Topic

Network & Infrastructure

Firewalls, VPNs, intrusion detection and zero trust — the network edge where most intrusions begin.

59 articles in this topic

Vulnerabilities

SonicWall SonicOS Trio (CVE-2026-0204/0205/0206) Threatens Saudi Bank Perimeters

Three newly disclosed SonicOS vulnerabilities — including a CVSS 8.0 access-control bypass — put SonicWall Gen6/7/8 firewalls at risk across Saudi banking perimeters. Here is the SAMA CSCC remediation playbook.

3 May 2026 4 min
Compliance & Regulation

Cisco SD-WAN Manager Bugs in CISA KEV Threaten Saudi Banks

CISA flagged three Cisco Catalyst SD-WAN Manager vulnerabilities — CVE-2026-20122, CVE-2026-20128, and CVE-2026-20133 — as actively exploited. Saudi banks running branch SD-WAN must patch immediately to preserve SAMA CSCC and NCA ECC compliance.

2 May 2026 4 min
Vulnerabilities

CVE-2026-33824: Windows IKE Zero-Click RCE Threatens Saudi Bank VPNs

Microsoft's April 2026 Patch Tuesday disclosed CVE-2026-33824, a critical double-free in Windows IKE Service Extensions (CVSS 9.8) that enables zero-click remote code execution on IPSec endpoints — the exact technology Saudi banks rely on for branch and partner connectivity.

2 May 2026 4 min
Vulnerabilities

CVE-2026-20133: Cisco SD-WAN Manager Leak Hits Saudi Bank Branches

CISA added Cisco Catalyst SD-WAN Manager flaw CVE-2026-20133 to KEV. Active exploitation exposes file-system data on the controller binding Saudi bank branches. Patch and assess now.

1 May 2026 4 min
Vulnerabilities

CVE-2026-4112: SonicWall SMA1000 SQL Injection Threatens Saudi Bank VPNs

A newly disclosed SonicWall SMA1000 SQL injection flaw (CVE-2026-4112) lets read-only administrators escalate to primary admin and seize bank VPN gateways. Saudi financial institutions must act under SAMA CSCC.

30 Apr 2026 4 min
Vulnerabilities

CVE-2026-20147: Cisco ISE RCE Chain Hits Saudi Bank NAC Backbone

Three critical Cisco ISE vulnerabilities allow authenticated attackers to escalate to root on the very appliance that authorizes every device on a Saudi bank's network — a direct hit on SAMA CSCC segmentation and NCA ECC identity controls.

30 Apr 2026 4 min
Vulnerabilities

CVE-2026-33824: Windows IKE Zero-Day Threatens Saudi Bank VPNs

An unauthenticated attacker can take over Windows IKE/IPsec VPN servers via UDP 500/4500 — CVSS 9.8. Saudi banks running Windows IKEv2 must patch immediately.

30 Apr 2026 4 min
Vulnerabilities

CVE-2026-1281 & CVE-2026-1340: The Ivanti EPMM Zero-Days Putting Saudi Bank MDM Fleets at Risk

A single bulletproof-hosted IP is driving 83% of active Ivanti EPMM exploitation via CVE-2026-1281 and CVE-2026-1340. Saudi banks running on-prem MDM face direct SAMA CSCC exposure — here is what to patch, hunt, and rotate now.

19 Apr 2026 4 min
Vulnerabilities

CVE-2026-21643: The Fortinet FortiClient EMS Zero-Auth SQL Injection CISA Is Flagging — Action Required for Saudi Financial Institutions

CISA confirmed active exploitation of CVE-2026-21643 on April 13, 2026 — a pre-authentication SQL injection in Fortinet FortiClient EMS with a CVSS score of 9.1. Saudi financial institutions running affected versions must patch immediately or face direct risk of unauthorized remote code execution with no credentials required.

19 Apr 2026 5 min
Ransomware

The Gentlemen: The RaaS Group That Built a Database of 14,700 FortiGate Devices — and Why Saudi Financial Institutions Are in the Crosshairs

The Gentlemen ransomware group has grown 420% in a single quarter and maintains a database of 14,700 pre-exploited FortiGate devices. Saudi financial institutions running FortiOS must act now — here is what you need to know.

19 Apr 2026 5 min
Network & Infrastructure

88% of Firewall Brute-Force Attacks Now Originate from the Middle East — Saudi Financial Perimeter Security Under Siege

Barracuda's SOC data reveals that 88% of surging brute-force attacks against SonicWall and FortiGate perimeter devices in Q1 2026 originate from the Middle East — a direct and escalating threat for Saudi financial institutions.

18 Apr 2026 4 min
Vulnerabilities

CVE-2026-35616: Fortinet FortiClient EMS Zero-Day Under Active Exploitation — A Direct Risk for Saudi Financial Endpoint Security

A critical pre-authentication bypass in Fortinet FortiClient EMS (CVE-2026-35616, CVSS 9.1) is being actively exploited in the wild. Saudi financial institutions relying on Fortinet for endpoint management must act now — CISA already mandated a patch deadline that has passed.

17 Apr 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality