Topic

Security Updates

Monthly patch cycles from the major vendors, and what to patch first.

9 articles in this topic

Vulnerabilities

MiniPlasma Zero-Day: A Six-Year-Old Windows Flaw Returns to Grant SYSTEM Access on Fully Patched Machines

A weaponized PoC exploit dubbed MiniPlasma grants SYSTEM privileges on fully patched Windows 11 by abusing a Cloud Filter driver flaw Microsoft supposedly fixed in 2020. No patch exists today.

21 May 2026 5 min
Vulnerabilities

Windows MiniPlasma Zero-Day Grants SYSTEM Access on Fully Patched Systems — PoC Is Public

A weaponized PoC exploit called MiniPlasma grants SYSTEM privileges on fully patched Windows 11 systems by exploiting a six-year-old flaw in the Cloud Filter driver. Here's what Saudi financial institutions must do now.

19 May 2026 5 min
Vulnerabilities

Microsoft May 2026 Patch Tuesday: Azure DevOps CVSS 10.0 and Netlogon RCE Demand Immediate Action

Microsoft patched 118 vulnerabilities in May 2026, including CVE-2026-42826 — a perfect CVSS 10.0 Azure DevOps information disclosure flaw exploitable without authentication. Here's what Saudi financial institutions must patch first.

19 May 2026 6 min
Vulnerabilities

Microsoft May 2026 Patch Tuesday: Netlogon RCE Flaw CVE-2026-41089 Threatens Every Domain Controller

Microsoft patched 137 vulnerabilities in May 2026 — but one stands out: CVE-2026-41089 lets unauthenticated attackers execute code as SYSTEM on domain controllers via a single network request.

13 May 2026 5 min
Vulnerabilities

CVE-2026-32201: Microsoft SharePoint Zero-Day Added to CISA KEV — Saudi Financial Institutions Must Patch Now

Microsoft's April 2026 Patch Tuesday confirmed active exploitation of CVE-2026-32201, a SharePoint Server spoofing zero-day now on CISA's KEV list. Saudi banks and financial firms relying on SharePoint for document management face credential theft and phishing risk until patched.

18 Apr 2026 5 min
Vulnerabilities

April 2026 Patch Tuesday: The Wormable Windows TCP/IP Flaw (CVE-2026-33827) Saudi Financial Teams Cannot Delay

Microsoft's second-largest Patch Tuesday ever drops 168 fixes, including a wormable TCP/IP RCE (CVSS 9.8) and an Active Directory flaw targeting every Windows Server from 2012 R2 to 2025. Here's what Saudi financial CISOs must patch first and why.

16 Apr 2026 5 min
Vulnerabilities

Cisco Patches Four Critical Flaws (CVSS 9.9) in ISE and Webex — Saudi Financial Networks Face Immediate NAC and Collaboration Risk

Cisco has disclosed four critical vulnerabilities — CVSS scores reaching 9.9 — in Identity Services Engine and Webex. For Saudi financial institutions running Cisco ISE as their NAC backbone, these flaws represent a direct path to full network compromise and unauthorized user impersonation.

16 Apr 2026 5 min
Vulnerabilities

Microsoft April 2026 Patch Tuesday: CVE-2026-33824 Windows IKE CVSS 9.8 Demands Immediate Action from Saudi Financial Institutions

167 vulnerabilities patched in one update cycle — including a CVSS 9.8 unauthenticated RCE in Windows IKE. Here's exactly what SAMA-regulated institutions must prioritize before this week ends.

15 Apr 2026 5 min
Vulnerabilities

Microsoft Patches Four Critical Azure Flaws at CVSS 10.0 — Saudi Banks on Azure Must Act Now

Microsoft disclosed four critical Azure vulnerabilities — two scoring a perfect CVSS 10.0 — affecting AI Foundry, Kubernetes Service, Custom Locations, and MCP Server. Saudi banks running workloads on Azure face urgent remediation requirements under SAMA CSCC.

5 Apr 2026 6 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality