Topic
Cloud & Identity
Cloud misconfiguration risk and the identity and single sign-on systems attackers target.
85 articles in this topic
Fortinet 2026 Threat Report: 389% Ransomware Surge, 1.7B Stolen Credentials, and What It Means for Saudi Finance
Fortinet's FortiGuard Labs confirms 7,831 ransomware victims in 2025 — a 389% spike — fueled by AI-assisted tools and 1.7 billion stolen credentials on the dark web. Saudi financial institutions face unique exposure.
VulnerabilitiesSAP S/4HANA and Commerce Cloud Hit with CVSS 9.6 Critical Flaws — Patch Now Before Attackers Move First
SAP released 15 security patches including two CVSS 9.6 critical flaws in S/4HANA and Commerce Cloud. Here's why Saudi banks and financial institutions running SAP must act within hours, not days.
VulnerabilitiesCVE-2026-32202: APT28 Exploits Zero-Click Windows Flaw to Steal NTLM Credentials — CISA Deadline Hits Today
A zero-click Windows shortcut flaw lets APT28 steal NTLM credentials without user interaction. Microsoft's incomplete patch left millions exposed — and CISA's remediation deadline expires today.
VulnerabilitiesIvanti EPMM Zero-Day CVE-2026-6973: RCE Hits Enterprise Mobile Management
Ivanti's Endpoint Manager Mobile zero-day CVE-2026-6973 is under active exploitation. Attackers chain stolen credentials with an input validation flaw to achieve full RCE on EPMM appliances managing thousands of corporate devices.
Supply Chain & Third PartyTanStack NPM Supply Chain Attack CVE-2026-45321: Trusted Packages Weaponized to Steal Developer Secrets
A self-spreading worm hijacked TanStack's trusted CI/CD pipeline, publishing 84 malicious npm packages that exfiltrated GitHub tokens, SSH keys, and cloud credentials. CVSS 9.6 — here's what SAMA-regulated institutions need to check immediately.
Cloud & IdentityFake OpenAI Model on Hugging Face Steals Credentials: AI Supply Chain Risk for Financial Institutions
A fake OpenAI model on Hugging Face reached 244K downloads before removal, deploying a Rust infostealer that harvested browser credentials and SSH keys. Here's what Saudi financial institutions must do now.
VulnerabilitiesBleeding Llama: Critical Ollama Flaw Leaks AI Server Memory to Unauthenticated Attackers
A critical out-of-bounds read in Ollama's GGUF loader lets attackers siphon API keys, user prompts, and credentials from 300,000+ exposed AI servers — no authentication required.
VulnerabilitiesDirty Frag: Linux Kernel Zero-Day Grants Root Access Across Cloud and Banking Infrastructure
Two chained Linux kernel flaws — CVE-2026-43284 and CVE-2026-43500 — let any unprivileged user reach root. Active exploitation confirmed. Here's what SAMA-regulated institutions must do now.
Cloud & IdentityMicrosoft Edge Stores Passwords in Plaintext RAM: Enterprise Risk for SAMA Banks
Microsoft confirms Edge loads every saved password into plaintext RAM at launch — by design. For SAMA-regulated banks, this turns every endpoint into a credential extraction target.
Breaches & Data LeaksShinyHunters Vishing-to-Salesforce Attack Chain: What SAMA Banks Must Know
ShinyHunters breached 500K+ Salesforce records via vishing and OAuth hijacking. Saudi financial institutions face the same attack pattern — here's how to defend under SAMA CSCC and NCA ECC.
Malware & Threat ActorsTCLBANKER Trojan Spreads via WhatsApp to Target 59 Financial Platforms
A new banking trojan called TCLBANKER hijacks WhatsApp and Outlook to spread across 3,000 contacts per victim, targeting 59 financial platforms with full-screen credential overlays.
VulnerabilitiesD-Link CVE-2026-0625 Zero-Day: DNS Hijack Risk for SAMA Banks
An unauthenticated RCE in end-of-life D-Link DSL routers (CVE-2026-0625, CVSS 9.3) enables silent DNS redirection. SAMA-regulated banks now face customer-side credential theft and BEC fraud at scale.