Topic
Compliance & Regulation
Saudi regulatory frameworks — NCA controls, the SAMA framework and the Personal Data Protection Law.
83 articles in this topic
NIST Stops Enriching Most CVEs: Saudi Financial Institutions Must Rebuild Their Vulnerability Management Strategy Now
On April 15, 2026, NIST quietly changed the rules of vulnerability management. Most CVEs will no longer receive severity scores or product details from NVD — and Saudi financial institutions that rely on NVD enrichment for SAMA CSCC compliance are directly exposed.
Compliance & RegulationSDAIA's 48 PDPL Enforcement Decisions: Saudi Financial Institutions Now Face Real Legal Exposure
SDAIA has formally issued 48 enforcement decisions under Saudi Arabia's PDPL. For financial institutions regulated by SAMA, this marks a decisive shift from documentation-based compliance to operational accountability — and the window to self-correct is closing.
Breaches & Data LeaksShinyHunters Hits McGraw-Hill via Salesforce Misconfiguration: 13.5M Records and a Warning Saudi Financial CISOs Must Heed
No malware, no CVE, no phishing — just a Salesforce misconfiguration. ShinyHunters walked out with 13.5 million McGraw-Hill records. Saudi banks running Salesforce or Dynamics 365 hold far more sensitive data and face identical exposure under PDPL and SAMA CSCC.
Phishing & FraudAI-Generated Phishing Is Now the #1 Email Threat of 2026 — A Tactical Response Guide for Saudi Financial CISOs
AI-generated phishing attacks have surged 1,265% since 2023 and now account for 82% of all phishing emails. For Saudi financial institutions under SAMA and NCA oversight, the stakes — and the compliance obligations — have never been higher.
Compliance & RegulationBooking.com Breach Forces Global PIN Resets — Third-Party Platform Risk Is Now a SAMA Compliance Issue for Saudi Financial Institutions
Booking.com confirmed hackers accessed customer reservation data on April 13, 2026. Saudi financial CISOs must review third-party risk registers, PDPL obligations, and phishing defences immediately.
Breaches & Data LeaksShinyHunters Breach Rockstar via Anodot: Saudi CISO Third-Party Alert
ShinyHunters extracted 78M records from Rockstar via Anodot, a third-party analytics vendor. SAMA CSCC mandates strict third-party risk controls — is your institution compliant?
VulnerabilitiesCritical FortiSandbox Flaws CVE-2026-39808 & CVE-2026-39813: Unauthenticated RCE That Saudi Financial Teams Cannot Afford to Miss
Fortinet disclosed two CVSS 9.1 vulnerabilities in FortiSandbox on April 15, 2026 — CVE-2026-39808 and CVE-2026-39813 — enabling unauthenticated code execution and privilege escalation. Saudi banks relying on FortiSandbox for SAMA CSCC-mandated malware detection must patch now.
VulnerabilitiesCVE-2026-25075: The 15-Year strongSwan Flaw That Can Crash Saudi Banks' VPN With One Packet
A single malformed EAP-TTLS packet can crash strongSwan VPN servers across 15+ years of releases. Saudi banks relying on IPsec/IKEv2 tunnels for branch and remote-access connectivity must patch CVE-2026-25075 to avoid an unauthenticated denial-of-service that SAMA CSCC classifies as a critical availability risk.
Breaches & Data LeaksBooking.com Breach Fuels Spear-Phishing Against Saudi Bank Employees
Booking.com confirmed hackers accessed customer reservation data. Saudi bank employees are now prime spear-phishing targets — here's your SAMA CSCC-aligned response.
Compliance & RegulationMicrosoft Secure Boot Certificates Expire June 26: The 75-Day Countdown Saudi Bank CISOs Cannot Ignore
Microsoft's 2011-era Secure Boot certificates expire June 26, 2026 — and Windows Server won't update itself. Saudi financial institutions have 75 days to act before losing boot-level protection, BitLocker hardening, and SAMA CSCC compliance posture.
Malware & Threat ActorsNorth Korea Stole $285M in 12 Minutes: The DPRK Infiltration Playbook Every Saudi CISO Must Study
North Korean hackers UNC4736 spent six months posing as a legitimate trading firm before draining $285M in 12 minutes. Saudi CISOs must understand this playbook—it maps directly to SAMA CSCC third-party and insider-threat domains.
Breaches & Data LeaksShinyHunters Breaches the European Commission: 350GB Exposed and What Saudi Banks Must Learn Now
ShinyHunters breached the European Commission's Europa.eu, exfiltrating 350GB including databases and contracts. Saudi financial institutions must act now on identity controls, data governance, and PDPL breach notification readiness.