Topic

Ransomware

Ransomware crews, double-extortion tradecraft, and what each campaign means for Saudi financial institutions.

42 articles in this topic

Vulnerabilities

cPanel Auth Bypass CVE-2026-41940: 1.5M Servers at Risk, Ransomware in the Wild

A CVSS 9.8 authentication bypass in cPanel & WHM has been weaponized since February 2026. With 1.5 million exposed instances and ransomware already deploying, Saudi financial institutions must audit their hosting infrastructure now.

11 May 2026 5 min
Ransomware

Ransomware Negotiator Convicted of Aiding BlackCat: Third-Party IR Vendor Risk for SAMA Banks

A ransomware negotiator pleaded guilty to feeding victim secrets to BlackCat operators — exposing a $75M insider threat that SAMA-regulated banks cannot ignore.

11 May 2026 5 min
Ransomware

Everest Ransomware Hits US Banks: Vendor Risk Lessons for SAMA

Everest ransomware claimed breaches at Frost Bank and Citizens Financial Group through a shared third-party vendor, exposing 250K+ customer records. SAMA-regulated banks face the same supply chain exposure — here is what every CISO must do now.

10 May 2026 4 min
Ransomware

Anubis Ransomware Adds Wiper: Critical Risk to SAMA Banks

Anubis ransomware-as-a-service now includes a destructive wiper alongside double extortion, breaking the traditional ransomware bargain. Saudi banks must adapt SAMA CSCC defenses immediately.

10 May 2026 4 min
Ransomware

NightSpire Ransomware Targets Financial Sector: SAMA Bank Defense Guide

NightSpire is rewriting double-extortion playbooks against the financial sector. Here is what SAMA-regulated banks must do to harden Fortinet edges, blunt CVE-2024-55591, and survive 48-hour ransom deadlines.

9 May 2026 4 min
Guides & Lessons

DigitalMint Insider Threat: $75M Lesson for SAMA Banks

A trusted ransomware negotiator betrayed his clients and funneled $75.25M to BlackCat. Here's what SAMA-regulated banks must change in their incident response vendor due diligence today.

9 May 2026 5 min
Ransomware

Akira Ransomware vs SonicWall VPN: Critical Risk to SAMA Banks

Akira ransomware affiliates exploit SonicWall SSL VPN to encrypt SAMA banks in under 4 hours, bypassing MFA. See defense steps and CSCC alignment.

9 May 2026 4 min
Ransomware

Fiserv Everest Ransomware Attack: Vendor Risk to SAMA Banks

Fiserv listed on Everest ransomware leak site after early-May 2026 attack. What SAMA-regulated banks must do now to assess fintech vendor exposure under CSCC.

8 May 2026 4 min
Ransomware

The Gentlemen Ransomware Surge: GPO Detonation Threat to SAMA Banks

The Gentlemen RaaS jumped from 35 to 182 victims in one quarter, targeting banks like Warka via SystemBC tunnels and GPO mass-detonation. Defense lessons for SAMA-regulated institutions.

6 May 2026 4 min
Ransomware

Everest Ransomware Hits Fiserv: SAMA Bank Payment Risk Lessons

On May 3, 2026, Everest ransomware claimed Fiserv — a global payments and core banking provider. SAMA-regulated banks face renewed third-party risk pressure and must respond.

5 May 2026 4 min
Ransomware

Akira Ransomware Bypasses MFA on SonicWall VPNs: SAMA Bank Defense Guide

Akira ransomware operators are now bypassing MFA on SonicWall SSL VPNs by exfiltrating OTP seed values from compromised firewalls. SAMA-regulated banks face urgent perimeter risk that demands immediate CSCC-aligned controls.

3 May 2026 5 min
Ransomware

DragonForce Hits Conrad Capital: 74GB Breach Lessons for SAMA Banks

DragonForce ransomware breached US investment advisor Conrad Capital, exfiltrating 74.23GB and demanding negotiations within five days. We unpack the attack and what SAMA-regulated Saudi institutions must harden in CSCC controls today.

3 May 2026 4 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality