Topic

Network & Infrastructure

Firewalls, VPNs, intrusion detection and zero trust — the network edge where most intrusions begin.

59 articles in this topic

Vulnerabilities

CVE-2026-41096: Windows DNS Client RCE Lets Attackers Hijack Every Endpoint Without a Click

Microsoft's May 2026 Patch Tuesday disclosed CVE-2026-41096, a CVSS 9.8 heap overflow in the Windows DNS Client enabling unauthenticated RCE on every Windows endpoint. Here's what Saudi financial institutions must do now.

21 May 2026 5 min
Vulnerabilities

CVE-2026-20182: Cisco SD-WAN CVSS 10.0 Auth Bypass Actively Exploited — Sixth Zero-Day This Year

Cisco's sixth SD-WAN zero-day in 2026 carries a perfect CVSS 10.0 score and is already being exploited by an advanced threat actor. Saudi financial institutions running SD-WAN fabrics face immediate risk.

20 May 2026 5 min
Vulnerabilities

CVE-2026-20182: Cisco SD-WAN CVSS 10.0 Auth Bypass Under Active Exploitation

A perfect-score CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN is being actively exploited by UAT-8616. If your WAN fabric runs on Cisco, this is not optional reading.

18 May 2026 5 min
Network & Infrastructure

CVE-2026-0300: Critical PAN-OS Buffer Overflow Grants Root Access to Palo Alto Firewalls

A critical buffer overflow in Palo Alto PAN-OS User-ID Authentication Portal is being exploited in the wild, giving attackers root-level code execution on PA-Series and VM-Series firewalls. Here is what Saudi financial CISOs must do now.

18 May 2026 6 min
Network & Infrastructure

CISA BOD 26-02 Deadline Hits: Why Saudi Financial Institutions Must Audit End-of-Life Edge Devices Now

CISA's May 2026 deadline for BOD 26-02 forces a global reckoning on unsupported edge devices. Saudi financial institutions running end-of-life firewalls and VPN appliances face identical threats from nation-state actors — here's what CISOs must do now.

18 May 2026 5 min
Vulnerabilities

CVE-2026-20182: Cisco SD-WAN Zero-Day Gives Attackers Full Admin Access Without Credentials

A CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN Controller is under active exploitation, letting attackers seize full admin control of enterprise network fabrics without any credentials.

16 May 2026 4 min
Vulnerabilities

CVE-2026-41096: Critical Windows DNS Client RCE Threatens Every Endpoint

CVE-2026-41096 scores CVSS 9.8—a heap overflow in Windows DNS Client allows unauthenticated RCE on every Windows machine via a single malicious DNS response. Here's what Saudi financial institutions must do now.

16 May 2026 4 min
Network & Infrastructure

CVE-2026-0300: Palo Alto PAN-OS Zero-Day Gives Attackers Root on Your Perimeter Firewall

A critical buffer overflow in Palo Alto PAN-OS User-ID Authentication Portal is being exploited in the wild—giving attackers root-level code execution on PA-Series and VM-Series firewalls without any credentials.

14 May 2026 5 min
Vulnerabilities

Ivanti EPMM Zero-Day CVE-2026-6973: RCE Hits Enterprise Mobile Management

Ivanti's Endpoint Manager Mobile zero-day CVE-2026-6973 is under active exploitation. Attackers chain stolen credentials with an input validation flaw to achieve full RCE on EPMM appliances managing thousands of corporate devices.

12 May 2026 5 min
Vulnerabilities

PAN-OS Zero-Day CVE-2026-0300: Root-Level RCE Threatens SAMA-Regulated Firewalls

A critical buffer overflow in Palo Alto PAN-OS (CVSS 9.3) is being exploited in the wild to achieve root-level code execution on firewalls — with no authentication required. SAMA-regulated institutions running PA-Series or VM-Series must mitigate immediately.

11 May 2026 5 min
Vulnerabilities

Ivanti EPMM CVE-2026-6973 RCE Exploited: SAMA Bank MDM Risk

CISA added Ivanti EPMM CVE-2026-6973 to the KEV catalog after confirmed in-the-wild exploitation. Saudi banks running on-prem MDM face severe risk to mobile device fleets and corporate data.

10 May 2026 3 min
Vulnerabilities

D-Link CVE-2026-0625 Zero-Day: DNS Hijack Risk for SAMA Banks

An unauthenticated RCE in end-of-life D-Link DSL routers (CVE-2026-0625, CVSS 9.3) enables silent DNS redirection. SAMA-regulated banks now face customer-side credential theft and BEC fraud at scale.

10 May 2026 4 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality