Topic

Vulnerabilities

Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.

231 articles in this topic

Supply Chain & Third Party

Trivy Supply Chain Attack CVE-2026-33634: When Your Security Scanner Becomes the Threat

Attackers compromised Aqua Security's Trivy scanner to harvest CI/CD secrets from thousands of pipelines. Here's what happened, who's behind it, and why Saudi financial institutions running Trivy must act immediately.

1 Apr 2026 5 min
Vulnerabilities

Cisco SD-WAN Zero-Day CVE-2026-20127: CVSS 10 Flaw Exploited Since 2023 Threatens Saudi Network Infrastructure

A CVSS 10.0 zero-day in Cisco Catalyst SD-WAN has been exploited since 2023 by threat actor UAT-8616. CISA mandated emergency patching. Here's what Saudi financial institutions need to do now.

1 Apr 2026 6 min
Vulnerabilities

Lesson 24: Vulnerability Analysis — From Discovery to Assessment

Hands-On Cybersecurity Path — Lesson 4 of 10. Master the vulnerability analysis lifecycle: from scanning and discovery to risk-based prioritization aligned with SAMA and NCA requirements.

1 Apr 2026 8 min
Vulnerabilities

CVE-2026-21643: FortiClient EMS SQL Injection Under Active Attack — Patch Before Attackers Steal Your Endpoint Inventory

A pre-auth SQL injection in FortiClient EMS 7.4.4 lets attackers dump admin credentials and endpoint policies with a single HTTP request. Exploitation began March 26 — here's what Saudi CISOs must do now.

1 Apr 2026 5 min
Network & Infrastructure

Citrix NetScaler CVE-2026-3055: CISA KEV-Listed Memory Leak Hitting Financial Gateways

CISA added CVE-2026-3055 to its Known Exploited Vulnerabilities catalog on March 30. Attackers are already harvesting credentials from unpatched NetScaler gateways — here's what Saudi financial CISOs must do before the April 2 deadline.

1 Apr 2026 6 min
Malware & Threat Actors

Operation TrueChaos: How a Video Conferencing Zero-Day Turned Trusted Updates into Malware

A zero-day in TrueConf's update mechanism let attackers push malware to every connected endpoint. Here's what Operation TrueChaos means for SAMA-regulated institutions and how to harden your internal software supply chain.

1 Apr 2026 5 min
Vulnerabilities

Oracle Identity Manager CVE-2026-21992: Emergency RCE Patch Every Saudi Bank Must Apply Now

Oracle issues rare emergency patch for CVE-2026-21992 — a CVSS 9.8 pre-auth RCE flaw in Identity Manager. Saudi financial institutions using Oracle IAM must act immediately.

1 Apr 2026 4 min
Vulnerabilities

CVE-2026-33017: Langflow AI Pipeline RCE Exploited in 20 Hours — What CISOs Must Know

A critical code injection flaw in Langflow was weaponized within 20 hours of disclosure. If your organization runs AI workflow platforms, here's what you need to do immediately.

31 Mar 2026 5 min
Vulnerabilities

APT28 Weaponizes MSHTML Zero-Day CVE-2026-21513: What Saudi Financial CISOs Must Do Now

Russia-linked APT28 exploited a critical MSHTML zero-day for weeks before Microsoft patched it. Saudi financial institutions running Windows infrastructure face direct exposure — here's the technical breakdown and remediation playbook.

31 Mar 2026 6 min
Vulnerabilities

Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026-20131: Urgent Action for Financial Institutions

Interlock ransomware exploited a CVSS 10.0 Cisco Firewall Management Center zero-day for over a month before disclosure. Here's what Saudi financial institutions must do immediately.

31 Mar 2026 5 min
Guides & Lessons

Lesson 8: Application Security — OWASP Top 10 Vulnerabilities

Path 1: Cybersecurity Fundamentals — Lesson 8 of 10. Master the OWASP Top 10 vulnerabilities and learn how to protect your organization's web applications from the most critical security risks.

31 Mar 2026 8 min
Vulnerabilities

Cisco SD-WAN Zero-Day CVE-2026-20127: A CVSS 10.0 Threat Hiding Since 2023

A maximum-severity authentication bypass in Cisco Catalyst SD-WAN has been silently exploited by threat actor UAT-8616 since 2023. With CISA mandating emergency remediation, Saudi financial institutions running SD-WAN must act immediately.

31 Mar 2026 4 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality