Insights & analysis

The blog.

Analysis of vulnerabilities and threats prioritised for Saudi finance — alongside AI and regulatory compliance.

400 articles · 14 topics

Supply Chain & Third Party

Mini Shai-Hulud Supply Chain Attack: SAMA Bank DevSecOps Risk

A new worm campaign compromised PyTorch Lightning, intercom-client and 1,800+ developer repos across npm, PyPI and PHP. Here is what SAMA-regulated banks must do now.

10 May 2026 4 min
Vulnerabilities

Ivanti EPMM CVE-2026-6973 RCE Exploited: SAMA Bank MDM Risk

CISA added Ivanti EPMM CVE-2026-6973 to the KEV catalog after confirmed in-the-wild exploitation. Saudi banks running on-prem MDM face severe risk to mobile device fleets and corporate data.

10 May 2026 3 min
Vulnerabilities

SharePoint CVE-2026-32201 Zero-Day RCE: Critical Risk to SAMA Banks

A new SharePoint zero-day vulnerability (CVE-2026-32201) is being actively exploited, exposing more than 1,300 internet-facing servers to unauthenticated remote code execution. SAMA-regulated banks must act now.

10 May 2026 3 min
Ransomware

Everest Ransomware Hits US Banks: Vendor Risk Lessons for SAMA

Everest ransomware claimed breaches at Frost Bank and Citizens Financial Group through a shared third-party vendor, exposing 250K+ customer records. SAMA-regulated banks face the same supply chain exposure — here is what every CISO must do now.

10 May 2026 4 min
Vulnerabilities

Apache HTTP/2 CVE-2026-23918 Double-Free RCE: SAMA Bank Risk

Apache HTTP Server 2.4.66 contains a critical HTTP/2 double-free vulnerability (CVE-2026-23918) enabling unauthenticated RCE — a direct threat to SAMA-regulated banking web infrastructure.

10 May 2026 4 min
Vulnerabilities

D-Link CVE-2026-0625 Zero-Day: DNS Hijack Risk for SAMA Banks

An unauthenticated RCE in end-of-life D-Link DSL routers (CVE-2026-0625, CVSS 9.3) enables silent DNS redirection. SAMA-regulated banks now face customer-side credential theft and BEC fraud at scale.

10 May 2026 4 min
Ransomware

Anubis Ransomware Adds Wiper: Critical Risk to SAMA Banks

Anubis ransomware-as-a-service now includes a destructive wiper alongside double extortion, breaking the traditional ransomware bargain. Saudi banks must adapt SAMA CSCC defenses immediately.

10 May 2026 4 min
Ransomware

NightSpire Ransomware Targets Financial Sector: SAMA Bank Defense Guide

NightSpire is rewriting double-extortion playbooks against the financial sector. Here is what SAMA-regulated banks must do to harden Fortinet edges, blunt CVE-2024-55591, and survive 48-hour ransom deadlines.

9 May 2026 4 min
Vulnerabilities

Weaver E-cology CVE-2026-22679: Unauthenticated RCE Risk to SAMA Banks

A CVSS 9.8 unauthenticated RCE flaw in Weaver E-cology is being actively exploited via an exposed Dubbo debug endpoint. SAMA-regulated banks running this enterprise collaboration platform face direct threats to integrity and availability obligations under CSCC.

9 May 2026 4 min
Vulnerabilities

cPanel CVE-2026-41940 Auth Bypass: Risk to SAMA Banks

A critical CRLF-injection auth bypass in cPanel & WHM (CVSS 9.8) is under mass exploitation, putting Saudi banks' supply chains and PCI-DSS scope at risk.

9 May 2026 4 min
Cloud & Identity

MuddyWater Targets Microsoft Teams MFA: SAMA Bank Defense Guide

Iranian state-sponsored MuddyWater is exploiting Microsoft Teams social engineering to harvest credentials and manipulate MFA at financial institutions, then planting Chaos ransomware as a false flag. Here is what SAMA-regulated banks must do.

9 May 2026 4 min
Guides & Lessons

DigitalMint Insider Threat: $75M Lesson for SAMA Banks

A trusted ransomware negotiator betrayed his clients and funneled $75.25M to BlackCat. Here's what SAMA-regulated banks must change in their incident response vendor due diligence today.

9 May 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality