Topic

Cloud & Identity

Cloud misconfiguration risk and the identity and single sign-on systems attackers target.

85 articles in this topic

Cloud & Identity

EvilToken: The AI-Powered Phishing Kit That Defeats MFA and Targets Saudi Financial M365 Environments

A new phishing-as-a-service toolkit called EvilToken is bypassing MFA at scale using AI-generated lures and OAuth device code abuse, targeting M365 users across the UAE and beyond — a direct risk to Saudi financial institutions.

18 Apr 2026 5 min
Breaches & Data Leaks

ShinyHunters Hits McGraw-Hill via Salesforce Misconfiguration: 13.5M Records and a Warning Saudi Financial CISOs Must Heed

No malware, no CVE, no phishing — just a Salesforce misconfiguration. ShinyHunters walked out with 13.5 million McGraw-Hill records. Saudi banks running Salesforce or Dynamics 365 hold far more sensitive data and face identical exposure under PDPL and SAMA CSCC.

18 Apr 2026 7 min
Phishing & Fraud

W3LL Phishing Marketplace Dismantled: How a $500 Kit Bypassed MFA at Scale — Lessons for Saudi Financial CISOs

FBI Atlanta and Indonesian National Police seized the W3LL phishing marketplace on April 10, 2026 — a platform that sold MFA-bypassing phishing kits for $500 and enabled over $20M in fraud across 17,000 victims. Here's what SAMA-regulated institutions must do now.

15 Apr 2026 5 min
Cloud & Identity

Scattered Spider Returns: AI-Powered Vishing and Azure AD Hijacking Now Target Saudi Financial Institutions

Scattered Spider has pivoted from retail and tech to financial institutions, deploying AI-powered voice phishing and Azure AD federation backdoors to bypass MFA. Saudi banks under SAMA supervision face immediate exposure — here is what your security team must do now.

15 Apr 2026 5 min
Malware & Threat Actors

CVE-2026-40175: Axios Gets Hit Twice — North Korean Backdoor Then a 9.9 CVSS Flaw That Hands Attackers Your AWS Keys

Axios npm suffered a North Korean supply chain backdoor in March, then a 9.9 CVSS flaw a week later. Saudi open banking teams running Node.js on AWS need to act before threat actors chain both.

14 Apr 2026 6 min
Vulnerabilities

React2Shell (CVE-2025-55182): The CVSS-10 Flaw Silently Draining API Keys from Financial Web Apps

A CVSS-10 flaw in React Server Components has enabled threat actor UAT-10608 to silently harvest credentials from 766+ hosts. Saudi financial institutions running Next.js-based portals face immediate exposure.

7 Apr 2026 5 min
Cloud & Identity

FBI & CISA Alert: Russian Intelligence Is Hijacking WhatsApp Accounts — Saudi Banks Are a Prime Target

Russian state-sponsored actors are walking around end-to-end encryption by hijacking WhatsApp and Signal accounts directly. Saudi financial institutions — where WhatsApp is the de facto business communication channel — are acutely exposed.

7 Apr 2026 6 min
Cloud & Identity

How Social Engineering Hijacks Okta to Breach Every SaaS You Use

A single phone call compromised Hims & Hers' Okta SSO in Feb 2026, exposing 1.8M customer support tickets. Saudi banks using SSO face the same risk — here's how to defend.

6 Apr 2026 5 min
Vulnerabilities

TrueConf CVE-2026-3502: Video Conferencing Update Hijack Exploited by State-Sponsored Hackers

CISA flags TrueConf Client CVE-2026-3502 after Chinese-linked hackers weaponize its update mechanism. Saudi banks relying on video conferencing must audit software integrity controls immediately.

6 Apr 2026 5 min
Cloud & Identity

Everest Ransomware Steals 910GB from Nissan via Stale FTP Credentials — A Third-Party Risk Wake-Up Call for Saudi Banks

Everest ransomware exfiltrated 910GB of Nissan customer and loan data through a vendor FTP server with 3-year-old credentials and no MFA. Here's what Saudi financial institutions must learn about third-party risk management.

6 Apr 2026 5 min
Vulnerabilities

Progress ShareFile Pre-Auth RCE Chain: 30,000 Servers Exposed and Saudi Banks Must Patch Now

Two chained ShareFile flaws give attackers full server control without credentials. With 30,000 instances exposed globally, Saudi financial institutions running on-premise ShareFile must act before exploitation campaigns begin.

6 Apr 2026 6 min
Vulnerabilities

Microsoft Patches Four Critical Azure Flaws at CVSS 10.0 — Saudi Banks on Azure Must Act Now

Microsoft disclosed four critical Azure vulnerabilities — two scoring a perfect CVSS 10.0 — affecting AI Foundry, Kubernetes Service, Custom Locations, and MCP Server. Saudi banks running workloads on Azure face urgent remediation requirements under SAMA CSCC.

5 Apr 2026 6 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality