Insights & analysis
The blog.
Analysis of vulnerabilities and threats prioritised for Saudi finance — alongside AI and regulatory compliance.
400 articles · 14 topics
GopherWhisper APT: Slack & Microsoft 365 C2 Risk to SAMA Banks
ESET unveils GopherWhisper — a China-aligned APT using Discord, Slack and Microsoft 365 Outlook as covert C2. SAMA-regulated banks face the same legitimate-service abuse risk and must rethink detection.
Cloud & IdentityPCPJack Cloud Worm: Credential Theft Threat to SAMA Banks
SentinelLabs has uncovered PCPJack, a self-propagating cloud worm that hijacks TeamPCP infrastructure and steals credentials at scale. Saudi financial institutions running cloud workloads face urgent SAMA CSCC exposure.
VulnerabilitiesCitrixBleed 3 (CVE-2026-3055): Critical Risk for SAMA Banks
A critical Citrix NetScaler memory overread (CVE-2026-3055) is being actively exploited against SAML-enabled appliances. Saudi banks must patch and rotate session tokens before attackers harvest more.
Vulnerabilitiesvm2 Sandbox Escape (CVE-2026-24118): RCE Risk for SAMA Banks
Twelve critical vm2 Node.js sandbox escape vulnerabilities, including CVE-2026-24118 (CVSS 9.8), let attackers execute arbitrary code on host servers. Saudi banks and fintechs running Node.js platforms face urgent SAMA CSCC remediation pressure.
Phishing & FraudVENOMOUS#HELPER RMM Phishing Campaign: Risk to SAMA Banks
A new initial-access campaign is hijacking legitimate RMM tools — SimpleHelp and ScreenConnect — to slip past EDR and establish dual-channel persistence. Here is why CISOs at SAMA-regulated banks must act this week.
VulnerabilitiescPanel CVE-2026-41940: Vendor Risk for SAMA-Regulated Banks
A pre-auth cPanel bypass (CVE-2026-41940) exposes 1.5M internet-facing servers — including those running Saudi bank marketing sites and vendor portals. Here is what SAMA-regulated CISOs must act on now.
Cloud & IdentityTeamPCP Cloud Compromise: CI/CD Threat for SAMA Banks
TeamPCP weaponized open-source security tools (Trivy, LiteLLM, KICS) to harvest CI/CD secrets and pivot into AWS, Azure and SaaS environments. SAMA-regulated banks must reassess third-party and pipeline trust now.
Supply Chain & Third PartyTrellix Source Code Breach: Supply Chain Threat to SAMA Banks
Trellix confirmed unauthorized access to its source code repository in May 2026. For SAMA-regulated banks relying on Trellix XDR and EDR, this incident raises urgent supply chain and third-party risk questions under SAMA CSCC.
Malware & Threat ActorsDAEMON Tools Supply Chain Backdoor: SAMA Bank Endpoint Risk
Kaspersky uncovered a trojanized DAEMON Tools installer distributing a Chinese-linked backdoor through the vendor's official domain since April 8, 2026 — a direct test of SAMA CSCC software supply chain controls.
VulnerabilitiesCVE-2026-0300: PAN-OS Captive Portal RCE Threat to SAMA Banks
A critical PAN-OS Captive Portal buffer overflow lets unauthenticated attackers gain root on Palo Alto firewalls. SAMA-regulated banks must patch and isolate User-ID portals immediately.
Network & InfrastructureIran's PLC Campaign: OT/IT Convergence Risks for SAMA Banks
CISA's April 2026 advisory reveals an Iranian APT campaign abusing internet-exposed Rockwell PLCs. SAMA-regulated banks run similar OT systems in data centers and branches—here's how to defend them.
VulnerabilitiesMOVEit CVE-2026-4670: Critical Auth Bypass Threatens SAMA Banks
A CVSS 9.8 authentication bypass flaw in MOVEit Automation (CVE-2026-4670) lets unauthenticated attackers seize full administrative control of file transfer servers. Saudi financial institutions must act now.