Topic
Guides & Lessons
A series of practical lessons and guides in cybersecurity and AI — from fundamentals to practice.
43 articles in this topic
Instructure Pays ShinyHunters Ransom After 275M Canvas Records Stolen: SaaS Vendor Risk Lessons for Financial Institutions
Instructure paid ShinyHunters after 275M Canvas records were stolen in two breaches within one week. Critical SaaS vendor risk lessons for SAMA-regulated financial institutions.
RansomwareWhen Your Ransomware Negotiator Works for the Attackers: Insider Threat Lessons from the BlackCat Case
A ransomware negotiator secretly fed attackers his clients' confidential strategy—inflating a $25M payout. This case exposes a critical blind spot in third-party risk management for financial institutions.
RansomwareNitrogen Ransomware Hits Foxconn: Supply Chain Lessons for Saudi Financial Institutions
Nitrogen ransomware breached Foxconn, exfiltrating 8TB of confidential data from Apple, Google, and Intel projects. Here's what Saudi financial institutions must learn about supply chain risk under SAMA CSCC.
Breaches & Data LeaksCanvas LMS Mega-Breach: Lessons in Third-Party SaaS Risk for Saudi Institutions
ShinyHunters compromised Instructure's Canvas LMS, exposing data from 8,800+ institutions and 275 million users — the largest educational breach in history. Here's what Saudi organizations must learn about third-party SaaS risk.
RansomwareEverest Ransomware Hits US Banks: Vendor Risk Lessons for SAMA
Everest ransomware claimed breaches at Frost Bank and Citizens Financial Group through a shared third-party vendor, exposing 250K+ customer records. SAMA-regulated banks face the same supply chain exposure — here is what every CISO must do now.
Guides & LessonsDigitalMint Insider Threat: $75M Lesson for SAMA Banks
A trusted ransomware negotiator betrayed his clients and funneled $75.25M to BlackCat. Here's what SAMA-regulated banks must change in their incident response vendor due diligence today.
Breaches & Data LeaksItron Utility Breach: Critical Infrastructure Lessons for SAMA Banks
Utility tech giant Itron disclosed an intrusion into internal systems. For Saudi banks under SAMA CSCC, this is a sharp reminder: third-party assurance is non-negotiable.
Breaches & Data LeaksShinyHunters' 9M-Record Medtronic Hack: SAMA Bank Lessons
ShinyHunters claimed 9 million records stolen from Medtronic, then quietly delisted the victim. Saudi banks face the same pure-extortion playbook — here is how to prepare.
Breaches & Data LeaksMarquis Breach Expands to 80 Banks: SonicWall Lessons for SAMA Third-Party Risk
The Marquis ransomware breach has expanded to 80 banks and 824,000 customers — exploited through a SonicWall firewall flaw. Here's what SAMA-regulated banks must do now to harden third-party and perimeter controls.
RansomwareEverest Ransomware Hits Fiserv: SAMA Bank Payment Risk Lessons
On May 3, 2026, Everest ransomware claimed Fiserv — a global payments and core banking provider. SAMA-regulated banks face renewed third-party risk pressure and must respond.
Breaches & Data LeaksMarquis Breach Hits 80 Banks: SAMA Vendor Risk Lessons for Saudi CISOs
The Marquis Software ransomware breach exposed 824,000 customers across 80 US banks via a single SonicWall CVE. Here is the SAMA CSCC 3.4 vendor-risk playbook every Saudi CISO must apply now.
Supply Chain & Third PartyMini Shai-Hulud SAP npm Attack: SAMA Bank Supply Chain Lessons
Compromised SAP CAP npm packages exfiltrate developer and CI/CD secrets through a Bun-based loader. Here is what SAMA-regulated banks must verify now.