Topic
Breaches & Data Leaks
Real-world intrusions and data leaks — how they started and the lessons for security teams.
66 articles in this topic
TeamPCP's Trivy Supply Chain Attack Exposed 30 EU Entities — Is Your CI/CD Pipeline the Next Target?
A single compromised open-source tool gave attackers access to AWS secrets across 1,000+ SaaS environments. Saudi financial institutions running similar CI/CD pipelines face the same exposure.
Cloud & IdentityShinyHunters' 2026 Vishing Campaign: How Attackers Are Hijacking Okta SSO to Breach Bank-Grade SaaS Platforms
ShinyHunters used real-time voice phishing to steal Okta SSO credentials and MFA codes, then pivoted into Zendesk, Salesforce, and other SaaS platforms to steal millions of support tickets. Saudi banks running the same SaaS stack are directly exposed.
VulnerabilitiesF5 BIG-IP APM CVE-2025-53521: Unauthenticated RCE Puts 14,000+ Exposed Instances at Risk — What Saudi Banks Must Do Now
A critical F5 BIG-IP APM flaw reclassified from DoS to unauthenticated RCE is being actively exploited — with 14,000+ instances still exposed globally. Here is what Saudi financial institutions must patch immediately.
Malware & Threat ActorsDPRK Steals $285M via Drift Protocol: What Saudi Financial Firms Must Know
North Korean threat actors linked to the Lazarus Group stole $285M from Drift Protocol using a legitimate Solana feature as a weapon — here's what this means for Saudi financial institutions.
Breaches & Data LeaksShinyHunters Salesforce Campaign Hits 400+ Firms: What Saudi Banks Must Do Now
ShinyHunters has breached over 400 organizations through Salesforce Experience Cloud misconfigurations, stealing millions of records. Saudi financial institutions relying on Salesforce must act immediately to lock down guest user permissions and protect customer data.
Cloud & IdentityReact2Shell Exploits Breach 766 Hosts: Massive Credential Theft Campaign Targets Web Apps
A large-scale credential harvesting operation tracked as UAT-10608 is exploiting the React2Shell vulnerability to breach Next.js applications and steal AWS secrets, SSH keys, and database credentials at scale.