Insights & analysis
The blog.
Analysis of vulnerabilities and threats prioritised for Saudi finance — alongside AI and regulatory compliance.
400 articles · 14 topics
Mini Shai-Hulud Supply Chain Attack: SAMA Bank DevSecOps Risk
A new worm campaign compromised PyTorch Lightning, intercom-client and 1,800+ developer repos across npm, PyPI and PHP. Here is what SAMA-regulated banks must do now.
VulnerabilitiesIvanti EPMM CVE-2026-6973 RCE Exploited: SAMA Bank MDM Risk
CISA added Ivanti EPMM CVE-2026-6973 to the KEV catalog after confirmed in-the-wild exploitation. Saudi banks running on-prem MDM face severe risk to mobile device fleets and corporate data.
VulnerabilitiesSharePoint CVE-2026-32201 Zero-Day RCE: Critical Risk to SAMA Banks
A new SharePoint zero-day vulnerability (CVE-2026-32201) is being actively exploited, exposing more than 1,300 internet-facing servers to unauthenticated remote code execution. SAMA-regulated banks must act now.
RansomwareEverest Ransomware Hits US Banks: Vendor Risk Lessons for SAMA
Everest ransomware claimed breaches at Frost Bank and Citizens Financial Group through a shared third-party vendor, exposing 250K+ customer records. SAMA-regulated banks face the same supply chain exposure — here is what every CISO must do now.
VulnerabilitiesApache HTTP/2 CVE-2026-23918 Double-Free RCE: SAMA Bank Risk
Apache HTTP Server 2.4.66 contains a critical HTTP/2 double-free vulnerability (CVE-2026-23918) enabling unauthenticated RCE — a direct threat to SAMA-regulated banking web infrastructure.
VulnerabilitiesD-Link CVE-2026-0625 Zero-Day: DNS Hijack Risk for SAMA Banks
An unauthenticated RCE in end-of-life D-Link DSL routers (CVE-2026-0625, CVSS 9.3) enables silent DNS redirection. SAMA-regulated banks now face customer-side credential theft and BEC fraud at scale.
RansomwareAnubis Ransomware Adds Wiper: Critical Risk to SAMA Banks
Anubis ransomware-as-a-service now includes a destructive wiper alongside double extortion, breaking the traditional ransomware bargain. Saudi banks must adapt SAMA CSCC defenses immediately.
RansomwareNightSpire Ransomware Targets Financial Sector: SAMA Bank Defense Guide
NightSpire is rewriting double-extortion playbooks against the financial sector. Here is what SAMA-regulated banks must do to harden Fortinet edges, blunt CVE-2024-55591, and survive 48-hour ransom deadlines.
VulnerabilitiesWeaver E-cology CVE-2026-22679: Unauthenticated RCE Risk to SAMA Banks
A CVSS 9.8 unauthenticated RCE flaw in Weaver E-cology is being actively exploited via an exposed Dubbo debug endpoint. SAMA-regulated banks running this enterprise collaboration platform face direct threats to integrity and availability obligations under CSCC.
VulnerabilitiescPanel CVE-2026-41940 Auth Bypass: Risk to SAMA Banks
A critical CRLF-injection auth bypass in cPanel & WHM (CVSS 9.8) is under mass exploitation, putting Saudi banks' supply chains and PCI-DSS scope at risk.
Cloud & IdentityMuddyWater Targets Microsoft Teams MFA: SAMA Bank Defense Guide
Iranian state-sponsored MuddyWater is exploiting Microsoft Teams social engineering to harvest credentials and manipulate MFA at financial institutions, then planting Chaos ransomware as a false flag. Here is what SAMA-regulated banks must do.
Guides & LessonsDigitalMint Insider Threat: $75M Lesson for SAMA Banks
A trusted ransomware negotiator betrayed his clients and funneled $75.25M to BlackCat. Here's what SAMA-regulated banks must change in their incident response vendor due diligence today.