Insights & analysis
The blog.
Analysis of vulnerabilities and threats prioritised for Saudi finance — alongside AI and regulatory compliance.
400 articles · 14 topics
Fake Ledger Live on Apple's App Store Stole $9.5M in 7 Days — App Supply Chain Risk Is Now a Board-Level Issue for Saudi Financial Institutions
A fraudulent Ledger Live app slipped through Apple's review process and stole $9.5 million from 50+ victims in a single week. Here's what this means for your institution's third-party and app supply chain risk posture.
VulnerabilitiesCVE-2026-35616: Fortinet FortiClient EMS Zero-Day Now Actively Exploited — Urgent Action Required for Saudi Financial Institutions
A CVSS 9.1 zero-day in Fortinet FortiClient EMS allows unauthenticated attackers to execute code on your endpoint management server — and exploitation has been recorded in the wild since March 31, 2026.
Malware & Threat ActorsCPUID Supply Chain Attack: How STX RAT Hijacked CPU-Z and HWMonitor — A Warning for Saudi Financial IT Teams
On April 9–10, 2026, attackers hijacked CPUID's official download servers to distribute STX RAT via trojanized CPU-Z and HWMonitor installers. Here's what Saudi financial institutions need to know.
Artificial IntelligencePushpaganda: AI-Generated Fake News in Google Discover Is Now Targeting Your Employees' Phones
HUMAN Security uncovered Pushpaganda — 240M poisoned ad requests exploiting Google Discover to deliver scareware via Android push notifications. Here's what every Saudi financial CISO must act on now.
Phishing & FraudW3LL Phishing Marketplace Dismantled: How a $500 Kit Bypassed MFA at Scale — Lessons for Saudi Financial CISOs
FBI Atlanta and Indonesian National Police seized the W3LL phishing marketplace on April 10, 2026 — a platform that sold MFA-bypassing phishing kits for $500 and enabled over $20M in fraud across 17,000 victims. Here's what SAMA-regulated institutions must do now.
Cloud & IdentityScattered Spider Returns: AI-Powered Vishing and Azure AD Hijacking Now Target Saudi Financial Institutions
Scattered Spider has pivoted from retail and tech to financial institutions, deploying AI-powered voice phishing and Azure AD federation backdoors to bypass MFA. Saudi banks under SAMA supervision face immediate exposure — here is what your security team must do now.
VulnerabilitiesSharePoint Zero-Day CVE-2026-32201: CISA KEV Alert Hits Saudi Banks
CISA's April 14 double-alert: a SharePoint zero-day (CVE-2026-32201) and a resurrected 2009 Office flaw prove old vulnerabilities never die. Saudi banks have a 13-day patch window — here's your action plan.
Malware & Threat ActorsAdobe's BPO Backdoor: How 'Mr. Raccoon' Stole 13M Support Tickets — and What Saudi Financial Institutions Must Learn About Vendor Risk
A threat actor called "Mr. Raccoon" compromised an Indian BPO contractor via RAT malware, exfiltrating 13M Adobe support tickets, 15K employee records, and unpublished HackerOne vulnerability reports — a masterclass in third-party risk gone wrong.
VulnerabilitiesCVE-2026-40261 & CVE-2026-40176: PHP Composer's Hidden Command Injection Risk — What Saudi Fintech Dev Teams Must Patch Now
Two command injection flaws in PHP Composer's Perforce VCS driver allow arbitrary code execution — no Perforce installation required. Saudi financial development teams still running Composer 2.0–2.9.5 are exposed right now.
VulnerabilitiesCVE-2026-25075: The 15-Year strongSwan Flaw That Can Crash Saudi Banks' VPN With One Packet
A single malformed EAP-TTLS packet can crash strongSwan VPN servers across 15+ years of releases. Saudi banks relying on IPsec/IKEv2 tunnels for branch and remote-access connectivity must patch CVE-2026-25075 to avoid an unauthenticated denial-of-service that SAMA CSCC classifies as a critical availability risk.
Breaches & Data LeaksBooking.com Breach Fuels Spear-Phishing Against Saudi Bank Employees
Booking.com confirmed hackers accessed customer reservation data. Saudi bank employees are now prime spear-phishing targets — here's your SAMA CSCC-aligned response.
Artificial IntelligenceAgentic AI: 2026's #1 Cyber Threat and What Saudi Banks Must Do Now
Autonomous AI agents can plan, adapt, and persist inside your environment indefinitely. With 80%+ of Saudi organizations racing to adopt AI tools, the attack surface is expanding faster than most defenses can keep up.