Topic

Supply Chain & Third Party

Attacks that arrive through vendors, software packages and the third-party platforms you trust.

40 articles in this topic

Ransomware

Ransomware Negotiator Convicted of Aiding BlackCat: Third-Party IR Vendor Risk for SAMA Banks

A ransomware negotiator pleaded guilty to feeding victim secrets to BlackCat operators — exposing a $75M insider threat that SAMA-regulated banks cannot ignore.

11 May 2026 5 min
Malware & Threat Actors

JDownloader Python RAT Supply Chain Attack: SAMA Bank Risk

Attackers compromised the official JDownloader website between May 6 and May 7, 2026, swapping legitimate Windows and Linux installers with a modular Python RAT. Here is what SAMA-regulated banks must do now.

11 May 2026 4 min
Supply Chain & Third Party

Mini Shai-Hulud Supply Chain Attack: SAMA Bank DevSecOps Risk

A new worm campaign compromised PyTorch Lightning, intercom-client and 1,800+ developer repos across npm, PyPI and PHP. Here is what SAMA-regulated banks must do now.

10 May 2026 4 min
Supply Chain & Third Party

Trellix Source Code Breach: Supply Chain Threat to SAMA Banks

Trellix confirmed unauthorized access to its source code repository in May 2026. For SAMA-regulated banks relying on Trellix XDR and EDR, this incident raises urgent supply chain and third-party risk questions under SAMA CSCC.

7 May 2026 4 min
Malware & Threat Actors

DAEMON Tools Supply Chain Backdoor: SAMA Bank Endpoint Risk

Kaspersky uncovered a trojanized DAEMON Tools installer distributing a Chinese-linked backdoor through the vendor's official domain since April 8, 2026 — a direct test of SAMA CSCC software supply chain controls.

7 May 2026 4 min
Breaches & Data Leaks

Marquis Breach Expands to 80 Banks: SonicWall Lessons for SAMA Third-Party Risk

The Marquis ransomware breach has expanded to 80 banks and 824,000 customers — exploited through a SonicWall firewall flaw. Here's what SAMA-regulated banks must do now to harden third-party and perimeter controls.

6 May 2026 4 min
Supply Chain & Third Party

Mini Shai-Hulud SAP npm Attack: SAMA Bank Supply Chain Lessons

Compromised SAP CAP npm packages exfiltrate developer and CI/CD secrets through a Bun-based loader. Here is what SAMA-regulated banks must verify now.

4 May 2026 4 min
Supply Chain & Third Party

PyTorch Lightning PyPI Hijack: SAMA Bank AI Supply Chain Risk

On April 30, 2026, attackers pushed malicious PyTorch Lightning packages to PyPI to harvest CI/CD secrets. Here is what SAMA-regulated banks must do under CSCC supply chain controls.

4 May 2026 4 min
Breaches & Data Leaks

Vercel-Context AI OAuth Breach: SaaS Supply Chain Lessons for SAMA Banks

A single employee-installed AI plugin gave attackers OAuth access to Vercel's corporate Google environment. The blast radius reached hundreds of downstream organizations — and exposes a control gap that SAMA-regulated banks routinely overlook.

4 May 2026 4 min
Breaches & Data Leaks

PyTorch Lightning PyPI Hack: Shai-Hulud Worm Hits Saudi Bank AI

On April 30, 2026, PyTorch Lightning 2.6.2 and 2.6.3 were compromised by a Mini Shai-Hulud worm stealing credentials and poisoning GitHub. Saudi banks running AI/ML workloads face an urgent SAMA CSCC TPRM event.

1 May 2026 4 min
Supply Chain & Third Party

Bitwarden CLI Compromised: Supply Chain Attack Puts Saudi Bank CI/CD Secrets at Risk

On April 22, a malicious Bitwarden CLI version was live on npm for 93 minutes — stealing SSH keys, cloud secrets, and CI/CD tokens. Here's what Saudi financial institutions must do immediately.

25 Apr 2026 6 min
Breaches & Data Leaks

ShinyHunters Breach Anodot to Compromise Dozens of Snowflake Accounts: A Supply Chain Wake-Up Call for Saudi Financial Institutions

On April 7, 2026, the ShinyHunters gang breached AI analytics firm Anodot and weaponized stolen Snowflake authentication tokens against dozens of companies. Saudi financial institutions using cloud data platforms face direct SAMA CSCC third-party risk exposure — here's what you must do now.

19 Apr 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality