Insights & analysis

The blog.

Analysis of vulnerabilities and threats prioritised for Saudi finance — alongside AI and regulatory compliance.

400 articles · 14 topics

Breaches & Data Leaks

Marquis Breach Expands to 80 Banks: SonicWall Lessons for SAMA Third-Party Risk

The Marquis ransomware breach has expanded to 80 banks and 824,000 customers — exploited through a SonicWall firewall flaw. Here's what SAMA-regulated banks must do now to harden third-party and perimeter controls.

6 May 2026 4 min
Vulnerabilities

ASP.NET Core CVE-2026-40372: Forged Cookie Threat to SAMA Banks

Microsoft released an out-of-band patch for CVE-2026-40372, a CVSS 9.1 ASP.NET Core flaw that lets attackers forge auth cookies and gain SYSTEM. Direct risk to SAMA bank apps.

6 May 2026 4 min
Phishing & Fraud

AccountDumpling: Google AppSheet Phishing Bypasses DMARC — A SAMA Email Risk

Attackers are weaponizing Google AppSheet's noreply@appsheet.com address to send phishing emails that pass SPF, DKIM and DMARC. The AccountDumpling campaign is a wake-up call for every SAMA-regulated bank that treats email authentication as a finished control.

6 May 2026 4 min
Network & Infrastructure

CVE-2026-0227: PAN-OS GlobalProtect DoS Threat to SAMA Banks

An unauthenticated DoS flaw in PAN-OS GlobalProtect can force Saudi bank firewalls into maintenance mode. Here's what SAMA-regulated CISOs must do before exploitation goes mainstream.

6 May 2026 4 min
Ransomware

The Gentlemen Ransomware Surge: GPO Detonation Threat to SAMA Banks

The Gentlemen RaaS jumped from 35 to 182 victims in one quarter, targeting banks like Warka via SystemBC tunnels and GPO mass-detonation. Defense lessons for SAMA-regulated institutions.

6 May 2026 4 min
Vulnerabilities

CVE-2026-32202 Zero-Click NTLM Leak: APT28 Threat to SAMA Banks

Microsoft and CISA confirmed active exploitation of CVE-2026-32202, a zero-click Windows Shell flaw leaking NTLM hashes. SAMA banks face urgent endpoint and SMB-egress risk.

5 May 2026 4 min
Vulnerabilities

cPanel CVE-2026-41940 Auth Bypass: SAMA Bank Web Tier and Vendor Risk

CVE-2026-41940 is a CVSS 9.8 cPanel authentication bypass actively weaponised against 1.5M servers worldwide. Here is the SAMA-aligned response Saudi banks need now.

5 May 2026 4 min
Vulnerabilities

Apache HTTP/2 CVE-2026-23918 RCE: SAMA Bank Web Tier Risk

Apache shipped 2.4.67 on May 4, 2026 to fix CVE-2026-23918, an HTTP/2 double-free enabling RCE on millions of servers. Saudi banks face direct exposure on internet-facing web tiers under SAMA CSCC.

5 May 2026 4 min
Cloud & Identity

Vercel-Context AI OAuth Breach: Shadow AI Risk Lessons for SAMA Banks

A single Shadow AI tool installed by one Vercel employee triggered an OAuth supply-chain breach exposing API keys, source code, and customer credentials — a textbook warning for SAMA-regulated banks tightening third-party governance under CSCC and ECC.

5 May 2026 5 min
Cloud & Identity

CVE-2026-42354: Sentry SAML SSO Bypass Threatens SAMA Bank IAM

A critical Sentry SAML SSO bypass (CVE-2026-42354) enables full account takeover with only the victim's email address. Saudi financial institutions relying on federated identity must act now to align with SAMA CSCC IAM controls.

5 May 2026 4 min
Vulnerabilities

CVE-2026-42779: Apache MINA Deserialization RCE Hits SAMA Banks

A critical Apache MINA deserialization flaw (CVE-2026-42779, CVSS 9.8) bypasses classname allowlists and enables unauthenticated RCE in financial messaging systems. SAMA CSCC patch guidance inside.

5 May 2026 4 min
Vulnerabilities

SonicWall CVE-2026-0204 Triad: Firewall Risk for SAMA Banks

SonicWall's April 29, 2026 advisory disclosed three SonicOS flaws — access bypass, path traversal, and a remote crash — directly threatening the perimeter of SAMA-regulated banks. Here is what Saudi CISOs must do this week.

5 May 2026 4 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality