Topic
Software Engineering
Building software securely — DevSecOps, delivery pipelines and code quality.
24 articles in this topic
Langflow CVE-2026-33017 RCE: AI Pipeline Threat to SAMA Banks
An unauthenticated RCE in Langflow's public flow endpoint puts AI orchestration pipelines at Saudi financial institutions in the crosshairs. Here is what SAMA-regulated banks must do this week.
VulnerabilitiesCVE-2026-3854: GitHub RCE Threatens SAMA Bank Source Code
A single crafted git push gave attackers cross-tenant RCE on GitHub, exposing millions of private repositories. With 88% of self-hosted GHES still vulnerable, SAMA-regulated banks face a direct threat to their source code crown jewels and CSCC compliance posture.
VulnerabilitiesCVE-2026-3854: GitHub RCE via Git Push Threatens Saudi Bank CI/CD
A critical 8.7 CVSS GitHub vulnerability lets any authenticated user execute code through a single git push command. Saudi banks running GHES face full source-code and secrets exposure under SAMA CSCC.
VulnerabilitiesCVE-2026-3854: A Single Git Push Hijacks GitHub — Saudi Banks at Risk
A single git push can now grant full remote code execution on GitHub Enterprise Server. For Saudi financial institutions running internal repositories, CVE-2026-3854 is more than a DevOps incident — it is a SAMA CSCC source-code protection breach waiting to happen.
Supply Chain & Third PartyBitwarden CLI Compromised: Supply Chain Attack Puts Saudi Bank CI/CD Secrets at Risk
On April 22, a malicious Bitwarden CLI version was live on npm for 93 minutes — stealing SSH keys, cloud secrets, and CI/CD tokens. Here's what Saudi financial institutions must do immediately.
Supply Chain & Third PartyAxios npm Supply Chain Attack by UNC1069: Saudi Financial DevOps Alert
UNC1069 compromised Axios npm with the WAVESHAPER.V2 backdoor, exposing over 100M weekly downloads. Saudi financial institutions must audit dependency trees and CI/CD pipelines immediately.
Software EngineeringTrivy Supply Chain Attack Breaches European Commission — Why Saudi Banks Must Audit Their DevSecOps Tools
A compromised build of Trivy — one of the most trusted open-source vulnerability scanners — gave TeamPCP a backdoor into the European Commission's AWS infrastructure. If your DevSecOps pipeline trusts open-source tools implicitly, your institution could be next.
Malware & Threat ActorsFake Claude Code Leak on GitHub Delivers Vidar Stealer — Why Saudi Bank Dev Teams Must Vet Every Download
A fake Claude Code repository on GitHub is delivering Vidar infostealer and GhostSocks proxy malware to developers who download it. Here's what Saudi bank security teams need to know — and do — right now.
Software EngineeringTeamPCP's Trivy Supply Chain Attack Exposed 30 EU Entities — Is Your CI/CD Pipeline the Next Target?
A single compromised open-source tool gave attackers access to AWS secrets across 1,000+ SaaS environments. Saudi financial institutions running similar CI/CD pipelines face the same exposure.
Supply Chain & Third PartyTrivy Supply Chain Attack CVE-2026-33634: When Your Security Scanner Becomes the Threat
Attackers compromised Aqua Security's Trivy scanner to harvest CI/CD secrets from thousands of pipelines. Here's what happened, who's behind it, and why Saudi financial institutions running Trivy must act immediately.
VulnerabilitiesCVE-2026-33017: Langflow AI Pipeline RCE Exploited in 20 Hours — What CISOs Must Know
A critical code injection flaw in Langflow was weaponized within 20 hours of disclosure. If your organization runs AI workflow platforms, here's what you need to do immediately.
VulnerabilitiesLangflow AI Exploited in 20 Hours: Why Saudi Financial Institutions Must Secure AI Pipelines
A critical unauthenticated RCE flaw in Langflow was weaponized within 20 hours of disclosure. Here's what SAMA-regulated institutions adopting AI must do immediately.