Topic

Vulnerabilities

Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.

228 articles in this topic

Vulnerabilities

BlueHammer, RedSun, and UnDefend: Three Windows Defender Zero-Days Turn Your Endpoint Shield into an Attack Vector

Three zero-day exploits targeting Windows Defender surfaced within 13 days. BlueHammer is patched, but RedSun and UnDefend remain open — and threat actors are chaining all three in live intrusions against enterprise networks.

13 May 2026 5 min
Vulnerabilities

Microsoft May 2026 Patch Tuesday: Netlogon RCE Flaw CVE-2026-41089 Threatens Every Domain Controller

Microsoft patched 137 vulnerabilities in May 2026 — but one stands out: CVE-2026-41089 lets unauthenticated attackers execute code as SYSTEM on domain controllers via a single network request.

13 May 2026 5 min
Vulnerabilities

Copy Fail CVE-2026-31431: 732 Bytes to Root on Every Linux Server in Your Financial Infrastructure

A nine-year-old Linux kernel flaw dubbed "Copy Fail" lets any unprivileged user escalate to root with a 732-byte script. Every major distribution since 2017 is affected — here's what Saudi financial institutions must do now.

13 May 2026 5 min
Vulnerabilities

CVE-2026-3854: Critical GitHub RCE Flaw Exposed Millions of Repositories via Single Git Push

A single git push command was all it took to execute arbitrary code on GitHub's backend servers. CVE-2026-3854 exposed millions of public and private repositories — here's what Saudi financial institutions must do now.

13 May 2026 5 min
Vulnerabilities

CVE-2026-41940: cPanel Zero-Day Auth Bypass Exposes 1.5M Hosting Servers to Root Takeover

A CVSS 9.8 zero-day in cPanel & WHM lets unauthenticated attackers gain root-level WHM access via CRLF injection — exploited in the wild since February 2026 across 1.5 million exposed servers.

13 May 2026 5 min
Vulnerabilities

Critical n8n Workflow Automation Flaws CVE-2026-42231 & CVE-2026-42232: Chained Prototype Pollution to Full RCE

Two prototype pollution vulnerabilities in n8n can be chained for full remote code execution with a CVSS 9.4 score. If your organization uses workflow automation, here's what you need to do now.

13 May 2026 5 min
Vulnerabilities

SAP S/4HANA and Commerce Cloud Hit with CVSS 9.6 Critical Flaws — Patch Now Before Attackers Move First

SAP released 15 security patches including two CVSS 9.6 critical flaws in S/4HANA and Commerce Cloud. Here's why Saudi banks and financial institutions running SAP must act within hours, not days.

13 May 2026 5 min
Vulnerabilities

Google Confirms Hackers Used AI to Build a Zero-Day Exploit — What Saudi Financial Institutions Must Do Now

Google's Threat Intelligence Group confirmed that hackers used AI to find and exploit a zero-day vulnerability targeting a widely used admin tool. For SAMA-regulated institutions, this marks a turning point in threat modeling.

12 May 2026 5 min
Vulnerabilities

CVE-2026-32202: APT28 Exploits Zero-Click Windows Flaw to Steal NTLM Credentials — CISA Deadline Hits Today

A zero-click Windows shortcut flaw lets APT28 steal NTLM credentials without user interaction. Microsoft's incomplete patch left millions exposed — and CISA's remediation deadline expires today.

12 May 2026 4 min
Vulnerabilities

BlueHammer, RedSun, UnDefend: Three Windows Defender Zero-Days That Turned Your Shield Into a Weapon

One researcher, three zero-days, 13 days. BlueHammer, RedSun, and UnDefend exploited Windows Defender's own remediation engine to escalate privileges to SYSTEM — and only one has been patched.

12 May 2026 5 min
Vulnerabilities

Ivanti EPMM Zero-Day CVE-2026-6973: RCE Hits Enterprise Mobile Management

Ivanti's Endpoint Manager Mobile zero-day CVE-2026-6973 is under active exploitation. Attackers chain stolen credentials with an input validation flaw to achieve full RCE on EPMM appliances managing thousands of corporate devices.

12 May 2026 5 min
Supply Chain & Third Party

TanStack NPM Supply Chain Attack CVE-2026-45321: Trusted Packages Weaponized to Steal Developer Secrets

A self-spreading worm hijacked TanStack's trusted CI/CD pipeline, publishing 84 malicious npm packages that exfiltrated GitHub tokens, SSH keys, and cloud credentials. CVSS 9.6 — here's what SAMA-regulated institutions need to check immediately.

12 May 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality