Insights & analysis

The blog.

Analysis of vulnerabilities and threats prioritised for Saudi finance — alongside AI and regulatory compliance.

400 articles · 14 topics

Ransomware

Everest Ransomware Hits Fiserv: SAMA Bank Payment Risk Lessons

On May 3, 2026, Everest ransomware claimed Fiserv — a global payments and core banking provider. SAMA-regulated banks face renewed third-party risk pressure and must respond.

5 May 2026 4 min
Vulnerabilities

Fortinet CVE-2026-24858: FortiCloud SSO Bypass Hits SAMA Banks

Fortinet's CVE-2026-24858 lets attackers bypass FortiCloud SSO and seize admin control over FortiOS, FortiManager, and FortiProxy. Why SAMA-regulated banks must act before patches arrive.

5 May 2026 4 min
Vulnerabilities

MOVEit CVE-2026-4670 Auth Bypass: SAMA Bank File Transfer Risk

Progress Software patched a critical MOVEit Automation auth bypass (CVE-2026-4670) that exposes credentials and financial files. Saudi banks must act before exploitation hits SAMA-regulated MFT flows.

5 May 2026 4 min
Breaches & Data Leaks

Marquis Breach Hits 80 Banks: SAMA Vendor Risk Lessons for Saudi CISOs

The Marquis Software ransomware breach exposed 824,000 customers across 80 US banks via a single SonicWall CVE. Here is the SAMA CSCC 3.4 vendor-risk playbook every Saudi CISO must apply now.

5 May 2026 5 min
Vulnerabilities

BlueHammer CVE-2026-33825: Defender Zero-Day Hits SAMA Banks

A leaked Microsoft Defender exploit known as BlueHammer (CVE-2026-33825) escalates any unprivileged user to SYSTEM on fully patched Windows. What SAMA-regulated banks must do now to stay aligned with CSCC endpoint controls.

5 May 2026 4 min
Supply Chain & Third Party

Mini Shai-Hulud SAP npm Attack: SAMA Bank Supply Chain Lessons

Compromised SAP CAP npm packages exfiltrate developer and CI/CD secrets through a Bun-based loader. Here is what SAMA-regulated banks must verify now.

4 May 2026 4 min
Vulnerabilities

CVE-2026-3854: GitHub RCE Threatens SAMA Bank Source Code

A single crafted git push gave attackers cross-tenant RCE on GitHub, exposing millions of private repositories. With 88% of self-hosted GHES still vulnerable, SAMA-regulated banks face a direct threat to their source code crown jewels and CSCC compliance posture.

4 May 2026 4 min
Vulnerabilities

CVE-2026-32201: SharePoint Zero-Day Hits SAMA Bank Collaboration

Microsoft confirms active exploitation of SharePoint zero-day CVE-2026-32201. Over 1,300 servers remain exposed online. Here is what SAMA-regulated banks must do this week to stay aligned with CSCC controls.

4 May 2026 4 min
Vulnerabilities

CVE-2026-0625: D-Link DSL Zero-Day Threatens SAMA Bank Edge

Active exploitation of CVE-2026-0625 in end-of-life D-Link DSL gateways enables DNS hijacking and remote code execution. SAMA banks must audit branch and home-office edge devices now.

4 May 2026 4 min
Malware & Threat Actors

Anatsa Trojan Hits 831 Banking Apps: SAMA Mobile Banking Defense

Zscaler ThreatLabz uncovered Anatsa's expansion to 831 financial apps with stealthier evasion. SAMA banks must reinforce mobile defense under CSCC mandates.

4 May 2026 4 min
Vulnerabilities

CVE-2026-33824: Critical Windows IKE RCE Threatens SAMA Bank VPNs

Microsoft's May 2026 Patch Tuesday disclosed CVE-2026-33824, a CVSS 9.8 unauthenticated RCE in Windows IKE Service Extensions. SAMA-regulated banks running IPSec VPNs must patch immediately.

4 May 2026 5 min
Supply Chain & Third Party

PyTorch Lightning PyPI Hijack: SAMA Bank AI Supply Chain Risk

On April 30, 2026, attackers pushed malicious PyTorch Lightning packages to PyPI to harvest CI/CD secrets. Here is what SAMA-regulated banks must do under CSCC supply chain controls.

4 May 2026 4 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality