Topic
Breaches & Data Leaks
Real-world intrusions and data leaks — how they started and the lessons for security teams.
66 articles in this topic
CPUID Supply Chain Breach: How STX RAT Hijacked CPU-Z & HWMonitor — A Wake-Up Call for Saudi Data Centers
On April 9, 2026, attackers quietly replaced CPUID's legitimate CPU-Z and HWMonitor downloads with trojanized packages delivering STX RAT — a full-featured remote access trojan. If your data center team downloaded hardware monitoring tools that week, read this now.
Breaches & Data LeaksMr. Raccoon's Adobe Breach: How One BPO Contractor Exposed 13M Support Tickets
A single malware-infected BPO contractor handed threat actor "Mr. Raccoon" 13 million Adobe support tickets. Here is what Saudi financial institutions relying on outsourced IT support must do right now.
Malware & Threat ActorsNorth Korea Stole $285M in 12 Minutes: The DPRK Infiltration Playbook Every Saudi CISO Must Study
North Korean hackers UNC4736 spent six months posing as a legitimate trading firm before draining $285M in 12 minutes. Saudi CISOs must understand this playbook—it maps directly to SAMA CSCC third-party and insider-threat domains.
Breaches & Data LeaksThe Lloyds API Glitch That Exposed 450,000 Banking Customers: What Saudi Banks Must Learn Now
On March 12, 2026, a single faulty API update at Lloyds Banking Group exposed the transaction data of 447,936 customers. For Saudi banks, this is not a distant cautionary tale — it is a blueprint of what happens when API security is treated as an afterthought.
Breaches & Data LeaksShinyHunters Breaches the European Commission: 350GB Exposed and What Saudi Banks Must Learn Now
ShinyHunters breached the European Commission's Europa.eu, exfiltrating 350GB including databases and contracts. Saudi financial institutions must act now on identity controls, data governance, and PDPL breach notification readiness.
Cloud & IdentityHow Social Engineering Hijacks Okta to Breach Every SaaS You Use
A single phone call compromised Hims & Hers' Okta SSO in Feb 2026, exposing 1.8M customer support tickets. Saudi banks using SSO face the same risk — here's how to defend.
Software EngineeringTrivy Supply Chain Attack Breaches European Commission — Why Saudi Banks Must Audit Their DevSecOps Tools
A compromised build of Trivy — one of the most trusted open-source vulnerability scanners — gave TeamPCP a backdoor into the European Commission's AWS infrastructure. If your DevSecOps pipeline trusts open-source tools implicitly, your institution could be next.
Cloud & IdentityEverest Ransomware Steals 910GB from Nissan via Stale FTP Credentials — A Third-Party Risk Wake-Up Call for Saudi Banks
Everest ransomware exfiltrated 910GB of Nissan customer and loan data through a vendor FTP server with 3-year-old credentials and no MFA. Here's what Saudi financial institutions must learn about third-party risk management.
VulnerabilitiesProgress ShareFile Pre-Auth RCE Chain: 30,000 Servers Exposed and Saudi Banks Must Patch Now
Two chained ShareFile flaws give attackers full server control without credentials. With 30,000 instances exposed globally, Saudi financial institutions running on-premise ShareFile must act before exploitation campaigns begin.
Artificial IntelligenceLiteLLM Supply Chain Attack: How TeamPCP and Lapsus$ Breached 500,000 Machines Through an AI Library Saudi Banks May Be Running
A 40-minute window was all it took. TeamPCP poisoned LiteLLM's PyPI packages and set off a cascade that compromised 500,000 machines, 1,000+ SaaS environments, and handed Lapsus$ 4TB of data from AI startup Mercor.
Breaches & Data LeaksDrift Protocol's $285M Hack: Why Saudi Financial Institutions Must Rethink DeFi Exposure Now
North Korean-linked attackers executed a $285M exploit against Solana's Drift Protocol using fake tokens, oracle manipulation, and governance hijacking — the largest DeFi hack of 2026. Here's why Saudi FIs must reassess their digital asset risk posture.
Breaches & Data LeaksShinyHunters Claims 3M+ Cisco Salesforce Records: The CRM Security Crisis Saudi Banks Must Act On Now
ShinyHunters claims 3 million Cisco Salesforce records stolen — FBI, NASA, and government agency data included. Saudi financial institutions using Cisco products face cascading vendor risk right now.