sandbox Escape (CVE-2026-44008): Node.js Risk for SAMA Banks

A new vm2 sandbox breakout (CVE-2026-44008, CVSS 9.8) gives attackers a clean path from untrusted JavaScript to the host. Here is what SAMA-regulated banks running Node.js fintech APIs and AI agents must do this week.

9 May 2026 4 min
Artificial Intelligence

IMF Warns AI Cyberattacks Threaten Financial Stability: SAMA Bank Response

The IMF's May 7, 2026 Global Financial Stability assessment identifies AI-fueled cyberattacks as a core systemic risk to the banking sector. Saudi institutions regulated by SAMA CSCC face direct exposure — and must adapt their cyber resilience model now.

9 May 2026 4 min
Artificial Intelligence

FastGPT SSRF (CVE-2026-44286): AI Agent Risk to SAMA Banks

Two new FastGPT vulnerabilities disclosed May 8, 2026 (CVE-2026-44286 unauthenticated SSRF and CVE-2026-44284 MCP toolset bypass) put Saudi banks experimenting with AI agents at risk of internal network pivoting and metadata theft.

9 May 2026 4 min
Vulnerabilities

Langflow CVE-2026-33017 RCE: AI Pipeline Threat to SAMA Banks

An unauthenticated RCE in Langflow's public flow endpoint puts AI orchestration pipelines at Saudi financial institutions in the crosshairs. Here is what SAMA-regulated banks must do this week.

6 May 2026 3 min
Vulnerabilities

MOVEit Automation CVE-2026-4670: Critical Auth Bypass Threatens SAMA Banks

Progress disclosed CVE-2026-4670 — a CVSS 9.8 authentication bypass in MOVEit Automation. Here is what SAMA-regulated banks must do this week to protect interbank file transfers and meet third-party risk obligations.

6 May 2026 4 min
Cloud & Identity

Vercel-Context AI OAuth Breach: Shadow AI Risk Lessons for SAMA Banks

A single Shadow AI tool installed by one Vercel employee triggered an OAuth supply-chain breach exposing API keys, source code, and customer credentials — a textbook warning for SAMA-regulated banks tightening third-party governance under CSCC and ECC.

5 May 2026 5 min
Supply Chain & Third Party

PyTorch Lightning PyPI Hijack: SAMA Bank AI Supply Chain Risk

On April 30, 2026, attackers pushed malicious PyTorch Lightning packages to PyPI to harvest CI/CD secrets. Here is what SAMA-regulated banks must do under CSCC supply chain controls.

4 May 2026 4 min
Vulnerabilities

Ni8mare CVE-2026-21858: n8n RCE Threatens Saudi Bank AI Workflows

A CVSS 10.0 unauthenticated RCE in n8n webhook handling — dubbed Ni8mare — exposes the AI workflow automation platforms many Saudi banks now run for SOC orchestration and DevSecOps pipelines. Here is the SAMA CSCC patch path.

3 May 2026 4 min
Artificial Intelligence

Agentic AI Risks for Saudi Banks: Five Eyes Guidance Decoded

On April 30, 2026, six Five Eyes cyber agencies released joint guidance on agentic AI security risks. Saudi banks scaling autonomous AI must align with SAMA CSCC and NCA ECC before granting agents broader authority.

2 May 2026 4 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality