Topic

Cloud & Identity

Cloud misconfiguration risk and the identity and single sign-on systems attackers target.

85 articles in this topic

Vulnerabilities

Fortinet CVE-2026-24858: FortiCloud SSO Bypass Hits SAMA Banks

Fortinet's CVE-2026-24858 lets attackers bypass FortiCloud SSO and seize admin control over FortiOS, FortiManager, and FortiProxy. Why SAMA-regulated banks must act before patches arrive.

5 May 2026 4 min
Vulnerabilities

MOVEit CVE-2026-4670 Auth Bypass: SAMA Bank File Transfer Risk

Progress Software patched a critical MOVEit Automation auth bypass (CVE-2026-4670) that exposes credentials and financial files. Saudi banks must act before exploitation hits SAMA-regulated MFT flows.

5 May 2026 4 min
Supply Chain & Third Party

PyTorch Lightning PyPI Hijack: SAMA Bank AI Supply Chain Risk

On April 30, 2026, attackers pushed malicious PyTorch Lightning packages to PyPI to harvest CI/CD secrets. Here is what SAMA-regulated banks must do under CSCC supply chain controls.

4 May 2026 4 min
Breaches & Data Leaks

Vercel-Context AI OAuth Breach: SaaS Supply Chain Lessons for SAMA Banks

A single employee-installed AI plugin gave attackers OAuth access to Vercel's corporate Google environment. The blast radius reached hundreds of downstream organizations — and exposes a control gap that SAMA-regulated banks routinely overlook.

4 May 2026 4 min
Ransomware

Akira Ransomware Bypasses MFA on SonicWall VPNs: SAMA Bank Defense Guide

Akira ransomware operators are now bypassing MFA on SonicWall SSL VPNs by exfiltrating OTP seed values from compromised firewalls. SAMA-regulated banks face urgent perimeter risk that demands immediate CSCC-aligned controls.

3 May 2026 5 min
Breaches & Data Leaks

ShinyHunters Salesforce Heist Threatens Saudi Bank SaaS Security

The ShinyHunters extortion group has exfiltrated 1.5 billion records from 760 Salesforce tenants through OAuth abuse and vishing—exposing critical TPRM gaps for Saudi SAMA-regulated financial institutions.

2 May 2026 4 min
Vulnerabilities

CVE-2026-32202: Windows Shell Zero-Click NTLM Leak Hits Saudi Banks

A zero-click Windows Shell flaw silently leaks NTLMv2 hashes the moment a user browses a folder. Saudi financial institutions under SAMA CSCC must patch CVE-2026-32202 by May 12 to avoid credential theft and lateral movement across Active Directory.

29 Apr 2026 4 min
Vulnerabilities

CVE-2026-3854: A Single Git Push Hijacks GitHub — Saudi Banks at Risk

A single git push can now grant full remote code execution on GitHub Enterprise Server. For Saudi financial institutions running internal repositories, CVE-2026-3854 is more than a DevOps incident — it is a SAMA CSCC source-code protection breach waiting to happen.

29 Apr 2026 4 min
Cloud & Identity

McGraw-Hill's 13.5M-Record Salesforce Breach: Why Cloud Misconfiguration Is the Silent SAMA CSCC Compliance Failure

A Salesforce misconfiguration exposed 13.5 million records at McGraw-Hill. With 31% of cloud breaches sharing this same root cause, Saudi financial institutions must audit their SaaS posture before their next SAMA review.

19 Apr 2026 6 min
Artificial Intelligence

ClawHavoc: How 1,184 Malicious AI Agent Skills Are Harvesting Credentials from Financial Sector Employees

Attackers poisoned OpenClaw's AI agent marketplace with over 1,184 malicious skills deploying the AMOS credential stealer. 12% of the entire registry was compromised — and Saudi financial institutions adopting agentic AI tools are directly in the crosshairs.

19 Apr 2026 5 min
Breaches & Data Leaks

ShinyHunters Breach Anodot to Compromise Dozens of Snowflake Accounts: A Supply Chain Wake-Up Call for Saudi Financial Institutions

On April 7, 2026, the ShinyHunters gang breached AI analytics firm Anodot and weaponized stolen Snowflake authentication tokens against dozens of companies. Saudi financial institutions using cloud data platforms face direct SAMA CSCC third-party risk exposure — here's what you must do now.

19 Apr 2026 5 min
Vulnerabilities

CVE-2026-21643: The Fortinet FortiClient EMS Zero-Auth SQL Injection CISA Is Flagging — Action Required for Saudi Financial Institutions

CISA confirmed active exploitation of CVE-2026-21643 on April 13, 2026 — a pre-authentication SQL injection in Fortinet FortiClient EMS with a CVSS score of 9.1. Saudi financial institutions running affected versions must patch immediately or face direct risk of unauthorized remote code execution with no credentials required.

19 Apr 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality