Topic
Software Engineering
Building software securely — DevSecOps, delivery pipelines and code quality.
24 articles in this topic
CVE-2026-21858: Critical n8n RCE Flaw Gives Attackers Full Control of Your Automation Pipelines
A perfect CVSS 10.0 unauthenticated RCE in n8n lets attackers hijack automation pipelines and every system they connect to. Here's what Saudi institutions must do now.
Breaches & Data LeaksGitHub Breached via Poisoned VS Code Extension: 3,800 Internal Repos Exfiltrated by TeamPCP
A poisoned VS Code extension gave TeamPCP access to 3,800 GitHub internal repositories — exposing Copilot, Actions, and CodeQL source code. Here's what Saudi CISOs must do about developer tool supply chain risk.
Supply Chain & Third PartyMini Shai-Hulud: SAP npm Supply Chain Attack Steals Developer Credentials and CI/CD Secrets
Four official SAP npm packages were compromised with credential-stealing malware in the Mini Shai-Hulud campaign. Here's what Saudi financial CISOs must do to protect their SAP development pipelines.
Software EngineeringGrafana GitHub Token Breach: How a CI/CD Misconfiguration Exposed the Codebase Behind Your SOC Dashboards
A single misconfigured GitHub Action let attackers steal Grafana's entire codebase. For Saudi financial institutions relying on Grafana for SOC dashboards, the breach raises urgent questions about CI/CD pipeline security and open-source supply chain risk.
Supply Chain & Third PartyMini Shai-Hulud Worm: How One npm Install Compromised 160+ Packages and Stole CI/CD Secrets
A self-propagating worm dubbed Mini Shai-Hulud hijacked 160+ npm and PyPI packages — including TanStack and Mistral AI — turning every compromised developer into a new infection vector. Here's what your DevSecOps team needs to act on immediately.
Software EngineeringGrafana GitHub Token Breach: CI/CD Pipeline Flaw Exposes Source Code to Extortion
Grafana Labs lost its entire source code after an attacker exploited a GitHub Actions misconfiguration. Learn how CI/CD pipeline vulnerabilities threaten Saudi financial institutions and what SAMA CSCC demands.
Software EngineeringMini Shai-Hulud Supply Chain Worm Hits TanStack and Breaches OpenAI Through Trusted CI/CD Pipelines
A self-spreading worm hijacked TanStack's legitimate GitHub Actions pipeline, published malicious packages indistinguishable from real ones, and breached OpenAI — exposing fatal gaps in software supply chain security.
VulnerabilitiesCVE-2026-3854: Critical GitHub RCE Flaw Exposed Millions of Repositories via Single Git Push
A single git push command was all it took to execute arbitrary code on GitHub's backend servers. CVE-2026-3854 exposed millions of public and private repositories — here's what Saudi financial institutions must do now.
Software EngineeringRubyGems Shuts Down Signups After BufferZoneCorp Supply Chain Attack Hits CI/CD Pipelines
RubyGems suspended new registrations after hundreds of malicious sleeper packages drained AWS keys, SSH credentials, and GitHub tokens from CI/CD pipelines — a wake-up call for every organization running open-source dependencies.
Software EngineeringCheckmarx Jenkins Plugin Backdoored by TeamPCP: CI/CD Supply Chain Under Siege
A rogue version of the Checkmarx Jenkins AST plugin was uploaded to the Jenkins Marketplace, turning trusted security tooling into an infostealer. Here's what happened and why SAMA-regulated institutions must audit their pipelines immediately.
Supply Chain & Third PartyMini Shai-Hulud Supply Chain Attack: SAMA Bank DevSecOps Risk
A new worm campaign compromised PyTorch Lightning, intercom-client and 1,800+ developer repos across npm, PyPI and PHP. Here is what SAMA-regulated banks must do now.
Cloud & IdentityTeamPCP Cloud Compromise: CI/CD Threat for SAMA Banks
TeamPCP weaponized open-source security tools (Trivy, LiteLLM, KICS) to harvest CI/CD secrets and pivot into AWS, Azure and SaaS environments. SAMA-regulated banks must reassess third-party and pipeline trust now.