Topic

Cloud & Identity

Cloud misconfiguration risk and the identity and single sign-on systems attackers target.

85 articles in this topic

Malware & Threat Actors

Handala Wiped 200,000 Stryker Devices in Minutes — The Intune Attack Vector Saudi Banks Cannot Ignore

On March 11, 2026, Iran-linked Handala triggered simultaneous factory resets on 200,000+ corporate devices at Stryker using Microsoft Intune. If your bank runs Azure AD, this attack vector is already in your environment.

5 Apr 2026 6 min
Breaches & Data Leaks

ShinyHunters Claims 3M+ Cisco Salesforce Records: The CRM Security Crisis Saudi Banks Must Act On Now

ShinyHunters claims 3 million Cisco Salesforce records stolen — FBI, NASA, and government agency data included. Saudi financial institutions using Cisco products face cascading vendor risk right now.

4 Apr 2026 6 min
Vulnerabilities

CVE-2026-3055: Citrix NetScaler's SAML IDP Flaw Is Being Actively Probed — What Saudi Banks Must Act On Now

A CVSS 9.3 memory overread in Citrix NetScaler is being actively probed by threat actors. Saudi banks using NetScaler as a SAML Identity Provider face credential exposure without any authentication required. Patch or isolate today.

4 Apr 2026 5 min
Cloud & Identity

ShinyHunters' 2026 Vishing Campaign: How Attackers Are Hijacking Okta SSO to Breach Bank-Grade SaaS Platforms

ShinyHunters used real-time voice phishing to steal Okta SSO credentials and MFA codes, then pivoted into Zendesk, Salesforce, and other SaaS platforms to steal millions of support tickets. Saudi banks running the same SaaS stack are directly exposed.

4 Apr 2026 6 min
Vulnerabilities

CVE-2026-23813: Critical HPE Aruba AOS-CX Flaw Grants Unauthenticated Admin Access — What Saudi Banks Must Do Now

A CVSS 9.8 authentication bypass in HPE Aruba AOS-CX switches lets any remote attacker reset admin credentials — no authentication required. Saudi banks running this hardware in branch or data-center networks need to act before this changes exploitation status.

4 Apr 2026 5 min
Breaches & Data Leaks

ShinyHunters Salesforce Campaign Hits 400+ Firms: What Saudi Banks Must Do Now

ShinyHunters has breached over 400 organizations through Salesforce Experience Cloud misconfigurations, stealing millions of records. Saudi financial institutions relying on Salesforce must act immediately to lock down guest user permissions and protect customer data.

3 Apr 2026 6 min
Cloud & Identity

React2Shell Exploits Breach 766 Hosts: Massive Credential Theft Campaign Targets Web Apps

A large-scale credential harvesting operation tracked as UAT-10608 is exploiting the React2Shell vulnerability to breach Next.js applications and steal AWS secrets, SSH keys, and database credentials at scale.

3 Apr 2026 5 min
Vulnerabilities

Oracle Identity Manager CVE-2026-21992: Pre-Auth RCE Threatens Saudi Financial IAM Systems

Oracle issued an emergency out-of-band patch for CVE-2026-21992, a CVSS 9.8 pre-authentication RCE flaw in Identity Manager. Saudi banks running Oracle Fusion Middleware face immediate risk.

3 Apr 2026 5 min
Cloud & Identity

Lesson 28: Cloud Security — Securing AWS, Azure, and GCP Environments

Hands-On Cybersecurity Path — Lesson 8 of 10. Master cloud security fundamentals across the three major providers and align your cloud posture with SAMA and NCA requirements.

1 Apr 2026 8 min
Vulnerabilities

CVE-2026-21643: FortiClient EMS SQL Injection Under Active Attack — Patch Before Attackers Steal Your Endpoint Inventory

A pre-auth SQL injection in FortiClient EMS 7.4.4 lets attackers dump admin credentials and endpoint policies with a single HTTP request. Exploitation began March 26 — here's what Saudi CISOs must do now.

1 Apr 2026 5 min
Network & Infrastructure

Citrix NetScaler CVE-2026-3055: CISA KEV-Listed Memory Leak Hitting Financial Gateways

CISA added CVE-2026-3055 to its Known Exploited Vulnerabilities catalog on March 30. Attackers are already harvesting credentials from unpatched NetScaler gateways — here's what Saudi financial CISOs must do before the April 2 deadline.

1 Apr 2026 6 min
Vulnerabilities

Oracle Identity Manager CVE-2026-21992: Emergency RCE Patch Every Saudi Bank Must Apply Now

Oracle issues rare emergency patch for CVE-2026-21992 — a CVSS 9.8 pre-auth RCE flaw in Identity Manager. Saudi financial institutions using Oracle IAM must act immediately.

1 Apr 2026 4 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality