Topic
Vulnerabilities
Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.
231 articles in this topic
Pwn2Own Berlin 2026: 47 Zero-Days in Enterprise Tech Expose What Scanners Miss
47 zero-days across Exchange, SharePoint, VMware ESXi, and AI platforms — $1.3M in bounties at Pwn2Own Berlin 2026. What the results mean for Saudi financial institutions and their 90-day patch window.
VulnerabilitiesMicrosoft May 2026 Patch Tuesday: Azure DevOps CVSS 10.0 and Netlogon RCE Demand Immediate Action
Microsoft patched 118 vulnerabilities in May 2026, including CVE-2026-42826 — a perfect CVSS 10.0 Azure DevOps information disclosure flaw exploitable without authentication. Here's what Saudi financial institutions must patch first.
VulnerabilitiesCVE-2026-23918: Apache HTTP/2 Double-Free Flaw Enables RCE on Millions of Servers
A critical double-free vulnerability in Apache HTTP Server's HTTP/2 module lets attackers crash or hijack servers with just two network frames. Here's what Saudi financial institutions need to do now.
VulnerabilitiesFunnel Builder WordPress Exploit: How Attackers Steal Payment Data from 40,000+ WooCommerce Stores
A critical flaw in the Funnel Builder WordPress plugin is being actively exploited to plant JavaScript skimmers on WooCommerce checkout pages, stealing cardholder data in real time. Here's what Saudi merchants and financial institutions need to know.
VulnerabilitiesGoogle Confirms First AI-Built Zero-Day Exploit: 2FA Bypass Signals a New Threat Era
Google's Threat Intelligence Group has confirmed the first real-world zero-day exploit built entirely by AI — a 2FA bypass that rewrites the rules for Saudi financial institutions relying on multi-factor authentication as a compliance checkbox.
Artificial IntelligenceClaw Chain: Four OpenClaw Flaws Let Attackers Hijack AI Agents from Inside the Sandbox
Four chainable vulnerabilities in OpenClaw AI agent platform — dubbed Claw Chain — allow sandbox escape, data theft, and persistent backdoors across 245,000 exposed servers. Critical implications for Saudi financial institutions under SAMA CSCC.
VulnerabilitiesCVE-2026-20182: Cisco SD-WAN CVSS 10.0 Auth Bypass Under Active Exploitation
A perfect-score CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN is being actively exploited by UAT-8616. If your WAN fabric runs on Cisco, this is not optional reading.
VulnerabilitiesNGINX Rift (CVE-2026-42945): 18-Year-Old RCE Flaw Now Actively Exploited in the Wild
CVE-2026-42945 — an 18-year-old heap buffer overflow in NGINX's rewrite module — is now actively exploited with a public PoC. Here's what Saudi financial CISOs must do before attackers reach the DMZ.
Network & InfrastructureCVE-2026-0300: Critical PAN-OS Buffer Overflow Grants Root Access to Palo Alto Firewalls
A critical buffer overflow in Palo Alto PAN-OS User-ID Authentication Portal is being exploited in the wild, giving attackers root-level code execution on PA-Series and VM-Series firewalls. Here is what Saudi financial CISOs must do now.
VulnerabilitiesYellowKey and GreenPlasma: Unpatched Windows Zero-Days That Bypass BitLocker and Grant SYSTEM Access
A disgruntled researcher dropped two unpatched Windows zero-days with public PoCs: YellowKey defeats BitLocker with a USB stick, and GreenPlasma escalates any user to SYSTEM. Here's what Saudi CISOs need to act on immediately.
Software EngineeringGrafana GitHub Token Breach: CI/CD Pipeline Flaw Exposes Source Code to Extortion
Grafana Labs lost its entire source code after an attacker exploited a GitHub Actions misconfiguration. Learn how CI/CD pipeline vulnerabilities threaten Saudi financial institutions and what SAMA CSCC demands.
VulnerabilitiesFragnesia (CVE-2026-46300): Linux Kernel Flaw Grants Root Access via Page Cache Corruption
A new Linux kernel privilege escalation vulnerability, Fragnesia (CVE-2026-46300), grants root access via page cache corruption with a public PoC. Learn why Saudi financial institutions must patch immediately.
From reading to doing
Could your systems be exposed to a similar flaw?
A vulnerability assessment finds the weaknesses in your systems before attackers do, and ranks the fixes by risk.
Vulnerability Assessment
Systematic comprehensive scanning of your infrastructure vulnerabilities with a prioritized remediation report for immediate actio...
Internal Penetration Testing
Realistic internal attack simulation to measure your internal network resilience against insider threats
Web Application Penetration Testing
Deep security assessment of web applications following OWASP Top 10 to protect your data and customers