Insights & analysis

The blog.

Analysis of vulnerabilities and threats prioritised for Saudi finance — alongside AI and regulatory compliance.

400 articles · 14 topics

Compliance & Regulation

Lesson 36: Third-Party Risk Management — Securing Your Vendor Ecosystem

Security Leadership Path — Lesson 6 of 10. Build a robust Third-Party Risk Management program that satisfies SAMA CSCC and NCA ECC requirements while protecting your organization from vendor-introduced threats.

3 Apr 2026 8 min
Vulnerabilities

Oracle Identity Manager CVE-2026-21992: Pre-Auth RCE Threatens Saudi Financial IAM Systems

Oracle issued an emergency out-of-band patch for CVE-2026-21992, a CVSS 9.8 pre-authentication RCE flaw in Identity Manager. Saudi banks running Oracle Fusion Middleware face immediate risk.

3 Apr 2026 5 min
Guides & Lessons

Lesson 34: Building a Cybersecurity Team — Hiring and Development

Security Leadership Path — Lesson 4 of 10. A practical guide to recruiting, structuring, and developing a cybersecurity team that meets SAMA CSCC staffing requirements and protects your organization.

1 Apr 2026 8 min
Vulnerabilities

CVE-2026-25075: 15-Year strongSwan VPN Flaw Threatens Saudi Financial Remote Access

A critical integer underflow in strongSwan's EAP-TTLS plugin lets unauthenticated attackers crash VPN gateways. With 15 years of affected versions, Saudi financial institutions must patch immediately to protect remote access infrastructure.

1 Apr 2026 6 min
Guides & Lessons

Lesson 32: Building an Effective Cybersecurity Strategy for Saudi Financial Institutions

Security Leadership Path — Lesson 2 of 10. A step-by-step guide to building a cybersecurity strategy that satisfies regulators, protects the business, and earns board-level support.

1 Apr 2026 8 min
Vulnerabilities

CVE-2026-32746: 32-Year-Old Telnetd Bug Gives Attackers Root Access — Why Saudi Financial Infrastructure Must Act Now

A 32-year-old buffer overflow in GNU telnetd now carries a CVSS 9.8 score and threatens every ICS, OT, and legacy network device still running Telnet on port 23 — including infrastructure inside Saudi financial institutions.

1 Apr 2026 5 min
Guides & Lessons

Lesson 30: Security Operations Center (SOC) — Building and Operating

Hands-On Cybersecurity Path — Lesson 10 of 10. A practical guide to designing, staffing, and running a SOC that meets Saudi regulatory expectations.

1 Apr 2026 9 min
Vulnerabilities

Chrome Zero-Day CVE-2026-5281: WebGPU Flaw Actively Exploited — What Saudi Financial Institutions Must Do Now

Google's fourth Chrome zero-day of 2026 is being exploited in the wild. CVE-2026-5281 targets the Dawn WebGPU engine and can lead to remote code execution — here's what SAMA-regulated organizations need to act on today.

1 Apr 2026 5 min
Cloud & Identity

Lesson 28: Cloud Security — Securing AWS, Azure, and GCP Environments

Hands-On Cybersecurity Path — Lesson 8 of 10. Master cloud security fundamentals across the three major providers and align your cloud posture with SAMA and NCA requirements.

1 Apr 2026 8 min
Supply Chain & Third Party

Trivy Supply Chain Attack CVE-2026-33634: When Your Security Scanner Becomes the Threat

Attackers compromised Aqua Security's Trivy scanner to harvest CI/CD secrets from thousands of pipelines. Here's what happened, who's behind it, and why Saudi financial institutions running Trivy must act immediately.

1 Apr 2026 5 min
Malware & Threat Actors

Lesson 26: Malware Analysis — Tools and Methodologies

Hands-On Cybersecurity Path — Lesson 6 of 10. Master the tools and methodologies used to dissect malicious software, from safe lab setup to behavioral analysis.

1 Apr 2026 8 min
Vulnerabilities

Cisco SD-WAN Zero-Day CVE-2026-20127: CVSS 10 Flaw Exploited Since 2023 Threatens Saudi Network Infrastructure

A CVSS 10.0 zero-day in Cisco Catalyst SD-WAN has been exploited since 2023 by threat actor UAT-8616. CISA mandated emergency patching. Here's what Saudi financial institutions need to do now.

1 Apr 2026 6 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality