Topic
Vulnerabilities
Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.
228 articles in this topic
BlueHammer, RedSun, and UnDefend: Three Windows Defender Zero-Days Turn Your Endpoint Shield into an Attack Vector
Three zero-day exploits targeting Windows Defender surfaced within 13 days. BlueHammer is patched, but RedSun and UnDefend remain open — and threat actors are chaining all three in live intrusions against enterprise networks.
VulnerabilitiesMicrosoft May 2026 Patch Tuesday: Netlogon RCE Flaw CVE-2026-41089 Threatens Every Domain Controller
Microsoft patched 137 vulnerabilities in May 2026 — but one stands out: CVE-2026-41089 lets unauthenticated attackers execute code as SYSTEM on domain controllers via a single network request.
VulnerabilitiesCopy Fail CVE-2026-31431: 732 Bytes to Root on Every Linux Server in Your Financial Infrastructure
A nine-year-old Linux kernel flaw dubbed "Copy Fail" lets any unprivileged user escalate to root with a 732-byte script. Every major distribution since 2017 is affected — here's what Saudi financial institutions must do now.
VulnerabilitiesCVE-2026-3854: Critical GitHub RCE Flaw Exposed Millions of Repositories via Single Git Push
A single git push command was all it took to execute arbitrary code on GitHub's backend servers. CVE-2026-3854 exposed millions of public and private repositories — here's what Saudi financial institutions must do now.
VulnerabilitiesCVE-2026-41940: cPanel Zero-Day Auth Bypass Exposes 1.5M Hosting Servers to Root Takeover
A CVSS 9.8 zero-day in cPanel & WHM lets unauthenticated attackers gain root-level WHM access via CRLF injection — exploited in the wild since February 2026 across 1.5 million exposed servers.
VulnerabilitiesCritical n8n Workflow Automation Flaws CVE-2026-42231 & CVE-2026-42232: Chained Prototype Pollution to Full RCE
Two prototype pollution vulnerabilities in n8n can be chained for full remote code execution with a CVSS 9.4 score. If your organization uses workflow automation, here's what you need to do now.
VulnerabilitiesSAP S/4HANA and Commerce Cloud Hit with CVSS 9.6 Critical Flaws — Patch Now Before Attackers Move First
SAP released 15 security patches including two CVSS 9.6 critical flaws in S/4HANA and Commerce Cloud. Here's why Saudi banks and financial institutions running SAP must act within hours, not days.
VulnerabilitiesGoogle Confirms Hackers Used AI to Build a Zero-Day Exploit — What Saudi Financial Institutions Must Do Now
Google's Threat Intelligence Group confirmed that hackers used AI to find and exploit a zero-day vulnerability targeting a widely used admin tool. For SAMA-regulated institutions, this marks a turning point in threat modeling.
VulnerabilitiesCVE-2026-32202: APT28 Exploits Zero-Click Windows Flaw to Steal NTLM Credentials — CISA Deadline Hits Today
A zero-click Windows shortcut flaw lets APT28 steal NTLM credentials without user interaction. Microsoft's incomplete patch left millions exposed — and CISA's remediation deadline expires today.
VulnerabilitiesBlueHammer, RedSun, UnDefend: Three Windows Defender Zero-Days That Turned Your Shield Into a Weapon
One researcher, three zero-days, 13 days. BlueHammer, RedSun, and UnDefend exploited Windows Defender's own remediation engine to escalate privileges to SYSTEM — and only one has been patched.
VulnerabilitiesIvanti EPMM Zero-Day CVE-2026-6973: RCE Hits Enterprise Mobile Management
Ivanti's Endpoint Manager Mobile zero-day CVE-2026-6973 is under active exploitation. Attackers chain stolen credentials with an input validation flaw to achieve full RCE on EPMM appliances managing thousands of corporate devices.
Supply Chain & Third PartyTanStack NPM Supply Chain Attack CVE-2026-45321: Trusted Packages Weaponized to Steal Developer Secrets
A self-spreading worm hijacked TanStack's trusted CI/CD pipeline, publishing 84 malicious npm packages that exfiltrated GitHub tokens, SSH keys, and cloud credentials. CVSS 9.6 — here's what SAMA-regulated institutions need to check immediately.
From reading to doing
Could your systems be exposed to a similar flaw?
A vulnerability assessment finds the weaknesses in your systems before attackers do, and ranks the fixes by risk.
Vulnerability Assessment
Systematic comprehensive scanning of your infrastructure vulnerabilities with a prioritized remediation report for immediate actio...
Internal Penetration Testing
Realistic internal attack simulation to measure your internal network resilience against insider threats
Web Application Penetration Testing
Deep security assessment of web applications following OWASP Top 10 to protect your data and customers