Topic

Cloud & Identity

Cloud misconfiguration risk and the identity and single sign-on systems attackers target.

85 articles in this topic

Cloud & Identity

PCPJack Cloud Worm: Credential Theft Threat to SAMA Banks

A newly discovered credential-stealing worm called PCPJack is propagating across exposed cloud infrastructure by exploiting five known CVEs. Saudi banks running Docker, Kubernetes, Redis, and MongoDB face elevated exposure under SAMA CSCC.

10 May 2026 3 min
Cloud & Identity

MuddyWater Targets Microsoft Teams MFA: SAMA Bank Defense Guide

Iranian state-sponsored MuddyWater is exploiting Microsoft Teams social engineering to harvest credentials and manipulate MFA at financial institutions, then planting Chaos ransomware as a false flag. Here is what SAMA-regulated banks must do.

9 May 2026 4 min
Cloud & Identity

PCPJack Cloud Worm: Credential Theft Threat to SAMA Banks

A newly disclosed cloud worm called PCPJack chains 5 CVEs to harvest credentials across Docker, Kubernetes, Redis, MongoDB and RayML — a direct risk for SAMA-regulated banks running cloud workloads.

9 May 2026 4 min
Malware & Threat Actors

GopherWhisper APT: Slack & Microsoft 365 C2 Risk to SAMA Banks

ESET unveils GopherWhisper — a China-aligned APT using Discord, Slack and Microsoft 365 Outlook as covert C2. SAMA-regulated banks face the same legitimate-service abuse risk and must rethink detection.

8 May 2026 4 min
Cloud & Identity

PCPJack Cloud Worm: Credential Theft Threat to SAMA Banks

SentinelLabs has uncovered PCPJack, a self-propagating cloud worm that hijacks TeamPCP infrastructure and steals credentials at scale. Saudi financial institutions running cloud workloads face urgent SAMA CSCC exposure.

8 May 2026 4 min
Cloud & Identity

TeamPCP Cloud Compromise: CI/CD Threat for SAMA Banks

TeamPCP weaponized open-source security tools (Trivy, LiteLLM, KICS) to harvest CI/CD secrets and pivot into AWS, Azure and SaaS environments. SAMA-regulated banks must reassess third-party and pipeline trust now.

7 May 2026 4 min
Phishing & Fraud

AiTM Phishing Campaign 2026: 35,000-Victim MFA Bypass Threatens SAMA Banks

Microsoft Defender Research uncovered a multi-stage AiTM phishing campaign that hit 35,000 users across 26 countries — financial services was 18% of victims. What SAMA-regulated banks must do today.

7 May 2026 4 min
Vulnerabilities

CVE-2026-32202: APT28's Zero-Click Windows Shell Threat to SAMA Banks

A zero-click Windows Shell vulnerability (CVE-2026-32202) is being weaponized by Russian APT28 to silently harvest NTLMv2 credentials. Saudi banks face an urgent patching window before May 12.

7 May 2026 4 min
Cloud & Identity

Oracle Identity Manager CVE-2026-21992: Critical IAM Threat to SAMA Banks

A pre-authentication RCE in Oracle Identity Manager (CVSS 9.8) gives attackers direct control of the IAM core that Saudi banks rely on for SAMA CSCC compliance. Here is how to detect, patch, and respond.

7 May 2026 4 min
Malware & Threat Actors

MuddyWater's Teams Attack: Iranian APT Threat to SAMA Banks

Iranian state-sponsored MuddyWater is exploiting Microsoft Teams screen-share to harvest credentials and bypass MFA, while masking espionage as Chaos ransomware. Implications for SAMA-regulated banks.

6 May 2026 4 min
Cloud & Identity

Vercel-Context AI OAuth Breach: Shadow AI Risk Lessons for SAMA Banks

A single Shadow AI tool installed by one Vercel employee triggered an OAuth supply-chain breach exposing API keys, source code, and customer credentials — a textbook warning for SAMA-regulated banks tightening third-party governance under CSCC and ECC.

5 May 2026 5 min
Cloud & Identity

CVE-2026-42354: Sentry SAML SSO Bypass Threatens SAMA Bank IAM

A critical Sentry SAML SSO bypass (CVE-2026-42354) enables full account takeover with only the victim's email address. Saudi financial institutions relying on federated identity must act now to align with SAMA CSCC IAM controls.

5 May 2026 4 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality