Topic
Cloud & Identity
Cloud misconfiguration risk and the identity and single sign-on systems attackers target.
85 articles in this topic
Handala Wiped 200,000 Stryker Devices in Minutes — The Intune Attack Vector Saudi Banks Cannot Ignore
On March 11, 2026, Iran-linked Handala triggered simultaneous factory resets on 200,000+ corporate devices at Stryker using Microsoft Intune. If your bank runs Azure AD, this attack vector is already in your environment.
Breaches & Data LeaksShinyHunters Claims 3M+ Cisco Salesforce Records: The CRM Security Crisis Saudi Banks Must Act On Now
ShinyHunters claims 3 million Cisco Salesforce records stolen — FBI, NASA, and government agency data included. Saudi financial institutions using Cisco products face cascading vendor risk right now.
VulnerabilitiesCVE-2026-3055: Citrix NetScaler's SAML IDP Flaw Is Being Actively Probed — What Saudi Banks Must Act On Now
A CVSS 9.3 memory overread in Citrix NetScaler is being actively probed by threat actors. Saudi banks using NetScaler as a SAML Identity Provider face credential exposure without any authentication required. Patch or isolate today.
Cloud & IdentityShinyHunters' 2026 Vishing Campaign: How Attackers Are Hijacking Okta SSO to Breach Bank-Grade SaaS Platforms
ShinyHunters used real-time voice phishing to steal Okta SSO credentials and MFA codes, then pivoted into Zendesk, Salesforce, and other SaaS platforms to steal millions of support tickets. Saudi banks running the same SaaS stack are directly exposed.
VulnerabilitiesCVE-2026-23813: Critical HPE Aruba AOS-CX Flaw Grants Unauthenticated Admin Access — What Saudi Banks Must Do Now
A CVSS 9.8 authentication bypass in HPE Aruba AOS-CX switches lets any remote attacker reset admin credentials — no authentication required. Saudi banks running this hardware in branch or data-center networks need to act before this changes exploitation status.
Breaches & Data LeaksShinyHunters Salesforce Campaign Hits 400+ Firms: What Saudi Banks Must Do Now
ShinyHunters has breached over 400 organizations through Salesforce Experience Cloud misconfigurations, stealing millions of records. Saudi financial institutions relying on Salesforce must act immediately to lock down guest user permissions and protect customer data.
Cloud & IdentityReact2Shell Exploits Breach 766 Hosts: Massive Credential Theft Campaign Targets Web Apps
A large-scale credential harvesting operation tracked as UAT-10608 is exploiting the React2Shell vulnerability to breach Next.js applications and steal AWS secrets, SSH keys, and database credentials at scale.
VulnerabilitiesOracle Identity Manager CVE-2026-21992: Pre-Auth RCE Threatens Saudi Financial IAM Systems
Oracle issued an emergency out-of-band patch for CVE-2026-21992, a CVSS 9.8 pre-authentication RCE flaw in Identity Manager. Saudi banks running Oracle Fusion Middleware face immediate risk.
Cloud & IdentityLesson 28: Cloud Security — Securing AWS, Azure, and GCP Environments
Hands-On Cybersecurity Path — Lesson 8 of 10. Master cloud security fundamentals across the three major providers and align your cloud posture with SAMA and NCA requirements.
VulnerabilitiesCVE-2026-21643: FortiClient EMS SQL Injection Under Active Attack — Patch Before Attackers Steal Your Endpoint Inventory
A pre-auth SQL injection in FortiClient EMS 7.4.4 lets attackers dump admin credentials and endpoint policies with a single HTTP request. Exploitation began March 26 — here's what Saudi CISOs must do now.
Network & InfrastructureCitrix NetScaler CVE-2026-3055: CISA KEV-Listed Memory Leak Hitting Financial Gateways
CISA added CVE-2026-3055 to its Known Exploited Vulnerabilities catalog on March 30. Attackers are already harvesting credentials from unpatched NetScaler gateways — here's what Saudi financial CISOs must do before the April 2 deadline.
VulnerabilitiesOracle Identity Manager CVE-2026-21992: Emergency RCE Patch Every Saudi Bank Must Apply Now
Oracle issues rare emergency patch for CVE-2026-21992 — a CVSS 9.8 pre-auth RCE flaw in Identity Manager. Saudi financial institutions using Oracle IAM must act immediately.