Insights & analysis
The blog.
Analysis of vulnerabilities and threats prioritised for Saudi finance — alongside AI and regulatory compliance.
400 articles · 14 topics
Lesson 24: Vulnerability Analysis — From Discovery to Assessment
Hands-On Cybersecurity Path — Lesson 4 of 10. Master the vulnerability analysis lifecycle: from scanning and discovery to risk-based prioritization aligned with SAMA and NCA requirements.
VulnerabilitiesCVE-2026-21643: FortiClient EMS SQL Injection Under Active Attack — Patch Before Attackers Steal Your Endpoint Inventory
A pre-auth SQL injection in FortiClient EMS 7.4.4 lets attackers dump admin credentials and endpoint policies with a single HTTP request. Exploitation began March 26 — here's what Saudi CISOs must do now.
Guides & LessonsLesson 22: Reconnaissance — OSINT Techniques for Beginners
Path 3: Hands-On Cybersecurity — Lesson 2 of 10. Master OSINT reconnaissance techniques to map an organization's digital footprint before a penetration test.
Network & InfrastructureCitrix NetScaler CVE-2026-3055: CISA KEV-Listed Memory Leak Hitting Financial Gateways
CISA added CVE-2026-3055 to its Known Exploited Vulnerabilities catalog on March 30. Attackers are already harvesting credentials from unpatched NetScaler gateways — here's what Saudi financial CISOs must do before the April 2 deadline.
Compliance & RegulationLesson 20: Building an Information Security Governance (GRC) Program from Scratch
Saudi Regulatory Compliance — Lesson 10 of 10. Build a complete GRC program from scratch, aligned with SAMA, NCA, and PDPL requirements for Saudi financial institutions.
Malware & Threat ActorsOperation TrueChaos: How a Video Conferencing Zero-Day Turned Trusted Updates into Malware
A zero-day in TrueConf's update mechanism let attackers push malware to every connected endpoint. Here's what Operation TrueChaos means for SAMA-regulated institutions and how to harden your internal software supply chain.
Compliance & RegulationLesson 18: Cybersecurity Maturity Assessment — How to Measure Your Current Posture
Path 2: Saudi Regulatory Compliance — Lesson 8 of 10. Learn practical methods to measure your cybersecurity maturity against SAMA CSCC and NCA ECC benchmarks.
VulnerabilitiesOracle Identity Manager CVE-2026-21992: Emergency RCE Patch Every Saudi Bank Must Apply Now
Oracle issues rare emergency patch for CVE-2026-21992 — a CVSS 9.8 pre-auth RCE flaw in Identity Manager. Saudi financial institutions using Oracle IAM must act immediately.
Compliance & RegulationLesson 16: ISO 27001:2022 — Key Changes and a Practical Implementation Plan
Saudi Regulatory Compliance Path — Lesson 6 of 10. Master the ISO 27001:2022 transition: new control structure, Annex A changes, and a phased implementation roadmap for Saudi financial institutions.
Supply Chain & Third PartyAxios npm Supply Chain Attack: RAT Deployed via 100M-Download Package
Attackers hijacked Axios — the most popular npm HTTP client with 100M+ weekly downloads — to deploy a self-destructing RAT. Here's what Saudi financial institutions must do immediately.
Guides & LessonsLesson 14: Saudi Personal Data Protection Law (PDPL) — A Practical Guide
Path 2: Saudi Regulatory Compliance — Lesson 4 of 10. Master PDPL requirements, data subject rights, and build a practical compliance roadmap for your financial institution.
VulnerabilitiesCVE-2026-33017: Langflow AI Pipeline RCE Exploited in 20 Hours — What CISOs Must Know
A critical code injection flaw in Langflow was weaponized within 20 hours of disclosure. If your organization runs AI workflow platforms, here's what you need to do immediately.