Insights & analysis
The blog.
Analysis of vulnerabilities and threats prioritised for Saudi finance — alongside AI and regulatory compliance.
400 articles · 14 topics
MuddyWater's False-Flag Playbook: Iranian APT Hides Espionage Behind Chaos Ransomware
Iranian APT MuddyWater deployed Chaos ransomware as a decoy while conducting espionage via Microsoft Teams social engineering. Saudi CISOs must rethink their IR playbooks.
Breaches & Data LeaksShinyHunters' 2026 Breach Spree: How One Group Compromised Billions of Records Across Six Sectors
ShinyHunters breached the EU Commission, Medtronic, Rockstar Games, and 8,809 universities in five months — all through OAuth misconfigurations and supply chain trust. Here's what Saudi financial CISOs must do now.
VulnerabilitiesFirst AI-Generated Zero-Day Exploit Caught in the Wild: What Saudi Financial CISOs Must Know
Google confirms the first AI-generated zero-day exploit used by criminal hackers — a 2FA bypass built by an LLM. What this means for Saudi financial institutions and how CISOs should respond.
Compliance & RegulationNCA NCNICC-1:2025: Every Saudi Private Company Now Faces Mandatory Cybersecurity Controls
NCA's NCNICC-1:2025 makes cybersecurity controls mandatory for all Saudi private companies. Learn the 65 controls, Category A vs. B requirements, and how to achieve compliance alongside SAMA CSCC.
VulnerabilitiesWindows MiniPlasma Zero-Day Grants SYSTEM Access on Fully Patched Systems — PoC Is Public
A weaponized PoC exploit called MiniPlasma grants SYSTEM privileges on fully patched Windows 11 systems by exploiting a six-year-old flaw in the Cloud Filter driver. Here's what Saudi financial institutions must do now.
VulnerabilitiesCVE-2026-41103: Microsoft SSO Plugin Flaw Gives Attackers Admin Access to Your Jira and Confluence
A CVSS 9.1 flaw in Microsoft's SSO Plugin lets unauthenticated attackers forge SAML responses and gain admin access to Jira and Confluence—exposing compliance data, security findings, and internal documentation across SAMA-regulated institutions.
VulnerabilitiesCVE-2026-42897: Exchange OWA Zero-Day Turns a Single Email into Full Browser Hijack
Microsoft confirms active exploitation of CVE-2026-42897, a stored XSS in Exchange OWA that hijacks authenticated sessions via a single crafted email. CISA KEV-listed with a May 29 deadline—Saudi financial institutions must patch within 48 hours to meet SAMA CSCC requirements.
Cloud & IdentityTycoon2FA Rebounds: Device-Code Phishing Bypasses MFA to Hijack Microsoft 365 Accounts
The Tycoon2FA phishing-as-a-service kit has rebounded after a March takedown, now weaponizing OAuth device-code flows to steal Microsoft 365 tokens — rendering traditional MFA useless. Here's what Saudi CISOs need to know.
Software EngineeringGrafana GitHub Token Breach: How a CI/CD Misconfiguration Exposed the Codebase Behind Your SOC Dashboards
A single misconfigured GitHub Action let attackers steal Grafana's entire codebase. For Saudi financial institutions relying on Grafana for SOC dashboards, the breach raises urgent questions about CI/CD pipeline security and open-source supply chain risk.
Supply Chain & Third PartyMini Shai-Hulud Worm: How One npm Install Compromised 160+ Packages and Stole CI/CD Secrets
A self-propagating worm dubbed Mini Shai-Hulud hijacked 160+ npm and PyPI packages — including TanStack and Mistral AI — turning every compromised developer into a new infection vector. Here's what your DevSecOps team needs to act on immediately.
VulnerabilitiesPwn2Own Berlin 2026: 47 Zero-Days in Enterprise Tech Expose What Scanners Miss
47 zero-days across Exchange, SharePoint, VMware ESXi, and AI platforms — $1.3M in bounties at Pwn2Own Berlin 2026. What the results mean for Saudi financial institutions and their 90-day patch window.
VulnerabilitiesMicrosoft May 2026 Patch Tuesday: Azure DevOps CVSS 10.0 and Netlogon RCE Demand Immediate Action
Microsoft patched 118 vulnerabilities in May 2026, including CVE-2026-42826 — a perfect CVSS 10.0 Azure DevOps information disclosure flaw exploitable without authentication. Here's what Saudi financial institutions must patch first.