Topic
Cloud & Identity
Cloud misconfiguration risk and the identity and single sign-on systems attackers target.
85 articles in this topic
PCPJack Cloud Worm: Credential Theft Threat to SAMA Banks
A newly discovered credential-stealing worm called PCPJack is propagating across exposed cloud infrastructure by exploiting five known CVEs. Saudi banks running Docker, Kubernetes, Redis, and MongoDB face elevated exposure under SAMA CSCC.
Cloud & IdentityMuddyWater Targets Microsoft Teams MFA: SAMA Bank Defense Guide
Iranian state-sponsored MuddyWater is exploiting Microsoft Teams social engineering to harvest credentials and manipulate MFA at financial institutions, then planting Chaos ransomware as a false flag. Here is what SAMA-regulated banks must do.
Cloud & IdentityPCPJack Cloud Worm: Credential Theft Threat to SAMA Banks
A newly disclosed cloud worm called PCPJack chains 5 CVEs to harvest credentials across Docker, Kubernetes, Redis, MongoDB and RayML — a direct risk for SAMA-regulated banks running cloud workloads.
Malware & Threat ActorsGopherWhisper APT: Slack & Microsoft 365 C2 Risk to SAMA Banks
ESET unveils GopherWhisper — a China-aligned APT using Discord, Slack and Microsoft 365 Outlook as covert C2. SAMA-regulated banks face the same legitimate-service abuse risk and must rethink detection.
Cloud & IdentityPCPJack Cloud Worm: Credential Theft Threat to SAMA Banks
SentinelLabs has uncovered PCPJack, a self-propagating cloud worm that hijacks TeamPCP infrastructure and steals credentials at scale. Saudi financial institutions running cloud workloads face urgent SAMA CSCC exposure.
Cloud & IdentityTeamPCP Cloud Compromise: CI/CD Threat for SAMA Banks
TeamPCP weaponized open-source security tools (Trivy, LiteLLM, KICS) to harvest CI/CD secrets and pivot into AWS, Azure and SaaS environments. SAMA-regulated banks must reassess third-party and pipeline trust now.
Phishing & FraudAiTM Phishing Campaign 2026: 35,000-Victim MFA Bypass Threatens SAMA Banks
Microsoft Defender Research uncovered a multi-stage AiTM phishing campaign that hit 35,000 users across 26 countries — financial services was 18% of victims. What SAMA-regulated banks must do today.
VulnerabilitiesCVE-2026-32202: APT28's Zero-Click Windows Shell Threat to SAMA Banks
A zero-click Windows Shell vulnerability (CVE-2026-32202) is being weaponized by Russian APT28 to silently harvest NTLMv2 credentials. Saudi banks face an urgent patching window before May 12.
Cloud & IdentityOracle Identity Manager CVE-2026-21992: Critical IAM Threat to SAMA Banks
A pre-authentication RCE in Oracle Identity Manager (CVSS 9.8) gives attackers direct control of the IAM core that Saudi banks rely on for SAMA CSCC compliance. Here is how to detect, patch, and respond.
Malware & Threat ActorsMuddyWater's Teams Attack: Iranian APT Threat to SAMA Banks
Iranian state-sponsored MuddyWater is exploiting Microsoft Teams screen-share to harvest credentials and bypass MFA, while masking espionage as Chaos ransomware. Implications for SAMA-regulated banks.
Cloud & IdentityVercel-Context AI OAuth Breach: Shadow AI Risk Lessons for SAMA Banks
A single Shadow AI tool installed by one Vercel employee triggered an OAuth supply-chain breach exposing API keys, source code, and customer credentials — a textbook warning for SAMA-regulated banks tightening third-party governance under CSCC and ECC.
Cloud & IdentityCVE-2026-42354: Sentry SAML SSO Bypass Threatens SAMA Bank IAM
A critical Sentry SAML SSO bypass (CVE-2026-42354) enables full account takeover with only the victim's email address. Saudi financial institutions relying on federated identity must act now to align with SAMA CSCC IAM controls.