Topic
Ransomware
Ransomware crews, double-extortion tradecraft, and what each campaign means for Saudi financial institutions.
42 articles in this topic
cPanel Auth Bypass CVE-2026-41940: 1.5M Servers at Risk, Ransomware in the Wild
A CVSS 9.8 authentication bypass in cPanel & WHM has been weaponized since February 2026. With 1.5 million exposed instances and ransomware already deploying, Saudi financial institutions must audit their hosting infrastructure now.
RansomwareRansomware Negotiator Convicted of Aiding BlackCat: Third-Party IR Vendor Risk for SAMA Banks
A ransomware negotiator pleaded guilty to feeding victim secrets to BlackCat operators — exposing a $75M insider threat that SAMA-regulated banks cannot ignore.
RansomwareEverest Ransomware Hits US Banks: Vendor Risk Lessons for SAMA
Everest ransomware claimed breaches at Frost Bank and Citizens Financial Group through a shared third-party vendor, exposing 250K+ customer records. SAMA-regulated banks face the same supply chain exposure — here is what every CISO must do now.
RansomwareAnubis Ransomware Adds Wiper: Critical Risk to SAMA Banks
Anubis ransomware-as-a-service now includes a destructive wiper alongside double extortion, breaking the traditional ransomware bargain. Saudi banks must adapt SAMA CSCC defenses immediately.
RansomwareNightSpire Ransomware Targets Financial Sector: SAMA Bank Defense Guide
NightSpire is rewriting double-extortion playbooks against the financial sector. Here is what SAMA-regulated banks must do to harden Fortinet edges, blunt CVE-2024-55591, and survive 48-hour ransom deadlines.
Guides & LessonsDigitalMint Insider Threat: $75M Lesson for SAMA Banks
A trusted ransomware negotiator betrayed his clients and funneled $75.25M to BlackCat. Here's what SAMA-regulated banks must change in their incident response vendor due diligence today.
RansomwareAkira Ransomware vs SonicWall VPN: Critical Risk to SAMA Banks
Akira ransomware affiliates exploit SonicWall SSL VPN to encrypt SAMA banks in under 4 hours, bypassing MFA. See defense steps and CSCC alignment.
RansomwareFiserv Everest Ransomware Attack: Vendor Risk to SAMA Banks
Fiserv listed on Everest ransomware leak site after early-May 2026 attack. What SAMA-regulated banks must do now to assess fintech vendor exposure under CSCC.
RansomwareThe Gentlemen Ransomware Surge: GPO Detonation Threat to SAMA Banks
The Gentlemen RaaS jumped from 35 to 182 victims in one quarter, targeting banks like Warka via SystemBC tunnels and GPO mass-detonation. Defense lessons for SAMA-regulated institutions.
RansomwareEverest Ransomware Hits Fiserv: SAMA Bank Payment Risk Lessons
On May 3, 2026, Everest ransomware claimed Fiserv — a global payments and core banking provider. SAMA-regulated banks face renewed third-party risk pressure and must respond.
RansomwareAkira Ransomware Bypasses MFA on SonicWall VPNs: SAMA Bank Defense Guide
Akira ransomware operators are now bypassing MFA on SonicWall SSL VPNs by exfiltrating OTP seed values from compromised firewalls. SAMA-regulated banks face urgent perimeter risk that demands immediate CSCC-aligned controls.
RansomwareDragonForce Hits Conrad Capital: 74GB Breach Lessons for SAMA Banks
DragonForce ransomware breached US investment advisor Conrad Capital, exfiltrating 74.23GB and demanding negotiations within five days. We unpack the attack and what SAMA-regulated Saudi institutions must harden in CSCC controls today.