Topic
Compliance & Regulation
Saudi regulatory frameworks — NCA controls, the SAMA framework and the Personal Data Protection Law.
83 articles in this topic
CVE-2026-23918: Apache HTTP/2 Double-Free Flaw Crashes Servers and Opens the Door to RCE
Critical Apache HTTP/2 double-free vulnerability CVE-2026-23918 is actively exploited for DoS with RCE potential. Saudi financial institutions must patch to 2.4.67 immediately to meet SAMA CSCC and NCA ECC requirements.
Breaches & Data LeaksCoinbase Insider Bribery Breach: Why Saudi Financial CISOs Must Rethink Third-Party Personnel Risk
Bribed overseas contractors stole data from 70,000 Coinbase customers — a $400M lesson in why insider threat programs for third-party personnel are non-negotiable under SAMA CSCC and NCA ECC.
Compliance & RegulationNCA NCNICC-1:2025: Every Saudi Private Company Now Faces Mandatory Cybersecurity Controls
NCA's NCNICC-1:2025 makes cybersecurity controls mandatory for all Saudi private companies. Learn the 65 controls, Category A vs. B requirements, and how to achieve compliance alongside SAMA CSCC.
VulnerabilitiesCVE-2026-42897: Exchange OWA Zero-Day Turns a Single Email into Full Browser Hijack
Microsoft confirms active exploitation of CVE-2026-42897, a stored XSS in Exchange OWA that hijacks authenticated sessions via a single crafted email. CISA KEV-listed with a May 29 deadline—Saudi financial institutions must patch within 48 hours to meet SAMA CSCC requirements.
Artificial IntelligenceCritical Microsoft 365 Copilot Vulnerabilities: AI Assistants Become Data Exfiltration Vectors
Three critical CVEs in Microsoft 365 Copilot allow unauthorized data disclosure through AI injection attacks. Saudi financial institutions face compounded SAMA CSCC and PDPL compliance risks as AI assistants bypass traditional DLP controls.
Breaches & Data LeaksShinyHunters Vishing-to-Salesforce Attack Chain: What SAMA Banks Must Know
ShinyHunters breached 500K+ Salesforce records via vishing and OAuth hijacking. Saudi financial institutions face the same attack pattern — here's how to defend under SAMA CSCC and NCA ECC.
Cloud & IdentityPCPJack Cloud Worm: Credential Theft Threat to SAMA Banks
A newly discovered credential-stealing worm called PCPJack is propagating across exposed cloud infrastructure by exploiting five known CVEs. Saudi banks running Docker, Kubernetes, Redis, and MongoDB face elevated exposure under SAMA CSCC.
RansomwareAnubis Ransomware Adds Wiper: Critical Risk to SAMA Banks
Anubis ransomware-as-a-service now includes a destructive wiper alongside double extortion, breaking the traditional ransomware bargain. Saudi banks must adapt SAMA CSCC defenses immediately.
VulnerabilitiesApache HTTP/2 CVE-2026-23918: Critical RCE Risk to SAMA Banks
A critical double-free flaw in Apache HTTP Server 2.4.66 mod_http2 (CVE-2026-23918) enables DoS and remote code execution. Saudi banks running affected web servers face urgent SAMA CSCC patching pressure.
Artificial IntelligenceIMF Warns AI Cyberattacks Threaten Financial Stability: SAMA Bank Response
The IMF's May 7, 2026 Global Financial Stability assessment identifies AI-fueled cyberattacks as a core systemic risk to the banking sector. Saudi institutions regulated by SAMA CSCC face direct exposure — and must adapt their cyber resilience model now.
VulnerabilitiesPAN-OS CVE-2026-0300: Critical RCE Threat to SAMA Banks
CISA added Palo Alto PAN-OS CVE-2026-0300 to its KEV catalog after limited in-the-wild exploitation. Saudi banks exposing the User-ID Authentication Portal face an unauthenticated root RCE on the perimeter — here is what SAMA CSCC requires you to do now.
Cloud & IdentityPCPJack Cloud Worm: Credential Theft Threat to SAMA Banks
SentinelLabs has uncovered PCPJack, a self-propagating cloud worm that hijacks TeamPCP infrastructure and steals credentials at scale. Saudi financial institutions running cloud workloads face urgent SAMA CSCC exposure.