Insights & analysis
The blog.
Analysis of vulnerabilities and threats prioritised for Saudi finance — alongside AI and regulatory compliance.
400 articles · 14 topics
Vercel-Context AI OAuth Breach: SaaS Supply Chain Lessons for SAMA Banks
A single employee-installed AI plugin gave attackers OAuth access to Vercel's corporate Google environment. The blast radius reached hundreds of downstream organizations — and exposes a control gap that SAMA-regulated banks routinely overlook.
Malware & Threat ActorsInitial Access Brokers Hit GCC Finance: SAMA Bank Defense Playbook
Threat actor "Crimson" listed super-admin access to a GCC finance department in late April 2026. Here is what SAMA-regulated banks must do to defend against initial access brokers before ransomware affiliates buy in.
VulnerabilitiesFortiClient EMS CVE-2026-35616: Pre-Auth RCE Risk to SAMA Banks
CVE-2026-35616 in Fortinet FortiClient EMS allows pre-auth RCE on endpoint management servers across Saudi banks. Active exploitation confirmed by CISA — patch immediately under SAMA CSCC.
VulnerabilitiescPanel CVE-2026-41940 Auth Bypass: SAMA Bank Hosting Risk
A critical CRLF injection flaw (CVSS 9.8) lets unauthenticated attackers seize root on cPanel and WHM servers. Saudi banks face TPRM and hosting-supply-chain exposure. Here is the action plan.
VulnerabilitiesCisco SD-WAN Manager Exploited Trio (CVE-2026-20122/20128/20133): SAMA Bank Branch Risk
Three actively exploited Cisco Catalyst SD-WAN Manager vulnerabilities (CVE-2026-20122/20128/20133) place Saudi bank branch networks under immediate threat. Here is what SAMA-regulated CISOs must do this week.
RansomwareAkira Ransomware Bypasses MFA on SonicWall VPNs: SAMA Bank Defense Guide
Akira ransomware operators are now bypassing MFA on SonicWall SSL VPNs by exfiltrating OTP seed values from compromised firewalls. SAMA-regulated banks face urgent perimeter risk that demands immediate CSCC-aligned controls.
VulnerabilitiesFortra GoAnywhere MFT Flaws: Pre-CVE Threat to SAMA Banks
New Fortra GoAnywhere MFT vulnerabilities expose Saudi banks' regulated file transfers. Darktrace observed pre-CVE exploitation. SAMA CSCC remediation guide for Saudi CISOs.
RansomwareDragonForce Hits Conrad Capital: 74GB Breach Lessons for SAMA Banks
DragonForce ransomware breached US investment advisor Conrad Capital, exfiltrating 74.23GB and demanding negotiations within five days. We unpack the attack and what SAMA-regulated Saudi institutions must harden in CSCC controls today.
RansomwareScreenConnect CVE-2024-1708: Medusa Ransomware Threat to SAMA Banks
CISA added ConnectWise ScreenConnect CVE-2024-1708 to the KEV catalog on April 28, 2026, after China-linked Storm-1175 and North Korean Kimsuky weaponized the path-traversal flaw to deploy Medusa ransomware and ToddlerShark malware against managed service providers and their downstream customers.
VulnerabilitiesCopy Fail (CVE-2026-31431): 732-Byte Linux Root Escalation Hits Saudi Banks
A 732-byte Python script grants root on every major Linux distribution since 2017. CVE-2026-31431 'Copy Fail' threatens every Saudi bank's Linux infrastructure. Here's what SAMA CSCC requires now.
Breaches & Data LeaksShinyHunters Hits Ameriprise: 200GB SaaS Breach Lessons for SAMA Banks
ShinyHunters claimed 200GB of Ameriprise data, hitting nearly 48,000 customers via Salesforce and SharePoint. What SAMA-regulated Saudi banks must learn about SaaS supply chain risk and detection gaps.
RansomwareEverest Ransomware Hits Frost and Citizens: SAMA CSCC Lessons
Everest's April 2026 attacks on Frost Bank and Citizens Financial expose data-first extortion tactics SAMA-regulated banks must defend against now.