Topic
Supply Chain & Third Party
Attacks that arrive through vendors, software packages and the third-party platforms you trust.
40 articles in this topic
Ransomware Negotiator Convicted of Aiding BlackCat: Third-Party IR Vendor Risk for SAMA Banks
A ransomware negotiator pleaded guilty to feeding victim secrets to BlackCat operators — exposing a $75M insider threat that SAMA-regulated banks cannot ignore.
Malware & Threat ActorsJDownloader Python RAT Supply Chain Attack: SAMA Bank Risk
Attackers compromised the official JDownloader website between May 6 and May 7, 2026, swapping legitimate Windows and Linux installers with a modular Python RAT. Here is what SAMA-regulated banks must do now.
Supply Chain & Third PartyMini Shai-Hulud Supply Chain Attack: SAMA Bank DevSecOps Risk
A new worm campaign compromised PyTorch Lightning, intercom-client and 1,800+ developer repos across npm, PyPI and PHP. Here is what SAMA-regulated banks must do now.
Supply Chain & Third PartyTrellix Source Code Breach: Supply Chain Threat to SAMA Banks
Trellix confirmed unauthorized access to its source code repository in May 2026. For SAMA-regulated banks relying on Trellix XDR and EDR, this incident raises urgent supply chain and third-party risk questions under SAMA CSCC.
Malware & Threat ActorsDAEMON Tools Supply Chain Backdoor: SAMA Bank Endpoint Risk
Kaspersky uncovered a trojanized DAEMON Tools installer distributing a Chinese-linked backdoor through the vendor's official domain since April 8, 2026 — a direct test of SAMA CSCC software supply chain controls.
Breaches & Data LeaksMarquis Breach Expands to 80 Banks: SonicWall Lessons for SAMA Third-Party Risk
The Marquis ransomware breach has expanded to 80 banks and 824,000 customers — exploited through a SonicWall firewall flaw. Here's what SAMA-regulated banks must do now to harden third-party and perimeter controls.
Supply Chain & Third PartyMini Shai-Hulud SAP npm Attack: SAMA Bank Supply Chain Lessons
Compromised SAP CAP npm packages exfiltrate developer and CI/CD secrets through a Bun-based loader. Here is what SAMA-regulated banks must verify now.
Supply Chain & Third PartyPyTorch Lightning PyPI Hijack: SAMA Bank AI Supply Chain Risk
On April 30, 2026, attackers pushed malicious PyTorch Lightning packages to PyPI to harvest CI/CD secrets. Here is what SAMA-regulated banks must do under CSCC supply chain controls.
Breaches & Data LeaksVercel-Context AI OAuth Breach: SaaS Supply Chain Lessons for SAMA Banks
A single employee-installed AI plugin gave attackers OAuth access to Vercel's corporate Google environment. The blast radius reached hundreds of downstream organizations — and exposes a control gap that SAMA-regulated banks routinely overlook.
Breaches & Data LeaksPyTorch Lightning PyPI Hack: Shai-Hulud Worm Hits Saudi Bank AI
On April 30, 2026, PyTorch Lightning 2.6.2 and 2.6.3 were compromised by a Mini Shai-Hulud worm stealing credentials and poisoning GitHub. Saudi banks running AI/ML workloads face an urgent SAMA CSCC TPRM event.
Supply Chain & Third PartyBitwarden CLI Compromised: Supply Chain Attack Puts Saudi Bank CI/CD Secrets at Risk
On April 22, a malicious Bitwarden CLI version was live on npm for 93 minutes — stealing SSH keys, cloud secrets, and CI/CD tokens. Here's what Saudi financial institutions must do immediately.
Breaches & Data LeaksShinyHunters Breach Anodot to Compromise Dozens of Snowflake Accounts: A Supply Chain Wake-Up Call for Saudi Financial Institutions
On April 7, 2026, the ShinyHunters gang breached AI analytics firm Anodot and weaponized stolen Snowflake authentication tokens against dozens of companies. Saudi financial institutions using cloud data platforms face direct SAMA CSCC third-party risk exposure — here's what you must do now.