Insights & analysis
The blog.
Analysis of vulnerabilities and threats prioritised for Saudi finance — alongside AI and regulatory compliance.
400 articles · 14 topics
Marquis Breach Expands to 80 Banks: SonicWall Lessons for SAMA Third-Party Risk
The Marquis ransomware breach has expanded to 80 banks and 824,000 customers — exploited through a SonicWall firewall flaw. Here's what SAMA-regulated banks must do now to harden third-party and perimeter controls.
VulnerabilitiesASP.NET Core CVE-2026-40372: Forged Cookie Threat to SAMA Banks
Microsoft released an out-of-band patch for CVE-2026-40372, a CVSS 9.1 ASP.NET Core flaw that lets attackers forge auth cookies and gain SYSTEM. Direct risk to SAMA bank apps.
Phishing & FraudAccountDumpling: Google AppSheet Phishing Bypasses DMARC — A SAMA Email Risk
Attackers are weaponizing Google AppSheet's noreply@appsheet.com address to send phishing emails that pass SPF, DKIM and DMARC. The AccountDumpling campaign is a wake-up call for every SAMA-regulated bank that treats email authentication as a finished control.
Network & InfrastructureCVE-2026-0227: PAN-OS GlobalProtect DoS Threat to SAMA Banks
An unauthenticated DoS flaw in PAN-OS GlobalProtect can force Saudi bank firewalls into maintenance mode. Here's what SAMA-regulated CISOs must do before exploitation goes mainstream.
RansomwareThe Gentlemen Ransomware Surge: GPO Detonation Threat to SAMA Banks
The Gentlemen RaaS jumped from 35 to 182 victims in one quarter, targeting banks like Warka via SystemBC tunnels and GPO mass-detonation. Defense lessons for SAMA-regulated institutions.
VulnerabilitiesCVE-2026-32202 Zero-Click NTLM Leak: APT28 Threat to SAMA Banks
Microsoft and CISA confirmed active exploitation of CVE-2026-32202, a zero-click Windows Shell flaw leaking NTLM hashes. SAMA banks face urgent endpoint and SMB-egress risk.
VulnerabilitiescPanel CVE-2026-41940 Auth Bypass: SAMA Bank Web Tier and Vendor Risk
CVE-2026-41940 is a CVSS 9.8 cPanel authentication bypass actively weaponised against 1.5M servers worldwide. Here is the SAMA-aligned response Saudi banks need now.
VulnerabilitiesApache HTTP/2 CVE-2026-23918 RCE: SAMA Bank Web Tier Risk
Apache shipped 2.4.67 on May 4, 2026 to fix CVE-2026-23918, an HTTP/2 double-free enabling RCE on millions of servers. Saudi banks face direct exposure on internet-facing web tiers under SAMA CSCC.
Cloud & IdentityVercel-Context AI OAuth Breach: Shadow AI Risk Lessons for SAMA Banks
A single Shadow AI tool installed by one Vercel employee triggered an OAuth supply-chain breach exposing API keys, source code, and customer credentials — a textbook warning for SAMA-regulated banks tightening third-party governance under CSCC and ECC.
Cloud & IdentityCVE-2026-42354: Sentry SAML SSO Bypass Threatens SAMA Bank IAM
A critical Sentry SAML SSO bypass (CVE-2026-42354) enables full account takeover with only the victim's email address. Saudi financial institutions relying on federated identity must act now to align with SAMA CSCC IAM controls.
VulnerabilitiesCVE-2026-42779: Apache MINA Deserialization RCE Hits SAMA Banks
A critical Apache MINA deserialization flaw (CVE-2026-42779, CVSS 9.8) bypasses classname allowlists and enables unauthenticated RCE in financial messaging systems. SAMA CSCC patch guidance inside.
VulnerabilitiesSonicWall CVE-2026-0204 Triad: Firewall Risk for SAMA Banks
SonicWall's April 29, 2026 advisory disclosed three SonicOS flaws — access bypass, path traversal, and a remote crash — directly threatening the perimeter of SAMA-regulated banks. Here is what Saudi CISOs must do this week.