Topic
Artificial Intelligence
AI in attack, defence and business automation — its risks, opportunities and governance.
43 articles in this topic
PyTorch Lightning PyPI Hack: Shai-Hulud Worm Hits Saudi Bank AI
On April 30, 2026, PyTorch Lightning 2.6.2 and 2.6.3 were compromised by a Mini Shai-Hulud worm stealing credentials and poisoning GitHub. Saudi banks running AI/ML workloads face an urgent SAMA CSCC TPRM event.
Artificial IntelligenceShadow AI: The Invisible Threat Inside Saudi Banks That No SAMA Audit Will Catch
Three in four CISOs globally have already found unsanctioned AI tools running inside their organizations. In Saudi financial institutions, that means confidential customer data, earnings projections, and audit records may be flowing into AI platforms with no DPA, no access control, and no SAMA oversight.
Artificial IntelligenceClawHavoc: How 1,184 Malicious AI Agent Skills Are Harvesting Credentials from Financial Sector Employees
Attackers poisoned OpenClaw's AI agent marketplace with over 1,184 malicious skills deploying the AMOS credential stealer. 12% of the entire registry was compromised — and Saudi financial institutions adopting agentic AI tools are directly in the crosshairs.
VulnerabilitiesCVE-2026-39987: Hackers Exploit Marimo AI Notebook to Deploy Blockchain Backdoor via Hugging Face
A CVSS 9.3 RCE flaw in the Marimo AI notebook tool was weaponized within 10 hours of disclosure, delivering NKAbuse — a Go-based backdoor using blockchain C2 — via a typosquatted Hugging Face Space. Saudi financial institutions adopting AI tooling must act now.
Phishing & FraudThe Deepfake Threat Saudi Financial CISOs Can No Longer Ignore: AI Voice Cloning, CEO Fraud, and KYC Bypass in 2026
A darknet actor is selling real-time deepfake tools that defeat bank KYC in seconds. Across the GCC, fraudsters are impersonating CEOs with AI-cloned voices to authorize wire transfers. Saudi financial institutions need a response framework — now.
Cloud & IdentityEvilToken: The AI-Powered Phishing Kit That Defeats MFA and Targets Saudi Financial M365 Environments
A new phishing-as-a-service toolkit called EvilToken is bypassing MFA at scale using AI-generated lures and OAuth device code abuse, targeting M365 users across the UAE and beyond — a direct risk to Saudi financial institutions.
Phishing & FraudAI-Generated Phishing Is Now the #1 Email Threat of 2026 — A Tactical Response Guide for Saudi Financial CISOs
AI-generated phishing attacks have surged 1,265% since 2023 and now account for 82% of all phishing emails. For Saudi financial institutions under SAMA and NCA oversight, the stakes — and the compliance obligations — have never been higher.
Artificial IntelligencePushpaganda: AI-Generated Fake News in Google Discover Is Now Targeting Your Employees' Phones
HUMAN Security uncovered Pushpaganda — 240M poisoned ad requests exploiting Google Discover to deliver scareware via Android push notifications. Here's what every Saudi financial CISO must act on now.
Cloud & IdentityScattered Spider Returns: AI-Powered Vishing and Azure AD Hijacking Now Target Saudi Financial Institutions
Scattered Spider has pivoted from retail and tech to financial institutions, deploying AI-powered voice phishing and Azure AD federation backdoors to bypass MFA. Saudi banks under SAMA supervision face immediate exposure — here is what your security team must do now.
Artificial IntelligenceAgentic AI: 2026's #1 Cyber Threat and What Saudi Banks Must Do Now
Autonomous AI agents can plan, adapt, and persist inside your environment indefinitely. With 80%+ of Saudi organizations racing to adopt AI tools, the attack surface is expanding faster than most defenses can keep up.
VulnerabilitiesCVE-2026-39987: Marimo's Pre-Auth RCE Was Weaponized in Under 10 Hours — What Saudi AI Analytics Teams Must Do Now
A critical pre-authenticated RCE in Marimo (CVE-2026-39987, CVSS 9.3) was actively exploited just 9 hours 41 minutes after public disclosure — before any PoC existed. Saudi financial institutions using AI analytics pipelines must act immediately.
Artificial IntelligenceLiteLLM Supply Chain Attack: How TeamPCP and Lapsus$ Breached 500,000 Machines Through an AI Library Saudi Banks May Be Running
A 40-minute window was all it took. TeamPCP poisoned LiteLLM's PyPI packages and set off a cascade that compromised 500,000 machines, 1,000+ SaaS environments, and handed Lapsus$ 4TB of data from AI startup Mercor.