Topic
Vulnerabilities
Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.
228 articles in this topic
CVE-2026-23918: Apache HTTP/2 Double-Free Flaw Enables Remote Code Execution on Millions of Servers
A critical double-free vulnerability in Apache HTTP Server 2.4.66's HTTP/2 module lets attackers crash workers or achieve full RCE — and millions of internet-facing servers remain unpatched.
VulnerabilitiesGoogle Confirms First AI-Written Zero-Day Exploit: 2FA Bypass Weaponized for Mass Exploitation
Google GTIG confirms the first AI-written zero-day exploit bypassing 2FA on a widely used admin tool. Learn what this means for Saudi financial institutions and how to defend against AI-accelerated threats.
VulnerabilitiesFunnelKit WooCommerce Checkout Skimmer: How a Plugin Flaw Turns Online Stores Into Card-Harvesting Traps
Attackers exploit a flaw in FunnelKit's WooCommerce plugin to inject invisible payment skimmers on 40,000+ checkout pages. Learn how this impacts PCI-DSS compliance and what Saudi merchants must do now.
VulnerabilitiesOpenAI Daybreak: How AI-Powered Vulnerability Detection Changes the Game for Financial CISOs
OpenAI's Daybreak initiative uses GPT-5.5 to detect and patch vulnerabilities in minutes. Here's what Saudi financial CISOs need to know about AI-powered security operations.
VulnerabilitiesCVE-2026-32202: APT28 Exploits Zero-Click Windows Flaw to Steal Credentials Without User Interaction
An incomplete Microsoft patch left a zero-click credential theft vector wide open — and APT28 is already exploiting it. Here's what Saudi financial institutions need to do right now.
VulnerabilitiesCVE-2026-0073: Android Zero-Click RCE Lets Nearby Attackers Gain Shell Access Without User Interaction
Google patches a CVSS 9.8 zero-click RCE in Android's wireless ADB that lets nearby attackers gain full shell access — a direct threat to BYOD-enabled financial institutions.
Artificial IntelligenceCritical Microsoft 365 Copilot Vulnerabilities: AI Assistants Become Data Exfiltration Vectors
Three critical CVEs in Microsoft 365 Copilot allow unauthorized data disclosure through AI injection attacks. Saudi financial institutions face compounded SAMA CSCC and PDPL compliance risks as AI assistants bypass traditional DLP controls.
VulnerabilitiesCVE-2026-20182: Cisco SD-WAN Zero-Day Gives Attackers Full Admin Access Without Credentials
A CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN Controller is under active exploitation, letting attackers seize full admin control of enterprise network fabrics without any credentials.
VulnerabilitiesCVE-2026-42897: Actively Exploited Exchange Server Zero-Day Demands Immediate Action
Microsoft confirms active exploitation of CVE-2026-42897 in on-premises Exchange Server. Learn how this OWA XSS zero-day impacts Saudi financial institutions and what immediate mitigations to apply.
VulnerabilitiesNGINX Rift: 18-Year-Old Critical RCE Bug Hiding in Every Reverse Proxy
An 18-year-old heap buffer overflow in NGINX's rewrite module (CVE-2026-42945, CVSS 9.2) enables unauthenticated RCE on every unpatched reverse proxy. Here's what Saudi financial institutions must do now.
VulnerabilitiesCVE-2026-32201: Unpatched SharePoint Servers Expose Saudi Financial Institutions to Unauthenticated Spoofing
CISA added CVE-2026-32201 to its KEV catalog, yet over 1,300 SharePoint servers remain exposed. For Saudi banks running SharePoint on-prem, the window to patch is closing fast.
VulnerabilitiesCVE-2026-41096: Critical Windows DNS Client RCE Threatens Every Endpoint
CVE-2026-41096 scores CVSS 9.8—a heap overflow in Windows DNS Client allows unauthenticated RCE on every Windows machine via a single malicious DNS response. Here's what Saudi financial institutions must do now.
From reading to doing
Could your systems be exposed to a similar flaw?
A vulnerability assessment finds the weaknesses in your systems before attackers do, and ranks the fixes by risk.
Vulnerability Assessment
Systematic comprehensive scanning of your infrastructure vulnerabilities with a prioritized remediation report for immediate actio...
Internal Penetration Testing
Realistic internal attack simulation to measure your internal network resilience against insider threats
Web Application Penetration Testing
Deep security assessment of web applications following OWASP Top 10 to protect your data and customers