Topic
Compliance & Regulation
Saudi regulatory frameworks — NCA controls, the SAMA framework and the Personal Data Protection Law.
83 articles in this topic
vm2 Sandbox Escape (CVE-2026-24118): RCE Risk for SAMA Banks
Twelve critical vm2 Node.js sandbox escape vulnerabilities, including CVE-2026-24118 (CVSS 9.8), let attackers execute arbitrary code on host servers. Saudi banks and fintechs running Node.js platforms face urgent SAMA CSCC remediation pressure.
Supply Chain & Third PartyTrellix Source Code Breach: Supply Chain Threat to SAMA Banks
Trellix confirmed unauthorized access to its source code repository in May 2026. For SAMA-regulated banks relying on Trellix XDR and EDR, this incident raises urgent supply chain and third-party risk questions under SAMA CSCC.
Malware & Threat ActorsDAEMON Tools Supply Chain Backdoor: SAMA Bank Endpoint Risk
Kaspersky uncovered a trojanized DAEMON Tools installer distributing a Chinese-linked backdoor through the vendor's official domain since April 8, 2026 — a direct test of SAMA CSCC software supply chain controls.
VulnerabilitiesCopy Fail CVE-2026-31431: Linux Root Threat to SAMA Banks
A 732-byte exploit grants root on every major Linux distribution since 2017. Saudi banks running RHEL, Ubuntu, or Amazon Linux face urgent SAMA CSCC patching obligations.
Cloud & IdentityOracle Identity Manager CVE-2026-21992: Critical IAM Threat to SAMA Banks
A pre-authentication RCE in Oracle Identity Manager (CVSS 9.8) gives attackers direct control of the IAM core that Saudi banks rely on for SAMA CSCC compliance. Here is how to detect, patch, and respond.
VulnerabilitiesAndroid Zero-Click CVE-2026-0073: Mobile Banking Threat to SAMA Banks
A critical zero-click flaw in Android's wireless ADB daemon (CVE-2026-0073) allows attackers in Wi-Fi proximity to obtain a remote shell without any user interaction — a direct threat to Saudi mobile banking and BYOD fleets under SAMA CSCC.
Breaches & Data LeaksItron Utility Breach: Critical Infrastructure Lessons for SAMA Banks
Utility tech giant Itron disclosed an intrusion into internal systems. For Saudi banks under SAMA CSCC, this is a sharp reminder: third-party assurance is non-negotiable.
VulnerabilitiesApache HTTP/2 CVE-2026-23918 RCE: SAMA Bank Web Tier Risk
Apache shipped 2.4.67 on May 4, 2026 to fix CVE-2026-23918, an HTTP/2 double-free enabling RCE on millions of servers. Saudi banks face direct exposure on internet-facing web tiers under SAMA CSCC.
Cloud & IdentityCVE-2026-42354: Sentry SAML SSO Bypass Threatens SAMA Bank IAM
A critical Sentry SAML SSO bypass (CVE-2026-42354) enables full account takeover with only the victim's email address. Saudi financial institutions relying on federated identity must act now to align with SAMA CSCC IAM controls.
VulnerabilitiesCVE-2026-42779: Apache MINA Deserialization RCE Hits SAMA Banks
A critical Apache MINA deserialization flaw (CVE-2026-42779, CVSS 9.8) bypasses classname allowlists and enables unauthenticated RCE in financial messaging systems. SAMA CSCC patch guidance inside.
Breaches & Data LeaksMarquis Breach Hits 80 Banks: SAMA Vendor Risk Lessons for Saudi CISOs
The Marquis Software ransomware breach exposed 824,000 customers across 80 US banks via a single SonicWall CVE. Here is the SAMA CSCC 3.4 vendor-risk playbook every Saudi CISO must apply now.
VulnerabilitiesBlueHammer CVE-2026-33825: Defender Zero-Day Hits SAMA Banks
A leaked Microsoft Defender exploit known as BlueHammer (CVE-2026-33825) escalates any unprivileged user to SYSTEM on fully patched Windows. What SAMA-regulated banks must do now to stay aligned with CSCC endpoint controls.