Insights & analysis

The blog.

Analysis of vulnerabilities and threats prioritised for Saudi finance — alongside AI and regulatory compliance.

400 articles · 14 topics

Malware & Threat Actors

MuddyWater's False-Flag Playbook: Iranian APT Hides Espionage Behind Chaos Ransomware

Iranian APT MuddyWater deployed Chaos ransomware as a decoy while conducting espionage via Microsoft Teams social engineering. Saudi CISOs must rethink their IR playbooks.

19 May 2026 5 min
Breaches & Data Leaks

ShinyHunters' 2026 Breach Spree: How One Group Compromised Billions of Records Across Six Sectors

ShinyHunters breached the EU Commission, Medtronic, Rockstar Games, and 8,809 universities in five months — all through OAuth misconfigurations and supply chain trust. Here's what Saudi financial CISOs must do now.

19 May 2026 6 min
Vulnerabilities

First AI-Generated Zero-Day Exploit Caught in the Wild: What Saudi Financial CISOs Must Know

Google confirms the first AI-generated zero-day exploit used by criminal hackers — a 2FA bypass built by an LLM. What this means for Saudi financial institutions and how CISOs should respond.

19 May 2026 5 min
Compliance & Regulation

NCA NCNICC-1:2025: Every Saudi Private Company Now Faces Mandatory Cybersecurity Controls

NCA's NCNICC-1:2025 makes cybersecurity controls mandatory for all Saudi private companies. Learn the 65 controls, Category A vs. B requirements, and how to achieve compliance alongside SAMA CSCC.

19 May 2026 5 min
Vulnerabilities

Windows MiniPlasma Zero-Day Grants SYSTEM Access on Fully Patched Systems — PoC Is Public

A weaponized PoC exploit called MiniPlasma grants SYSTEM privileges on fully patched Windows 11 systems by exploiting a six-year-old flaw in the Cloud Filter driver. Here's what Saudi financial institutions must do now.

19 May 2026 5 min
Vulnerabilities

CVE-2026-41103: Microsoft SSO Plugin Flaw Gives Attackers Admin Access to Your Jira and Confluence

A CVSS 9.1 flaw in Microsoft's SSO Plugin lets unauthenticated attackers forge SAML responses and gain admin access to Jira and Confluence—exposing compliance data, security findings, and internal documentation across SAMA-regulated institutions.

19 May 2026 5 min
Vulnerabilities

CVE-2026-42897: Exchange OWA Zero-Day Turns a Single Email into Full Browser Hijack

Microsoft confirms active exploitation of CVE-2026-42897, a stored XSS in Exchange OWA that hijacks authenticated sessions via a single crafted email. CISA KEV-listed with a May 29 deadline—Saudi financial institutions must patch within 48 hours to meet SAMA CSCC requirements.

19 May 2026 5 min
Cloud & Identity

Tycoon2FA Rebounds: Device-Code Phishing Bypasses MFA to Hijack Microsoft 365 Accounts

The Tycoon2FA phishing-as-a-service kit has rebounded after a March takedown, now weaponizing OAuth device-code flows to steal Microsoft 365 tokens — rendering traditional MFA useless. Here's what Saudi CISOs need to know.

19 May 2026 6 min
Software Engineering

Grafana GitHub Token Breach: How a CI/CD Misconfiguration Exposed the Codebase Behind Your SOC Dashboards

A single misconfigured GitHub Action let attackers steal Grafana's entire codebase. For Saudi financial institutions relying on Grafana for SOC dashboards, the breach raises urgent questions about CI/CD pipeline security and open-source supply chain risk.

19 May 2026 5 min
Supply Chain & Third Party

Mini Shai-Hulud Worm: How One npm Install Compromised 160+ Packages and Stole CI/CD Secrets

A self-propagating worm dubbed Mini Shai-Hulud hijacked 160+ npm and PyPI packages — including TanStack and Mistral AI — turning every compromised developer into a new infection vector. Here's what your DevSecOps team needs to act on immediately.

19 May 2026 5 min
Vulnerabilities

Pwn2Own Berlin 2026: 47 Zero-Days in Enterprise Tech Expose What Scanners Miss

47 zero-days across Exchange, SharePoint, VMware ESXi, and AI platforms — $1.3M in bounties at Pwn2Own Berlin 2026. What the results mean for Saudi financial institutions and their 90-day patch window.

19 May 2026 6 min
Vulnerabilities

Microsoft May 2026 Patch Tuesday: Azure DevOps CVSS 10.0 and Netlogon RCE Demand Immediate Action

Microsoft patched 118 vulnerabilities in May 2026, including CVE-2026-42826 — a perfect CVSS 10.0 Azure DevOps information disclosure flaw exploitable without authentication. Here's what Saudi financial institutions must patch first.

19 May 2026 6 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality