Topic
Supply Chain & Third Party
Attacks that arrive through vendors, software packages and the third-party platforms you trust.
40 articles in this topic
Lesson 36: Third-Party Risk Management — Securing Your Vendor Ecosystem
Security Leadership Path — Lesson 6 of 10. Build a robust Third-Party Risk Management program that satisfies SAMA CSCC and NCA ECC requirements while protecting your organization from vendor-introduced threats.
Supply Chain & Third PartyTrivy Supply Chain Attack CVE-2026-33634: When Your Security Scanner Becomes the Threat
Attackers compromised Aqua Security's Trivy scanner to harvest CI/CD secrets from thousands of pipelines. Here's what happened, who's behind it, and why Saudi financial institutions running Trivy must act immediately.
Supply Chain & Third PartyAxios npm Supply Chain Attack: RAT Deployed via 100M-Download Package
Attackers hijacked Axios — the most popular npm HTTP client with 100M+ weekly downloads — to deploy a self-destructing RAT. Here's what Saudi financial institutions must do immediately.
Supply Chain & Third PartySoftware Supply Chain Attacks Surge: GlassWorm and LiteLLM Compromises Sound the Alarm
Two massive supply chain attacks in March 2026 — GlassWorm (9M+ installs via malicious IDE extensions) and LiteLLM (backdoored Python library with 3M daily downloads) — expose critical gaps in software development security for Saudi financial institutions.