Topic

Cloud & Identity

Cloud misconfiguration risk and the identity and single sign-on systems attackers target.

85 articles in this topic

Vulnerabilities

CVE-2026-32202: APT28 Exploits Zero-Click Windows Flaw to Steal Credentials Without User Interaction

An incomplete Microsoft patch left a zero-click credential theft vector wide open — and APT28 is already exploiting it. Here's what Saudi financial institutions need to do right now.

17 May 2026 6 min
Ransomware

Vishing and SSO Abuse: How Cybercrime Groups Are Executing Rapid SaaS Extortion in Minutes

Cybercrime groups like ShinyHunters are combining AI-powered vishing calls with SSO exploitation to breach SaaS environments in under 45 minutes. Learn how Saudi financial institutions can defend against this rapidly evolving threat.

17 May 2026 5 min
Vulnerabilities

CVE-2026-20182: Cisco SD-WAN Zero-Day Gives Attackers Full Admin Access Without Credentials

A CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN Controller is under active exploitation, letting attackers seize full admin control of enterprise network fabrics without any credentials.

16 May 2026 4 min
Breaches & Data Leaks

The Vercel Breach: How One Forgotten OAuth Token Exposed an Entire Platform

A single employee's forgotten trial of an AI tool handed attackers the keys to Vercel's kingdom. Here's what Saudi financial institutions must learn about OAuth sprawl and shadow AI before it happens to them.

16 May 2026 6 min
Malware & Threat Actors

MuddyWater's False Flag: Iranian APT Hides Espionage Behind Chaos Ransomware via Microsoft Teams

Iranian state-sponsored group MuddyWater weaponized Microsoft Teams screen-sharing to steal credentials and bypass MFA, planting Chaos ransomware artifacts as a decoy to hide espionage targeting banks and critical infrastructure.

16 May 2026 5 min
Cloud & Identity

CalPhishing: How Hackers Steal M365 Sessions Through Outlook Calendar Invites

A new phishing technique called CalPhishing weaponizes Outlook calendar invites to bypass MFA and steal Microsoft 365 session tokens — with hundreds of organizations compromised daily. Here's what Saudi CISOs need to know.

16 May 2026 6 min
Vulnerabilities

CVE-2026-32202: APT28 Exploits Zero-Click Windows Shell Flaw to Steal NTLM Credentials

Russian APT28 weaponizes an incomplete Windows Shell patch to silently harvest NTLM hashes — no clicks required. Here's what Saudi CISOs must do now.

15 May 2026 5 min
Network & Infrastructure

CVE-2026-0300: Palo Alto PAN-OS Zero-Day Gives Attackers Root on Your Perimeter Firewall

A critical buffer overflow in Palo Alto PAN-OS User-ID Authentication Portal is being exploited in the wild—giving attackers root-level code execution on PA-Series and VM-Series firewalls without any credentials.

14 May 2026 5 min
Vulnerabilities

Critical SAP Commerce Cloud and S/4HANA Flaws CVE-2026-34263 & CVE-2026-34260: CVSS 9.6 Threats to Saudi ERP Infrastructure

SAP's May 2026 Patch Day fixes two critical CVSS 9.6 vulnerabilities — an unauthenticated RCE in Commerce Cloud and a SQL injection in S/4HANA. Here's why Saudi financial institutions running SAP must patch immediately.

13 May 2026 5 min
Breaches & Data Leaks

Cushman & Wakefield Vishing Breach: How One Phone Call Exposed 500K Salesforce Records

A single vishing call gave ShinyHunters access to 500,000 Salesforce records at Cushman & Wakefield. Two ransomware groups now claim the data. Here's what went wrong and why Saudi institutions must act now.

13 May 2026 6 min
Supply Chain & Third Party

Mini Shai-Hulud Worm Hits TanStack and 170+ Packages: The Largest npm Supply Chain Attack of 2026

TeamPCP weaponized GitHub Actions OIDC tokens to publish 401 malicious package versions across TanStack, Mistral AI, and UiPath — stealing credentials from cloud providers, crypto wallets, and CI systems. Here's what happened and how to respond.

13 May 2026 5 min
Software Engineering

RubyGems Shuts Down Signups After BufferZoneCorp Supply Chain Attack Hits CI/CD Pipelines

RubyGems suspended new registrations after hundreds of malicious sleeper packages drained AWS keys, SSH credentials, and GitHub tokens from CI/CD pipelines — a wake-up call for every organization running open-source dependencies.

13 May 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality