Topic
Cloud & Identity
Cloud misconfiguration risk and the identity and single sign-on systems attackers target.
85 articles in this topic
Fortinet CVE-2026-24858: FortiCloud SSO Bypass Hits SAMA Banks
Fortinet's CVE-2026-24858 lets attackers bypass FortiCloud SSO and seize admin control over FortiOS, FortiManager, and FortiProxy. Why SAMA-regulated banks must act before patches arrive.
VulnerabilitiesMOVEit CVE-2026-4670 Auth Bypass: SAMA Bank File Transfer Risk
Progress Software patched a critical MOVEit Automation auth bypass (CVE-2026-4670) that exposes credentials and financial files. Saudi banks must act before exploitation hits SAMA-regulated MFT flows.
Supply Chain & Third PartyPyTorch Lightning PyPI Hijack: SAMA Bank AI Supply Chain Risk
On April 30, 2026, attackers pushed malicious PyTorch Lightning packages to PyPI to harvest CI/CD secrets. Here is what SAMA-regulated banks must do under CSCC supply chain controls.
Breaches & Data LeaksVercel-Context AI OAuth Breach: SaaS Supply Chain Lessons for SAMA Banks
A single employee-installed AI plugin gave attackers OAuth access to Vercel's corporate Google environment. The blast radius reached hundreds of downstream organizations — and exposes a control gap that SAMA-regulated banks routinely overlook.
RansomwareAkira Ransomware Bypasses MFA on SonicWall VPNs: SAMA Bank Defense Guide
Akira ransomware operators are now bypassing MFA on SonicWall SSL VPNs by exfiltrating OTP seed values from compromised firewalls. SAMA-regulated banks face urgent perimeter risk that demands immediate CSCC-aligned controls.
Breaches & Data LeaksShinyHunters Salesforce Heist Threatens Saudi Bank SaaS Security
The ShinyHunters extortion group has exfiltrated 1.5 billion records from 760 Salesforce tenants through OAuth abuse and vishing—exposing critical TPRM gaps for Saudi SAMA-regulated financial institutions.
VulnerabilitiesCVE-2026-32202: Windows Shell Zero-Click NTLM Leak Hits Saudi Banks
A zero-click Windows Shell flaw silently leaks NTLMv2 hashes the moment a user browses a folder. Saudi financial institutions under SAMA CSCC must patch CVE-2026-32202 by May 12 to avoid credential theft and lateral movement across Active Directory.
VulnerabilitiesCVE-2026-3854: A Single Git Push Hijacks GitHub — Saudi Banks at Risk
A single git push can now grant full remote code execution on GitHub Enterprise Server. For Saudi financial institutions running internal repositories, CVE-2026-3854 is more than a DevOps incident — it is a SAMA CSCC source-code protection breach waiting to happen.
Cloud & IdentityMcGraw-Hill's 13.5M-Record Salesforce Breach: Why Cloud Misconfiguration Is the Silent SAMA CSCC Compliance Failure
A Salesforce misconfiguration exposed 13.5 million records at McGraw-Hill. With 31% of cloud breaches sharing this same root cause, Saudi financial institutions must audit their SaaS posture before their next SAMA review.
Artificial IntelligenceClawHavoc: How 1,184 Malicious AI Agent Skills Are Harvesting Credentials from Financial Sector Employees
Attackers poisoned OpenClaw's AI agent marketplace with over 1,184 malicious skills deploying the AMOS credential stealer. 12% of the entire registry was compromised — and Saudi financial institutions adopting agentic AI tools are directly in the crosshairs.
Breaches & Data LeaksShinyHunters Breach Anodot to Compromise Dozens of Snowflake Accounts: A Supply Chain Wake-Up Call for Saudi Financial Institutions
On April 7, 2026, the ShinyHunters gang breached AI analytics firm Anodot and weaponized stolen Snowflake authentication tokens against dozens of companies. Saudi financial institutions using cloud data platforms face direct SAMA CSCC third-party risk exposure — here's what you must do now.
VulnerabilitiesCVE-2026-21643: The Fortinet FortiClient EMS Zero-Auth SQL Injection CISA Is Flagging — Action Required for Saudi Financial Institutions
CISA confirmed active exploitation of CVE-2026-21643 on April 13, 2026 — a pre-authentication SQL injection in Fortinet FortiClient EMS with a CVSS score of 9.1. Saudi financial institutions running affected versions must patch immediately or face direct risk of unauthorized remote code execution with no credentials required.
From reading to doing
How secure is your cloud environment?
A cloud security assessment reviews your account configuration, access rights and exposed data, and sets out what to fix first.
Cloud Security Assessment
Comprehensive security configuration review for AWS, Azure, and GCP cloud environments to ensure your data protection
Security Architecture Review
An in-depth review of your network and systems architecture to ensure security is built into the design, not bolted on later.
Cloud Infrastructure & IaC
We design secure, reproducible cloud infrastructure using infrastructure-as-code.