Topic
Ransomware
Ransomware crews, double-extortion tradecraft, and what each campaign means for Saudi financial institutions.
42 articles in this topic
MuddyWater's False-Flag Playbook: Iranian APT Hides Espionage Behind Chaos Ransomware
Iranian APT MuddyWater deployed Chaos ransomware as a decoy while conducting espionage via Microsoft Teams social engineering. Saudi CISOs must rethink their IR playbooks.
Malware & Threat ActorsMuddyWater's Chaos Ransomware Deception: Iranian Espionage Targeting Banks Under False Flag
Iranian APT MuddyWater deploys Chaos ransomware branding to disguise espionage operations targeting banks and defense contractors. Rapid7 research reveals no encryption — only data theft and credential harvesting behind a ransomware smokescreen.
Software EngineeringGrafana GitHub Token Breach: CI/CD Pipeline Flaw Exposes Source Code to Extortion
Grafana Labs lost its entire source code after an attacker exploited a GitHub Actions misconfiguration. Learn how CI/CD pipeline vulnerabilities threaten Saudi financial institutions and what SAMA CSCC demands.
Breaches & Data LeaksInstructure Pays ShinyHunters Ransom After 275M Canvas Records Stolen: SaaS Vendor Risk Lessons for Financial Institutions
Instructure paid ShinyHunters after 275M Canvas records were stolen in two breaches within one week. Critical SaaS vendor risk lessons for SAMA-regulated financial institutions.
Malware & Threat ActorsMuddyWater's False Flag: Iranian APT Hides Espionage Behind Chaos Ransomware
Rapid7 unmasks MuddyWater's Chaos ransomware campaign as Iranian state espionage. Critical lessons for Saudi financial sector CISOs on detecting false-flag operations.
RansomwareWhen Your Ransomware Negotiator Works for the Attackers: Insider Threat Lessons from the BlackCat Case
A ransomware negotiator secretly fed attackers his clients' confidential strategy—inflating a $25M payout. This case exposes a critical blind spot in third-party risk management for financial institutions.
RansomwareVishing and SSO Abuse: How Cybercrime Groups Are Executing Rapid SaaS Extortion in Minutes
Cybercrime groups like ShinyHunters are combining AI-powered vishing calls with SSO exploitation to breach SaaS environments in under 45 minutes. Learn how Saudi financial institutions can defend against this rapidly evolving threat.
RansomwareEverest Ransomware Hits Two US Banks via Third-Party Vendor: A Wake-Up Call for Saudi Financial Sector Supply Chain Security
Everest ransomware breached two US banks through a single shared vendor, exposing 250K customer records. Here's what Saudi financial institutions must learn about third-party risk under SAMA CSCC.
RansomwareNitrogen Ransomware Hits Foxconn: Supply Chain Lessons for Saudi Financial Institutions
Nitrogen ransomware breached Foxconn, exfiltrating 8TB of confidential data from Apple, Google, and Intel projects. Here's what Saudi financial institutions must learn about supply chain risk under SAMA CSCC.
Malware & Threat ActorsMuddyWater's False Flag: Iranian APT Hides Espionage Behind Chaos Ransomware via Microsoft Teams
Iranian state-sponsored group MuddyWater weaponized Microsoft Teams screen-sharing to steal credentials and bypass MFA, planting Chaos ransomware artifacts as a decoy to hide espionage targeting banks and critical infrastructure.
RansomwareEverest Ransomware Breaches TSYS and Two Major Banks Through a Single Vendor
The Everest ransomware group compromised a payment processor and two major US banks through a single third-party vendor — exposing 3.6 million records. Here's what Saudi financial institutions must do about third-party risk now.
Cloud & IdentityFortinet 2026 Threat Report: 389% Ransomware Surge, 1.7B Stolen Credentials, and What It Means for Saudi Finance
Fortinet's FortiGuard Labs confirms 7,831 ransomware victims in 2025 — a 389% spike — fueled by AI-assisted tools and 1.7 billion stolen credentials on the dark web. Saudi financial institutions face unique exposure.