Topic

Cloud & Identity

Cloud misconfiguration risk and the identity and single sign-on systems attackers target.

85 articles in this topic

Cloud & Identity

EvilTokens PhaaS: Device Code Phishing Bypasses MFA to Hijack Microsoft 365 Accounts

EvilTokens PhaaS platform has compromised 340+ Microsoft 365 orgs by abusing OAuth device code flow to bypass MFA. Learn how Saudi financial institutions can defend against this active threat.

21 May 2026 5 min
Vulnerabilities

CVE-2026-41096: Windows DNS Client RCE Lets Attackers Hijack Every Endpoint Without a Click

Microsoft's May 2026 Patch Tuesday disclosed CVE-2026-41096, a CVSS 9.8 heap overflow in the Windows DNS Client enabling unauthenticated RCE on every Windows endpoint. Here's what Saudi financial institutions must do now.

21 May 2026 5 min
Vulnerabilities

CVE-2026-0073: Android Zero-Click RCE Lets Attackers Hijack Devices Over Wi-Fi

A CVSS 9.8 zero-click flaw in Android's wireless ADB lets nearby attackers gain full shell access — no tap required. Saudi financial institutions running BYOD and mobile banking must patch immediately.

21 May 2026 6 min
Vulnerabilities

CVE-2026-41103: Critical Microsoft SSO Plugin Flaw Lets Attackers Forge Identities in Jira and Confluence

A CVSS 9.1 flaw in Microsoft's SSO Plugin for Jira and Confluence lets unauthenticated attackers forge identities and gain admin access — bypassing Entra ID entirely. Here's what Saudi CISOs must do now.

20 May 2026 5 min
Supply Chain & Third Party

Mini Shai-Hulud: SAP npm Supply Chain Attack Steals Developer Credentials and CI/CD Secrets

Four official SAP npm packages were compromised with credential-stealing malware in the Mini Shai-Hulud campaign. Here's what Saudi financial CISOs must do to protect their SAP development pipelines.

20 May 2026 5 min
Breaches & Data Leaks

ShinyHunters' 2026 Breach Spree: How One Group Compromised Billions of Records Across Six Sectors

ShinyHunters breached the EU Commission, Medtronic, Rockstar Games, and 8,809 universities in five months — all through OAuth misconfigurations and supply chain trust. Here's what Saudi financial CISOs must do now.

19 May 2026 6 min
Vulnerabilities

CVE-2026-41103: Microsoft SSO Plugin Flaw Gives Attackers Admin Access to Your Jira and Confluence

A CVSS 9.1 flaw in Microsoft's SSO Plugin lets unauthenticated attackers forge SAML responses and gain admin access to Jira and Confluence—exposing compliance data, security findings, and internal documentation across SAMA-regulated institutions.

19 May 2026 5 min
Vulnerabilities

CVE-2026-42897: Exchange OWA Zero-Day Turns a Single Email into Full Browser Hijack

Microsoft confirms active exploitation of CVE-2026-42897, a stored XSS in Exchange OWA that hijacks authenticated sessions via a single crafted email. CISA KEV-listed with a May 29 deadline—Saudi financial institutions must patch within 48 hours to meet SAMA CSCC requirements.

19 May 2026 5 min
Cloud & Identity

Tycoon2FA Rebounds: Device-Code Phishing Bypasses MFA to Hijack Microsoft 365 Accounts

The Tycoon2FA phishing-as-a-service kit has rebounded after a March takedown, now weaponizing OAuth device-code flows to steal Microsoft 365 tokens — rendering traditional MFA useless. Here's what Saudi CISOs need to know.

19 May 2026 6 min
Software Engineering

Grafana GitHub Token Breach: How a CI/CD Misconfiguration Exposed the Codebase Behind Your SOC Dashboards

A single misconfigured GitHub Action let attackers steal Grafana's entire codebase. For Saudi financial institutions relying on Grafana for SOC dashboards, the breach raises urgent questions about CI/CD pipeline security and open-source supply chain risk.

19 May 2026 5 min
Vulnerabilities

Microsoft May 2026 Patch Tuesday: Azure DevOps CVSS 10.0 and Netlogon RCE Demand Immediate Action

Microsoft patched 118 vulnerabilities in May 2026, including CVE-2026-42826 — a perfect CVSS 10.0 Azure DevOps information disclosure flaw exploitable without authentication. Here's what Saudi financial institutions must patch first.

19 May 2026 6 min
Artificial Intelligence

Claw Chain: Four OpenClaw Flaws Let Attackers Hijack AI Agents from Inside the Sandbox

Four chainable vulnerabilities in OpenClaw AI agent platform — dubbed Claw Chain — allow sandbox escape, data theft, and persistent backdoors across 245,000 exposed servers. Critical implications for Saudi financial institutions under SAMA CSCC.

18 May 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality