Insights & analysis
The blog.
Analysis of vulnerabilities and threats prioritised for Saudi finance — alongside AI and regulatory compliance.
400 articles · 14 topics
Lesson 36: Third-Party Risk Management — Securing Your Vendor Ecosystem
Security Leadership Path — Lesson 6 of 10. Build a robust Third-Party Risk Management program that satisfies SAMA CSCC and NCA ECC requirements while protecting your organization from vendor-introduced threats.
VulnerabilitiesOracle Identity Manager CVE-2026-21992: Pre-Auth RCE Threatens Saudi Financial IAM Systems
Oracle issued an emergency out-of-band patch for CVE-2026-21992, a CVSS 9.8 pre-authentication RCE flaw in Identity Manager. Saudi banks running Oracle Fusion Middleware face immediate risk.
Guides & LessonsLesson 34: Building a Cybersecurity Team — Hiring and Development
Security Leadership Path — Lesson 4 of 10. A practical guide to recruiting, structuring, and developing a cybersecurity team that meets SAMA CSCC staffing requirements and protects your organization.
VulnerabilitiesCVE-2026-25075: 15-Year strongSwan VPN Flaw Threatens Saudi Financial Remote Access
A critical integer underflow in strongSwan's EAP-TTLS plugin lets unauthenticated attackers crash VPN gateways. With 15 years of affected versions, Saudi financial institutions must patch immediately to protect remote access infrastructure.
Guides & LessonsLesson 32: Building an Effective Cybersecurity Strategy for Saudi Financial Institutions
Security Leadership Path — Lesson 2 of 10. A step-by-step guide to building a cybersecurity strategy that satisfies regulators, protects the business, and earns board-level support.
VulnerabilitiesCVE-2026-32746: 32-Year-Old Telnetd Bug Gives Attackers Root Access — Why Saudi Financial Infrastructure Must Act Now
A 32-year-old buffer overflow in GNU telnetd now carries a CVSS 9.8 score and threatens every ICS, OT, and legacy network device still running Telnet on port 23 — including infrastructure inside Saudi financial institutions.
Guides & LessonsLesson 30: Security Operations Center (SOC) — Building and Operating
Hands-On Cybersecurity Path — Lesson 10 of 10. A practical guide to designing, staffing, and running a SOC that meets Saudi regulatory expectations.
VulnerabilitiesChrome Zero-Day CVE-2026-5281: WebGPU Flaw Actively Exploited — What Saudi Financial Institutions Must Do Now
Google's fourth Chrome zero-day of 2026 is being exploited in the wild. CVE-2026-5281 targets the Dawn WebGPU engine and can lead to remote code execution — here's what SAMA-regulated organizations need to act on today.
Cloud & IdentityLesson 28: Cloud Security — Securing AWS, Azure, and GCP Environments
Hands-On Cybersecurity Path — Lesson 8 of 10. Master cloud security fundamentals across the three major providers and align your cloud posture with SAMA and NCA requirements.
Supply Chain & Third PartyTrivy Supply Chain Attack CVE-2026-33634: When Your Security Scanner Becomes the Threat
Attackers compromised Aqua Security's Trivy scanner to harvest CI/CD secrets from thousands of pipelines. Here's what happened, who's behind it, and why Saudi financial institutions running Trivy must act immediately.
Malware & Threat ActorsLesson 26: Malware Analysis — Tools and Methodologies
Hands-On Cybersecurity Path — Lesson 6 of 10. Master the tools and methodologies used to dissect malicious software, from safe lab setup to behavioral analysis.
VulnerabilitiesCisco SD-WAN Zero-Day CVE-2026-20127: CVSS 10 Flaw Exploited Since 2023 Threatens Saudi Network Infrastructure
A CVSS 10.0 zero-day in Cisco Catalyst SD-WAN has been exploited since 2023 by threat actor UAT-8616. CISA mandated emergency patching. Here's what Saudi financial institutions need to do now.