Topic
Security Updates
Monthly patch cycles from the major vendors, and what to patch first.
9 articles in this topic
MiniPlasma Zero-Day: A Six-Year-Old Windows Flaw Returns to Grant SYSTEM Access on Fully Patched Machines
A weaponized PoC exploit dubbed MiniPlasma grants SYSTEM privileges on fully patched Windows 11 by abusing a Cloud Filter driver flaw Microsoft supposedly fixed in 2020. No patch exists today.
VulnerabilitiesWindows MiniPlasma Zero-Day Grants SYSTEM Access on Fully Patched Systems — PoC Is Public
A weaponized PoC exploit called MiniPlasma grants SYSTEM privileges on fully patched Windows 11 systems by exploiting a six-year-old flaw in the Cloud Filter driver. Here's what Saudi financial institutions must do now.
VulnerabilitiesMicrosoft May 2026 Patch Tuesday: Azure DevOps CVSS 10.0 and Netlogon RCE Demand Immediate Action
Microsoft patched 118 vulnerabilities in May 2026, including CVE-2026-42826 — a perfect CVSS 10.0 Azure DevOps information disclosure flaw exploitable without authentication. Here's what Saudi financial institutions must patch first.
VulnerabilitiesMicrosoft May 2026 Patch Tuesday: Netlogon RCE Flaw CVE-2026-41089 Threatens Every Domain Controller
Microsoft patched 137 vulnerabilities in May 2026 — but one stands out: CVE-2026-41089 lets unauthenticated attackers execute code as SYSTEM on domain controllers via a single network request.
VulnerabilitiesCVE-2026-32201: Microsoft SharePoint Zero-Day Added to CISA KEV — Saudi Financial Institutions Must Patch Now
Microsoft's April 2026 Patch Tuesday confirmed active exploitation of CVE-2026-32201, a SharePoint Server spoofing zero-day now on CISA's KEV list. Saudi banks and financial firms relying on SharePoint for document management face credential theft and phishing risk until patched.
VulnerabilitiesApril 2026 Patch Tuesday: The Wormable Windows TCP/IP Flaw (CVE-2026-33827) Saudi Financial Teams Cannot Delay
Microsoft's second-largest Patch Tuesday ever drops 168 fixes, including a wormable TCP/IP RCE (CVSS 9.8) and an Active Directory flaw targeting every Windows Server from 2012 R2 to 2025. Here's what Saudi financial CISOs must patch first and why.
VulnerabilitiesCisco Patches Four Critical Flaws (CVSS 9.9) in ISE and Webex — Saudi Financial Networks Face Immediate NAC and Collaboration Risk
Cisco has disclosed four critical vulnerabilities — CVSS scores reaching 9.9 — in Identity Services Engine and Webex. For Saudi financial institutions running Cisco ISE as their NAC backbone, these flaws represent a direct path to full network compromise and unauthorized user impersonation.
VulnerabilitiesMicrosoft April 2026 Patch Tuesday: CVE-2026-33824 Windows IKE CVSS 9.8 Demands Immediate Action from Saudi Financial Institutions
167 vulnerabilities patched in one update cycle — including a CVSS 9.8 unauthenticated RCE in Windows IKE. Here's exactly what SAMA-regulated institutions must prioritize before this week ends.
VulnerabilitiesMicrosoft Patches Four Critical Azure Flaws at CVSS 10.0 — Saudi Banks on Azure Must Act Now
Microsoft disclosed four critical Azure vulnerabilities — two scoring a perfect CVSS 10.0 — affecting AI Foundry, Kubernetes Service, Custom Locations, and MCP Server. Saudi banks running workloads on Azure face urgent remediation requirements under SAMA CSCC.