Topic

Software Engineering

Building software securely — DevSecOps, delivery pipelines and code quality.

24 articles in this topic

Vulnerabilities

CVE-2026-21858: Critical n8n RCE Flaw Gives Attackers Full Control of Your Automation Pipelines

A perfect CVSS 10.0 unauthenticated RCE in n8n lets attackers hijack automation pipelines and every system they connect to. Here's what Saudi institutions must do now.

21 May 2026 4 min
Breaches & Data Leaks

GitHub Breached via Poisoned VS Code Extension: 3,800 Internal Repos Exfiltrated by TeamPCP

A poisoned VS Code extension gave TeamPCP access to 3,800 GitHub internal repositories — exposing Copilot, Actions, and CodeQL source code. Here's what Saudi CISOs must do about developer tool supply chain risk.

20 May 2026 5 min
Supply Chain & Third Party

Mini Shai-Hulud: SAP npm Supply Chain Attack Steals Developer Credentials and CI/CD Secrets

Four official SAP npm packages were compromised with credential-stealing malware in the Mini Shai-Hulud campaign. Here's what Saudi financial CISOs must do to protect their SAP development pipelines.

20 May 2026 5 min
Software Engineering

Grafana GitHub Token Breach: How a CI/CD Misconfiguration Exposed the Codebase Behind Your SOC Dashboards

A single misconfigured GitHub Action let attackers steal Grafana's entire codebase. For Saudi financial institutions relying on Grafana for SOC dashboards, the breach raises urgent questions about CI/CD pipeline security and open-source supply chain risk.

19 May 2026 5 min
Supply Chain & Third Party

Mini Shai-Hulud Worm: How One npm Install Compromised 160+ Packages and Stole CI/CD Secrets

A self-propagating worm dubbed Mini Shai-Hulud hijacked 160+ npm and PyPI packages — including TanStack and Mistral AI — turning every compromised developer into a new infection vector. Here's what your DevSecOps team needs to act on immediately.

19 May 2026 5 min
Software Engineering

Grafana GitHub Token Breach: CI/CD Pipeline Flaw Exposes Source Code to Extortion

Grafana Labs lost its entire source code after an attacker exploited a GitHub Actions misconfiguration. Learn how CI/CD pipeline vulnerabilities threaten Saudi financial institutions and what SAMA CSCC demands.

18 May 2026 5 min
Software Engineering

Mini Shai-Hulud Supply Chain Worm Hits TanStack and Breaches OpenAI Through Trusted CI/CD Pipelines

A self-spreading worm hijacked TanStack's legitimate GitHub Actions pipeline, published malicious packages indistinguishable from real ones, and breached OpenAI — exposing fatal gaps in software supply chain security.

16 May 2026 5 min
Vulnerabilities

CVE-2026-3854: Critical GitHub RCE Flaw Exposed Millions of Repositories via Single Git Push

A single git push command was all it took to execute arbitrary code on GitHub's backend servers. CVE-2026-3854 exposed millions of public and private repositories — here's what Saudi financial institutions must do now.

13 May 2026 5 min
Software Engineering

RubyGems Shuts Down Signups After BufferZoneCorp Supply Chain Attack Hits CI/CD Pipelines

RubyGems suspended new registrations after hundreds of malicious sleeper packages drained AWS keys, SSH credentials, and GitHub tokens from CI/CD pipelines — a wake-up call for every organization running open-source dependencies.

13 May 2026 5 min
Software Engineering

Checkmarx Jenkins Plugin Backdoored by TeamPCP: CI/CD Supply Chain Under Siege

A rogue version of the Checkmarx Jenkins AST plugin was uploaded to the Jenkins Marketplace, turning trusted security tooling into an infostealer. Here's what happened and why SAMA-regulated institutions must audit their pipelines immediately.

12 May 2026 5 min
Supply Chain & Third Party

Mini Shai-Hulud Supply Chain Attack: SAMA Bank DevSecOps Risk

A new worm campaign compromised PyTorch Lightning, intercom-client and 1,800+ developer repos across npm, PyPI and PHP. Here is what SAMA-regulated banks must do now.

10 May 2026 4 min
Cloud & Identity

TeamPCP Cloud Compromise: CI/CD Threat for SAMA Banks

TeamPCP weaponized open-source security tools (Trivy, LiteLLM, KICS) to harvest CI/CD secrets and pivot into AWS, Azure and SaaS environments. SAMA-regulated banks must reassess third-party and pipeline trust now.

7 May 2026 4 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality