Insights & analysis
The blog.
Analysis of vulnerabilities and threats prioritised for Saudi finance — alongside AI and regulatory compliance.
400 articles · 14 topics
Chrome Zero-Day CVE-2026-5281: WebGPU Exploit Chain Threatens Saudi Financial Institutions
Google's fourth zero-day of 2026 targets Chrome's WebGPU layer via a use-after-free in Dawn. CISA added it to the KEV catalog — here's what Saudi banks and financial institutions must do now.
Cloud & IdentityEverest Ransomware Steals 910GB from Nissan via Stale FTP Credentials — A Third-Party Risk Wake-Up Call for Saudi Banks
Everest ransomware exfiltrated 910GB of Nissan customer and loan data through a vendor FTP server with 3-year-old credentials and no MFA. Here's what Saudi financial institutions must learn about third-party risk management.
VulnerabilitiesProgress ShareFile Pre-Auth RCE Chain: 30,000 Servers Exposed and Saudi Banks Must Patch Now
Two chained ShareFile flaws give attackers full server control without credentials. With 30,000 instances exposed globally, Saudi financial institutions running on-premise ShareFile must act before exploitation campaigns begin.
VulnerabilitiesCisco IMC CVE-2026-20093: CVSS 9.8 Auth Bypass Puts Saudi Bank Server Infrastructure at Risk
A single crafted HTTP request can hand an attacker full admin access to your Cisco UCS servers. CVE-2026-20093 scores 9.8 CVSS and has no workaround — only a firmware update. Here's what Saudi bank infrastructure teams must do right now.
VulnerabilitiesInterlock Ransomware Exploited Cisco FMC Zero-Day for 36 Days Before Disclosure — Saudi Banks Must Audit Now
Interlock ransomware weaponized a CVSS 10.0 Cisco Firewall Management Center flaw for over a month before Cisco disclosed it. Saudi banks relying on Cisco firewalls face immediate exposure — here is what your SOC team must do today.
VulnerabilitiesMicrosoft Patches Four Critical Azure Flaws at CVSS 10.0 — Saudi Banks on Azure Must Act Now
Microsoft disclosed four critical Azure vulnerabilities — two scoring a perfect CVSS 10.0 — affecting AI Foundry, Kubernetes Service, Custom Locations, and MCP Server. Saudi banks running workloads on Azure face urgent remediation requirements under SAMA CSCC.
VulnerabilitiesFortiClient EMS Zero-Day CVE-2026-35616: CVSS 9.1 Pre-Auth RCE Under Active Exploitation
Fortinet's emergency hotfix for CVE-2026-35616 confirms active zero-day exploitation of FortiClient EMS. Saudi banks running versions 7.4.5–7.4.6 face unauthenticated remote code execution risk.
Malware & Threat ActorsFake Claude Code Leak on GitHub Delivers Vidar Stealer — Why Saudi Bank Dev Teams Must Vet Every Download
A fake Claude Code repository on GitHub is delivering Vidar infostealer and GhostSocks proxy malware to developers who download it. Here's what Saudi bank security teams need to know — and do — right now.
Artificial IntelligenceLiteLLM Supply Chain Attack: How TeamPCP and Lapsus$ Breached 500,000 Machines Through an AI Library Saudi Banks May Be Running
A 40-minute window was all it took. TeamPCP poisoned LiteLLM's PyPI packages and set off a cascade that compromised 500,000 machines, 1,000+ SaaS environments, and handed Lapsus$ 4TB of data from AI startup Mercor.
Malware & Threat ActorsWhatsApp Spyrtacus Alert: How Government-Grade Spyware Is Targeting Mobile Apps Saudi Banks Use Every Day
Meta's WhatsApp has flagged a government-grade spyware campaign using a counterfeit iOS app to harvest messages, calls, and recordings from targets' devices. For Saudi financial institutions relying on WhatsApp for business communications, the compliance and security implications are immediate.
Malware & Threat ActorsHandala Wiped 200,000 Stryker Devices in Minutes — The Intune Attack Vector Saudi Banks Cannot Ignore
On March 11, 2026, Iran-linked Handala triggered simultaneous factory resets on 200,000+ corporate devices at Stryker using Microsoft Intune. If your bank runs Azure AD, this attack vector is already in your environment.
Breaches & Data LeaksDrift Protocol's $285M Hack: Why Saudi Financial Institutions Must Rethink DeFi Exposure Now
North Korean-linked attackers executed a $285M exploit against Solana's Drift Protocol using fake tokens, oracle manipulation, and governance hijacking — the largest DeFi hack of 2026. Here's why Saudi FIs must reassess their digital asset risk posture.