Insights & analysis
The blog.
Analysis of vulnerabilities and threats prioritised for Saudi finance — alongside AI and regulatory compliance.
400 articles · 14 topics
Everest Ransomware Hits Fiserv: SAMA Bank Payment Risk Lessons
On May 3, 2026, Everest ransomware claimed Fiserv — a global payments and core banking provider. SAMA-regulated banks face renewed third-party risk pressure and must respond.
VulnerabilitiesFortinet CVE-2026-24858: FortiCloud SSO Bypass Hits SAMA Banks
Fortinet's CVE-2026-24858 lets attackers bypass FortiCloud SSO and seize admin control over FortiOS, FortiManager, and FortiProxy. Why SAMA-regulated banks must act before patches arrive.
VulnerabilitiesMOVEit CVE-2026-4670 Auth Bypass: SAMA Bank File Transfer Risk
Progress Software patched a critical MOVEit Automation auth bypass (CVE-2026-4670) that exposes credentials and financial files. Saudi banks must act before exploitation hits SAMA-regulated MFT flows.
Breaches & Data LeaksMarquis Breach Hits 80 Banks: SAMA Vendor Risk Lessons for Saudi CISOs
The Marquis Software ransomware breach exposed 824,000 customers across 80 US banks via a single SonicWall CVE. Here is the SAMA CSCC 3.4 vendor-risk playbook every Saudi CISO must apply now.
VulnerabilitiesBlueHammer CVE-2026-33825: Defender Zero-Day Hits SAMA Banks
A leaked Microsoft Defender exploit known as BlueHammer (CVE-2026-33825) escalates any unprivileged user to SYSTEM on fully patched Windows. What SAMA-regulated banks must do now to stay aligned with CSCC endpoint controls.
Supply Chain & Third PartyMini Shai-Hulud SAP npm Attack: SAMA Bank Supply Chain Lessons
Compromised SAP CAP npm packages exfiltrate developer and CI/CD secrets through a Bun-based loader. Here is what SAMA-regulated banks must verify now.
VulnerabilitiesCVE-2026-3854: GitHub RCE Threatens SAMA Bank Source Code
A single crafted git push gave attackers cross-tenant RCE on GitHub, exposing millions of private repositories. With 88% of self-hosted GHES still vulnerable, SAMA-regulated banks face a direct threat to their source code crown jewels and CSCC compliance posture.
VulnerabilitiesCVE-2026-32201: SharePoint Zero-Day Hits SAMA Bank Collaboration
Microsoft confirms active exploitation of SharePoint zero-day CVE-2026-32201. Over 1,300 servers remain exposed online. Here is what SAMA-regulated banks must do this week to stay aligned with CSCC controls.
VulnerabilitiesCVE-2026-0625: D-Link DSL Zero-Day Threatens SAMA Bank Edge
Active exploitation of CVE-2026-0625 in end-of-life D-Link DSL gateways enables DNS hijacking and remote code execution. SAMA banks must audit branch and home-office edge devices now.
Malware & Threat ActorsAnatsa Trojan Hits 831 Banking Apps: SAMA Mobile Banking Defense
Zscaler ThreatLabz uncovered Anatsa's expansion to 831 financial apps with stealthier evasion. SAMA banks must reinforce mobile defense under CSCC mandates.
VulnerabilitiesCVE-2026-33824: Critical Windows IKE RCE Threatens SAMA Bank VPNs
Microsoft's May 2026 Patch Tuesday disclosed CVE-2026-33824, a CVSS 9.8 unauthenticated RCE in Windows IKE Service Extensions. SAMA-regulated banks running IPSec VPNs must patch immediately.
Supply Chain & Third PartyPyTorch Lightning PyPI Hijack: SAMA Bank AI Supply Chain Risk
On April 30, 2026, attackers pushed malicious PyTorch Lightning packages to PyPI to harvest CI/CD secrets. Here is what SAMA-regulated banks must do under CSCC supply chain controls.