Topic
Compliance & Regulation
Saudi regulatory frameworks — NCA controls, the SAMA framework and the Personal Data Protection Law.
83 articles in this topic
CVE-2026-3854: GitHub RCE Threatens SAMA Bank Source Code
A single crafted git push gave attackers cross-tenant RCE on GitHub, exposing millions of private repositories. With 88% of self-hosted GHES still vulnerable, SAMA-regulated banks face a direct threat to their source code crown jewels and CSCC compliance posture.
VulnerabilitiesCVE-2026-32201: SharePoint Zero-Day Hits SAMA Bank Collaboration
Microsoft confirms active exploitation of SharePoint zero-day CVE-2026-32201. Over 1,300 servers remain exposed online. Here is what SAMA-regulated banks must do this week to stay aligned with CSCC controls.
VulnerabilitiesFortiClient EMS CVE-2026-35616: Pre-Auth RCE Risk to SAMA Banks
CVE-2026-35616 in Fortinet FortiClient EMS allows pre-auth RCE on endpoint management servers across Saudi banks. Active exploitation confirmed by CISA — patch immediately under SAMA CSCC.
VulnerabilitiesFortra GoAnywhere MFT Flaws: Pre-CVE Threat to SAMA Banks
New Fortra GoAnywhere MFT vulnerabilities expose Saudi banks' regulated file transfers. Darktrace observed pre-CVE exploitation. SAMA CSCC remediation guide for Saudi CISOs.
VulnerabilitiesCopy Fail (CVE-2026-31431): 732-Byte Linux Root Escalation Hits Saudi Banks
A 732-byte Python script grants root on every major Linux distribution since 2017. CVE-2026-31431 'Copy Fail' threatens every Saudi bank's Linux infrastructure. Here's what SAMA CSCC requires now.
RansomwareEverest Ransomware Hits Frost and Citizens: SAMA CSCC Lessons
Everest's April 2026 attacks on Frost Bank and Citizens Financial expose data-first extortion tactics SAMA-regulated banks must defend against now.
VulnerabilitiesNi8mare CVE-2026-21858: n8n RCE Threatens Saudi Bank AI Workflows
A CVSS 10.0 unauthenticated RCE in n8n webhook handling — dubbed Ni8mare — exposes the AI workflow automation platforms many Saudi banks now run for SOC orchestration and DevSecOps pipelines. Here is the SAMA CSCC patch path.
RansomwareCVE-2025-61882: Oracle EBS Clop Extortion Hits Saudi Banks
Clop is weaponizing Oracle EBS zero-day CVE-2025-61882 (CVSS 9.8) against insurers like Allianz UK. Saudi banks running EBS face direct SAMA CSCC and PDPL exposure.
VulnerabilitiesSonicWall SonicOS Trio (CVE-2026-0204/0205/0206) Threatens Saudi Bank Perimeters
Three newly disclosed SonicOS vulnerabilities — including a CVSS 8.0 access-control bypass — put SonicWall Gen6/7/8 firewalls at risk across Saudi banking perimeters. Here is the SAMA CSCC remediation playbook.
VulnerabilitiesBlueHammer (CVE-2026-33825): Defender Zero-Day Hits Saudi Banks
BlueHammer (CVE-2026-33825) abuses a TOCTOU race in Microsoft Defender to grant SYSTEM-level access without user interaction. Here is what Saudi banks must do today under SAMA CSCC and NCA ECC.
VulnerabilitiesCVE-2024-7399: Samsung MagicINFO Flaw Hits Saudi Bank Branches
CISA-listed CVE-2024-7399 in Samsung MagicINFO 9 Server is being weaponized by Mirai variants. Saudi bank branches running digital signage face a hidden OT/TPRM exposure under SAMA CSCC and NCA ECC.
Compliance & RegulationTrellix Source Code Breach: SAMA CSCC TPRM Lessons for Saudi Banks
Trellix, a major endpoint security vendor used across Saudi banking, disclosed unauthorized access to a portion of its source code repository. Here is what SAMA-regulated institutions must do now under CSCC TPRM controls.
From reading to doing
How ready are you for ECC-2:2024?
Assess your organisation against the NCA Essential Cybersecurity Controls in minutes. It is free and asks for no personal data.
NCA ECC Compliance
Assessment and preparation for compliance with the Essential Cybersecurity Controls (ECC) issued by the National Cybersecurity Aut...
SAMA CSF Compliance
Assessment and preparation for compliance with the Cybersecurity Framework (CSF) issued by the Saudi Central Bank (SAMA)
ISO 27001 Compliance & Certification
Prepare your organization to achieve ISO 27001 certification — the international standard for Information Security Management Syst...