Topic

Software Engineering

Building software securely — DevSecOps, delivery pipelines and code quality.

24 articles in this topic

Vulnerabilities

Langflow CVE-2026-33017 RCE: AI Pipeline Threat to SAMA Banks

An unauthenticated RCE in Langflow's public flow endpoint puts AI orchestration pipelines at Saudi financial institutions in the crosshairs. Here is what SAMA-regulated banks must do this week.

6 May 2026 3 min
Vulnerabilities

CVE-2026-3854: GitHub RCE Threatens SAMA Bank Source Code

A single crafted git push gave attackers cross-tenant RCE on GitHub, exposing millions of private repositories. With 88% of self-hosted GHES still vulnerable, SAMA-regulated banks face a direct threat to their source code crown jewels and CSCC compliance posture.

4 May 2026 4 min
Vulnerabilities

CVE-2026-3854: GitHub RCE via Git Push Threatens Saudi Bank CI/CD

A critical 8.7 CVSS GitHub vulnerability lets any authenticated user execute code through a single git push command. Saudi banks running GHES face full source-code and secrets exposure under SAMA CSCC.

1 May 2026 4 min
Vulnerabilities

CVE-2026-3854: A Single Git Push Hijacks GitHub — Saudi Banks at Risk

A single git push can now grant full remote code execution on GitHub Enterprise Server. For Saudi financial institutions running internal repositories, CVE-2026-3854 is more than a DevOps incident — it is a SAMA CSCC source-code protection breach waiting to happen.

29 Apr 2026 4 min
Supply Chain & Third Party

Bitwarden CLI Compromised: Supply Chain Attack Puts Saudi Bank CI/CD Secrets at Risk

On April 22, a malicious Bitwarden CLI version was live on npm for 93 minutes — stealing SSH keys, cloud secrets, and CI/CD tokens. Here's what Saudi financial institutions must do immediately.

25 Apr 2026 6 min
Supply Chain & Third Party

Axios npm Supply Chain Attack by UNC1069: Saudi Financial DevOps Alert

UNC1069 compromised Axios npm with the WAVESHAPER.V2 backdoor, exposing over 100M weekly downloads. Saudi financial institutions must audit dependency trees and CI/CD pipelines immediately.

16 Apr 2026 6 min
Software Engineering

Trivy Supply Chain Attack Breaches European Commission — Why Saudi Banks Must Audit Their DevSecOps Tools

A compromised build of Trivy — one of the most trusted open-source vulnerability scanners — gave TeamPCP a backdoor into the European Commission's AWS infrastructure. If your DevSecOps pipeline trusts open-source tools implicitly, your institution could be next.

6 Apr 2026 5 min
Malware & Threat Actors

Fake Claude Code Leak on GitHub Delivers Vidar Stealer — Why Saudi Bank Dev Teams Must Vet Every Download

A fake Claude Code repository on GitHub is delivering Vidar infostealer and GhostSocks proxy malware to developers who download it. Here's what Saudi bank security teams need to know — and do — right now.

5 Apr 2026 5 min
Software Engineering

TeamPCP's Trivy Supply Chain Attack Exposed 30 EU Entities — Is Your CI/CD Pipeline the Next Target?

A single compromised open-source tool gave attackers access to AWS secrets across 1,000+ SaaS environments. Saudi financial institutions running similar CI/CD pipelines face the same exposure.

4 Apr 2026 5 min
Supply Chain & Third Party

Trivy Supply Chain Attack CVE-2026-33634: When Your Security Scanner Becomes the Threat

Attackers compromised Aqua Security's Trivy scanner to harvest CI/CD secrets from thousands of pipelines. Here's what happened, who's behind it, and why Saudi financial institutions running Trivy must act immediately.

1 Apr 2026 5 min
Vulnerabilities

CVE-2026-33017: Langflow AI Pipeline RCE Exploited in 20 Hours — What CISOs Must Know

A critical code injection flaw in Langflow was weaponized within 20 hours of disclosure. If your organization runs AI workflow platforms, here's what you need to do immediately.

31 Mar 2026 5 min
Vulnerabilities

Langflow AI Exploited in 20 Hours: Why Saudi Financial Institutions Must Secure AI Pipelines

A critical unauthenticated RCE flaw in Langflow was weaponized within 20 hours of disclosure. Here's what SAMA-regulated institutions adopting AI must do immediately.

31 Mar 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality