Topic
Compliance & Regulation
Saudi regulatory frameworks — NCA controls, the SAMA framework and the Personal Data Protection Law.
83 articles in this topic
Cisco SD-WAN Manager Bugs in CISA KEV Threaten Saudi Banks
CISA flagged three Cisco Catalyst SD-WAN Manager vulnerabilities — CVE-2026-20122, CVE-2026-20128, and CVE-2026-20133 — as actively exploited. Saudi banks running branch SD-WAN must patch immediately to preserve SAMA CSCC and NCA ECC compliance.
Artificial IntelligenceAgentic AI Risks for Saudi Banks: Five Eyes Guidance Decoded
On April 30, 2026, six Five Eyes cyber agencies released joint guidance on agentic AI security risks. Saudi banks scaling autonomous AI must align with SAMA CSCC and NCA ECC before granting agents broader authority.
VulnerabilitiesCVE-2026-20700: Apple dyld Zero-Day Hits Saudi Bank Mobile Fleets
Apple's first actively exploited zero-day of 2026 — CVE-2026-20700 in dyld — was abused in a surveillance-grade chain against specific targets. Here is what Saudi banks under SAMA CSCC must do now.
RansomwareQilin Ransomware Tops Q1 2026: Threat Profile for Saudi Banks
Qilin became Q1 2026's most active ransomware group with 342 victims worldwide and a sharpened focus on financial services. Here is what Saudi CISOs operating under SAMA CSCC need to act on this quarter.
VulnerabilitiesCVE-2026-41940: cPanel Zero-Day Threatens Saudi Bank Hosting
A critical cPanel authentication bypass (CVE-2026-41940, CVSS 9.8) was exploited as a zero-day for two months before patch. Saudi banks must act on SAMA CSCC patch governance and third-party hosting risk obligations.
VulnerabilitiesCVE-2026-3854: GitHub RCE via Git Push Threatens Saudi Bank CI/CD
A critical 8.7 CVSS GitHub vulnerability lets any authenticated user execute code through a single git push command. Saudi banks running GHES face full source-code and secrets exposure under SAMA CSCC.
RansomwareEverest Ransomware Hits Frost & Citizens Banks: A Saudi TPRM Wake-Up Call
Everest ransomware listed Frost Bank and Citizens Financial Group on its leak site after compromising a shared third-party vendor. For SAMA-regulated banks, this is a textbook stress test of CSCC Domain 4 controls.
VulnerabilitiesCVE-2025-2749: Kentico Xperience RCE Threatens Saudi Bank Web Properties
CISA just added CVE-2025-2749, an authenticated RCE in Kentico Xperience's Staging Sync Server, to the KEV catalog with a May 4, 2026 federal deadline. Here's why Saudi banks running public CMS portals must act now under SAMA CSCC.
VulnerabilitiesCVE-2026-33825: Microsoft Defender Privilege Escalation Hits Saudi Bank Endpoints
Microsoft Defender's CVE-2026-33825 (CVSS 7.8) is being actively exploited as a zero-day for local privilege escalation. Here's what Saudi banks running Defender for Endpoint must do under SAMA CSCC.
Compliance & RegulationSimpleHelp RMM Hits CISA KEV: A Wake-Up Call for Saudi Bank Vendor Risk
On April 24, 2026, CISA added the SimpleHelp RMM authorization chain to its KEV catalog after confirmed ransomware exploitation. For Saudi banks relying on MSPs and remote support vendors, this is a direct SAMA CSCC TPRM trigger.
VulnerabilitiesCVE-2026-32202: Windows Shell Zero-Click NTLM Leak Hits Saudi Banks
CISA confirmed active exploitation of CVE-2026-32202, a zero-click Windows Shell NTLM hash leak born from an incomplete February patch. Saudi banks face SAMA CSCC and lateral movement risk.
VulnerabilitiesCVE-2026-34621: Adobe Reader Zero-Day Hits Saudi Bank PDF Workflows
Adobe rushed an emergency fix for CVE-2026-34621, an Acrobat Reader prototype pollution flaw exploited via weaponized PDFs since late 2025. For Saudi banks where PDF is the universal currency of statements, KYC, and regulatory filings, the patch window has already closed under SAMA CSCC and CISA KEV mandates.
From reading to doing
How ready are you for ECC-2:2024?
Assess your organisation against the NCA Essential Cybersecurity Controls in minutes. It is free and asks for no personal data.
NCA ECC Compliance
Assessment and preparation for compliance with the Essential Cybersecurity Controls (ECC) issued by the National Cybersecurity Aut...
SAMA CSF Compliance
Assessment and preparation for compliance with the Cybersecurity Framework (CSF) issued by the Saudi Central Bank (SAMA)
ISO 27001 Compliance & Certification
Prepare your organization to achieve ISO 27001 certification — the international standard for Information Security Management Syst...