Insights & analysis

The blog.

Analysis of vulnerabilities and threats prioritised for Saudi finance — alongside AI and regulatory compliance.

400 articles · 14 topics

Supply Chain & Third Party

Fake Ledger Live on Apple's App Store Stole $9.5M in 7 Days — App Supply Chain Risk Is Now a Board-Level Issue for Saudi Financial Institutions

A fraudulent Ledger Live app slipped through Apple's review process and stole $9.5 million from 50+ victims in a single week. Here's what this means for your institution's third-party and app supply chain risk posture.

15 Apr 2026 5 min
Vulnerabilities

CVE-2026-35616: Fortinet FortiClient EMS Zero-Day Now Actively Exploited — Urgent Action Required for Saudi Financial Institutions

A CVSS 9.1 zero-day in Fortinet FortiClient EMS allows unauthenticated attackers to execute code on your endpoint management server — and exploitation has been recorded in the wild since March 31, 2026.

15 Apr 2026 6 min
Malware & Threat Actors

CPUID Supply Chain Attack: How STX RAT Hijacked CPU-Z and HWMonitor — A Warning for Saudi Financial IT Teams

On April 9–10, 2026, attackers hijacked CPUID's official download servers to distribute STX RAT via trojanized CPU-Z and HWMonitor installers. Here's what Saudi financial institutions need to know.

15 Apr 2026 6 min
Artificial Intelligence

Pushpaganda: AI-Generated Fake News in Google Discover Is Now Targeting Your Employees' Phones

HUMAN Security uncovered Pushpaganda — 240M poisoned ad requests exploiting Google Discover to deliver scareware via Android push notifications. Here's what every Saudi financial CISO must act on now.

15 Apr 2026 5 min
Phishing & Fraud

W3LL Phishing Marketplace Dismantled: How a $500 Kit Bypassed MFA at Scale — Lessons for Saudi Financial CISOs

FBI Atlanta and Indonesian National Police seized the W3LL phishing marketplace on April 10, 2026 — a platform that sold MFA-bypassing phishing kits for $500 and enabled over $20M in fraud across 17,000 victims. Here's what SAMA-regulated institutions must do now.

15 Apr 2026 5 min
Cloud & Identity

Scattered Spider Returns: AI-Powered Vishing and Azure AD Hijacking Now Target Saudi Financial Institutions

Scattered Spider has pivoted from retail and tech to financial institutions, deploying AI-powered voice phishing and Azure AD federation backdoors to bypass MFA. Saudi banks under SAMA supervision face immediate exposure — here is what your security team must do now.

15 Apr 2026 5 min
Vulnerabilities

SharePoint Zero-Day CVE-2026-32201: CISA KEV Alert Hits Saudi Banks

CISA's April 14 double-alert: a SharePoint zero-day (CVE-2026-32201) and a resurrected 2009 Office flaw prove old vulnerabilities never die. Saudi banks have a 13-day patch window — here's your action plan.

15 Apr 2026 6 min
Malware & Threat Actors

Adobe's BPO Backdoor: How 'Mr. Raccoon' Stole 13M Support Tickets — and What Saudi Financial Institutions Must Learn About Vendor Risk

A threat actor called "Mr. Raccoon" compromised an Indian BPO contractor via RAT malware, exfiltrating 13M Adobe support tickets, 15K employee records, and unpublished HackerOne vulnerability reports — a masterclass in third-party risk gone wrong.

15 Apr 2026 5 min
Vulnerabilities

CVE-2026-40261 & CVE-2026-40176: PHP Composer's Hidden Command Injection Risk — What Saudi Fintech Dev Teams Must Patch Now

Two command injection flaws in PHP Composer's Perforce VCS driver allow arbitrary code execution — no Perforce installation required. Saudi financial development teams still running Composer 2.0–2.9.5 are exposed right now.

15 Apr 2026 5 min
Vulnerabilities

CVE-2026-25075: The 15-Year strongSwan Flaw That Can Crash Saudi Banks' VPN With One Packet

A single malformed EAP-TTLS packet can crash strongSwan VPN servers across 15+ years of releases. Saudi banks relying on IPsec/IKEv2 tunnels for branch and remote-access connectivity must patch CVE-2026-25075 to avoid an unauthenticated denial-of-service that SAMA CSCC classifies as a critical availability risk.

15 Apr 2026 5 min
Breaches & Data Leaks

Booking.com Breach Fuels Spear-Phishing Against Saudi Bank Employees

Booking.com confirmed hackers accessed customer reservation data. Saudi bank employees are now prime spear-phishing targets — here's your SAMA CSCC-aligned response.

14 Apr 2026 5 min
Artificial Intelligence

Agentic AI: 2026's #1 Cyber Threat and What Saudi Banks Must Do Now

Autonomous AI agents can plan, adapt, and persist inside your environment indefinitely. With 80%+ of Saudi organizations racing to adopt AI tools, the attack surface is expanding faster than most defenses can keep up.

14 Apr 2026 6 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality