Topic

Supply Chain & Third Party

Attacks that arrive through vendors, software packages and the third-party platforms you trust.

40 articles in this topic

Supply Chain & Third Party

Booking.com's ClickFix Supply Chain Breach: The Third-Party Vendor Risk Every Saudi Financial CISO Must Address Now

Booking.com confirmed a breach exposing millions of customers' reservation data — attackers never touched Booking.com directly. They compromised hotel partners using ClickFix malware. Saudi financial institutions face identical third-party exposure under SAMA CSCC.

18 Apr 2026 6 min
Compliance & Regulation

Booking.com Breach Forces Global PIN Resets — Third-Party Platform Risk Is Now a SAMA Compliance Issue for Saudi Financial Institutions

Booking.com confirmed hackers accessed customer reservation data on April 13, 2026. Saudi financial CISOs must review third-party risk registers, PDPL obligations, and phishing defences immediately.

16 Apr 2026 5 min
Vulnerabilities

EngageLab SDK Intent Redirection Flaw Exposed 50 Million Android Users — A Third-Party SDK Risk Alarm for Saudi Financial Mobile Apps

Microsoft uncovered an intent redirection vulnerability in EngageLab SDK that silently put 50 million Android users — including 30 million cryptocurrency wallet installs — at risk of private key theft. Saudi financial institutions relying on third-party mobile SDKs need to act now.

16 Apr 2026 6 min
Breaches & Data Leaks

ShinyHunters Breach Rockstar via Anodot: Saudi CISO Third-Party Alert

ShinyHunters extracted 78M records from Rockstar via Anodot, a third-party analytics vendor. SAMA CSCC mandates strict third-party risk controls — is your institution compliant?

16 Apr 2026 4 min
Supply Chain & Third Party

Axios npm Supply Chain Attack by UNC1069: Saudi Financial DevOps Alert

UNC1069 compromised Axios npm with the WAVESHAPER.V2 backdoor, exposing over 100M weekly downloads. Saudi financial institutions must audit dependency trees and CI/CD pipelines immediately.

16 Apr 2026 6 min
Supply Chain & Third Party

Fake Ledger Live on Apple's App Store Stole $9.5M in 7 Days — App Supply Chain Risk Is Now a Board-Level Issue for Saudi Financial Institutions

A fraudulent Ledger Live app slipped through Apple's review process and stole $9.5 million from 50+ victims in a single week. Here's what this means for your institution's third-party and app supply chain risk posture.

15 Apr 2026 5 min
Malware & Threat Actors

CPUID Supply Chain Attack: How STX RAT Hijacked CPU-Z and HWMonitor — A Warning for Saudi Financial IT Teams

On April 9–10, 2026, attackers hijacked CPUID's official download servers to distribute STX RAT via trojanized CPU-Z and HWMonitor installers. Here's what Saudi financial institutions need to know.

15 Apr 2026 6 min
Malware & Threat Actors

CPUID Supply Chain Breach: How STX RAT Hijacked CPU-Z & HWMonitor — A Wake-Up Call for Saudi Data Centers

On April 9, 2026, attackers quietly replaced CPUID's legitimate CPU-Z and HWMonitor downloads with trojanized packages delivering STX RAT — a full-featured remote access trojan. If your data center team downloaded hardware monitoring tools that week, read this now.

14 Apr 2026 5 min
Software Engineering

Trivy Supply Chain Attack Breaches European Commission — Why Saudi Banks Must Audit Their DevSecOps Tools

A compromised build of Trivy — one of the most trusted open-source vulnerability scanners — gave TeamPCP a backdoor into the European Commission's AWS infrastructure. If your DevSecOps pipeline trusts open-source tools implicitly, your institution could be next.

6 Apr 2026 5 min
Artificial Intelligence

LiteLLM Supply Chain Attack: How TeamPCP and Lapsus$ Breached 500,000 Machines Through an AI Library Saudi Banks May Be Running

A 40-minute window was all it took. TeamPCP poisoned LiteLLM's PyPI packages and set off a cascade that compromised 500,000 machines, 1,000+ SaaS environments, and handed Lapsus$ 4TB of data from AI startup Mercor.

5 Apr 2026 6 min
Software Engineering

TeamPCP's Trivy Supply Chain Attack Exposed 30 EU Entities — Is Your CI/CD Pipeline the Next Target?

A single compromised open-source tool gave attackers access to AWS secrets across 1,000+ SaaS environments. Saudi financial institutions running similar CI/CD pipelines face the same exposure.

4 Apr 2026 5 min
Supply Chain & Third Party

Axios NPM Supply Chain Attack: North Korean Hackers Weaponize JavaScript's Most Popular HTTP Client

North Korean threat actors hijacked the Axios npm package — 100 million weekly downloads — to deploy a cross-platform RAT. Here's what Saudi financial institutions need to know and do right now.

3 Apr 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality