Topic

Breaches & Data Leaks

Real-world intrusions and data leaks — how they started and the lessons for security teams.

66 articles in this topic

Malware & Threat Actors

CPUID Supply Chain Breach: How STX RAT Hijacked CPU-Z & HWMonitor — A Wake-Up Call for Saudi Data Centers

On April 9, 2026, attackers quietly replaced CPUID's legitimate CPU-Z and HWMonitor downloads with trojanized packages delivering STX RAT — a full-featured remote access trojan. If your data center team downloaded hardware monitoring tools that week, read this now.

14 Apr 2026 5 min
Breaches & Data Leaks

Mr. Raccoon's Adobe Breach: How One BPO Contractor Exposed 13M Support Tickets

A single malware-infected BPO contractor handed threat actor "Mr. Raccoon" 13 million Adobe support tickets. Here is what Saudi financial institutions relying on outsourced IT support must do right now.

7 Apr 2026 6 min
Malware & Threat Actors

North Korea Stole $285M in 12 Minutes: The DPRK Infiltration Playbook Every Saudi CISO Must Study

North Korean hackers UNC4736 spent six months posing as a legitimate trading firm before draining $285M in 12 minutes. Saudi CISOs must understand this playbook—it maps directly to SAMA CSCC third-party and insider-threat domains.

7 Apr 2026 5 min
Breaches & Data Leaks

The Lloyds API Glitch That Exposed 450,000 Banking Customers: What Saudi Banks Must Learn Now

On March 12, 2026, a single faulty API update at Lloyds Banking Group exposed the transaction data of 447,936 customers. For Saudi banks, this is not a distant cautionary tale — it is a blueprint of what happens when API security is treated as an afterthought.

7 Apr 2026 6 min
Breaches & Data Leaks

ShinyHunters Breaches the European Commission: 350GB Exposed and What Saudi Banks Must Learn Now

ShinyHunters breached the European Commission's Europa.eu, exfiltrating 350GB including databases and contracts. Saudi financial institutions must act now on identity controls, data governance, and PDPL breach notification readiness.

6 Apr 2026 4 min
Cloud & Identity

How Social Engineering Hijacks Okta to Breach Every SaaS You Use

A single phone call compromised Hims & Hers' Okta SSO in Feb 2026, exposing 1.8M customer support tickets. Saudi banks using SSO face the same risk — here's how to defend.

6 Apr 2026 5 min
Software Engineering

Trivy Supply Chain Attack Breaches European Commission — Why Saudi Banks Must Audit Their DevSecOps Tools

A compromised build of Trivy — one of the most trusted open-source vulnerability scanners — gave TeamPCP a backdoor into the European Commission's AWS infrastructure. If your DevSecOps pipeline trusts open-source tools implicitly, your institution could be next.

6 Apr 2026 5 min
Cloud & Identity

Everest Ransomware Steals 910GB from Nissan via Stale FTP Credentials — A Third-Party Risk Wake-Up Call for Saudi Banks

Everest ransomware exfiltrated 910GB of Nissan customer and loan data through a vendor FTP server with 3-year-old credentials and no MFA. Here's what Saudi financial institutions must learn about third-party risk management.

6 Apr 2026 5 min
Vulnerabilities

Progress ShareFile Pre-Auth RCE Chain: 30,000 Servers Exposed and Saudi Banks Must Patch Now

Two chained ShareFile flaws give attackers full server control without credentials. With 30,000 instances exposed globally, Saudi financial institutions running on-premise ShareFile must act before exploitation campaigns begin.

6 Apr 2026 6 min
Artificial Intelligence

LiteLLM Supply Chain Attack: How TeamPCP and Lapsus$ Breached 500,000 Machines Through an AI Library Saudi Banks May Be Running

A 40-minute window was all it took. TeamPCP poisoned LiteLLM's PyPI packages and set off a cascade that compromised 500,000 machines, 1,000+ SaaS environments, and handed Lapsus$ 4TB of data from AI startup Mercor.

5 Apr 2026 6 min
Breaches & Data Leaks

Drift Protocol's $285M Hack: Why Saudi Financial Institutions Must Rethink DeFi Exposure Now

North Korean-linked attackers executed a $285M exploit against Solana's Drift Protocol using fake tokens, oracle manipulation, and governance hijacking — the largest DeFi hack of 2026. Here's why Saudi FIs must reassess their digital asset risk posture.

5 Apr 2026 7 min
Breaches & Data Leaks

ShinyHunters Claims 3M+ Cisco Salesforce Records: The CRM Security Crisis Saudi Banks Must Act On Now

ShinyHunters claims 3 million Cisco Salesforce records stolen — FBI, NASA, and government agency data included. Saudi financial institutions using Cisco products face cascading vendor risk right now.

4 Apr 2026 6 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality