Topic
Vulnerabilities
Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.
231 articles in this topic
Trivy Supply Chain Attack CVE-2026-33634: When Your Security Scanner Becomes the Threat
Attackers compromised Aqua Security's Trivy scanner to harvest CI/CD secrets from thousands of pipelines. Here's what happened, who's behind it, and why Saudi financial institutions running Trivy must act immediately.
VulnerabilitiesCisco SD-WAN Zero-Day CVE-2026-20127: CVSS 10 Flaw Exploited Since 2023 Threatens Saudi Network Infrastructure
A CVSS 10.0 zero-day in Cisco Catalyst SD-WAN has been exploited since 2023 by threat actor UAT-8616. CISA mandated emergency patching. Here's what Saudi financial institutions need to do now.
VulnerabilitiesLesson 24: Vulnerability Analysis — From Discovery to Assessment
Hands-On Cybersecurity Path — Lesson 4 of 10. Master the vulnerability analysis lifecycle: from scanning and discovery to risk-based prioritization aligned with SAMA and NCA requirements.
VulnerabilitiesCVE-2026-21643: FortiClient EMS SQL Injection Under Active Attack — Patch Before Attackers Steal Your Endpoint Inventory
A pre-auth SQL injection in FortiClient EMS 7.4.4 lets attackers dump admin credentials and endpoint policies with a single HTTP request. Exploitation began March 26 — here's what Saudi CISOs must do now.
Network & InfrastructureCitrix NetScaler CVE-2026-3055: CISA KEV-Listed Memory Leak Hitting Financial Gateways
CISA added CVE-2026-3055 to its Known Exploited Vulnerabilities catalog on March 30. Attackers are already harvesting credentials from unpatched NetScaler gateways — here's what Saudi financial CISOs must do before the April 2 deadline.
Malware & Threat ActorsOperation TrueChaos: How a Video Conferencing Zero-Day Turned Trusted Updates into Malware
A zero-day in TrueConf's update mechanism let attackers push malware to every connected endpoint. Here's what Operation TrueChaos means for SAMA-regulated institutions and how to harden your internal software supply chain.
VulnerabilitiesOracle Identity Manager CVE-2026-21992: Emergency RCE Patch Every Saudi Bank Must Apply Now
Oracle issues rare emergency patch for CVE-2026-21992 — a CVSS 9.8 pre-auth RCE flaw in Identity Manager. Saudi financial institutions using Oracle IAM must act immediately.
VulnerabilitiesCVE-2026-33017: Langflow AI Pipeline RCE Exploited in 20 Hours — What CISOs Must Know
A critical code injection flaw in Langflow was weaponized within 20 hours of disclosure. If your organization runs AI workflow platforms, here's what you need to do immediately.
VulnerabilitiesAPT28 Weaponizes MSHTML Zero-Day CVE-2026-21513: What Saudi Financial CISOs Must Do Now
Russia-linked APT28 exploited a critical MSHTML zero-day for weeks before Microsoft patched it. Saudi financial institutions running Windows infrastructure face direct exposure — here's the technical breakdown and remediation playbook.
VulnerabilitiesInterlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026-20131: Urgent Action for Financial Institutions
Interlock ransomware exploited a CVSS 10.0 Cisco Firewall Management Center zero-day for over a month before disclosure. Here's what Saudi financial institutions must do immediately.
Guides & LessonsLesson 8: Application Security — OWASP Top 10 Vulnerabilities
Path 1: Cybersecurity Fundamentals — Lesson 8 of 10. Master the OWASP Top 10 vulnerabilities and learn how to protect your organization's web applications from the most critical security risks.
VulnerabilitiesCisco SD-WAN Zero-Day CVE-2026-20127: A CVSS 10.0 Threat Hiding Since 2023
A maximum-severity authentication bypass in Cisco Catalyst SD-WAN has been silently exploited by threat actor UAT-8616 since 2023. With CISA mandating emergency remediation, Saudi financial institutions running SD-WAN must act immediately.