Insights & analysis
The blog.
Analysis of vulnerabilities and threats prioritised for Saudi finance — alongside AI and regulatory compliance.
400 articles · 14 topics
ShinyHunters Breach Instructure Canvas: 275 Million Records Expose Education Sector's Blind Spot
ShinyHunters breached Instructure's Canvas LMS twice in ten days, stealing 275 million records from 8,800+ institutions. Here's what went wrong and why Saudi organizations must reassess cloud vendor risk under PDPL.
VulnerabilitiesCVE-2026-32202: APT28 Exploits Zero-Click Windows Flaw to Steal NTLM Credentials — CISA Deadline Hits Today
A zero-click Windows shortcut flaw lets APT28 steal NTLM credentials without user interaction. Microsoft's incomplete patch left millions exposed — and CISA's remediation deadline expires today.
VulnerabilitiesBlueHammer, RedSun, UnDefend: Three Windows Defender Zero-Days That Turned Your Shield Into a Weapon
One researcher, three zero-days, 13 days. BlueHammer, RedSun, and UnDefend exploited Windows Defender's own remediation engine to escalate privileges to SYSTEM — and only one has been patched.
Software EngineeringCheckmarx Jenkins Plugin Backdoored by TeamPCP: CI/CD Supply Chain Under Siege
A rogue version of the Checkmarx Jenkins AST plugin was uploaded to the Jenkins Marketplace, turning trusted security tooling into an infostealer. Here's what happened and why SAMA-regulated institutions must audit their pipelines immediately.
VulnerabilitiesIvanti EPMM Zero-Day CVE-2026-6973: RCE Hits Enterprise Mobile Management
Ivanti's Endpoint Manager Mobile zero-day CVE-2026-6973 is under active exploitation. Attackers chain stolen credentials with an input validation flaw to achieve full RCE on EPMM appliances managing thousands of corporate devices.
Supply Chain & Third PartyTanStack NPM Supply Chain Attack CVE-2026-45321: Trusted Packages Weaponized to Steal Developer Secrets
A self-spreading worm hijacked TanStack's trusted CI/CD pipeline, publishing 84 malicious npm packages that exfiltrated GitHub tokens, SSH keys, and cloud credentials. CVSS 9.6 — here's what SAMA-regulated institutions need to check immediately.
VulnerabilitiesApache HTTP/2 Double-Free CVE-2026-23918: Two Frames, Zero Auth, Full RCE
A double-free in Apache mod_http2 lets attackers crash or take over servers with just two HTTP/2 frames and zero authentication. Here's what Saudi financial institutions need to do immediately.
Cloud & IdentityFake OpenAI Model on Hugging Face Steals Credentials: AI Supply Chain Risk for Financial Institutions
A fake OpenAI model on Hugging Face reached 244K downloads before removal, deploying a Rust infostealer that harvested browser credentials and SSH keys. Here's what Saudi financial institutions must do now.
VulnerabilitiesFortiClient EMS Zero-Day CVE-2026-35616: Pre-Auth API Bypass Hits Endpoint Management at Scale
A critical pre-authentication API bypass in FortiClient EMS was exploited as a zero-day before Fortinet disclosed it. Here's what SAMA-regulated institutions must do now.
VulnerabilitiesBleeding Llama: Critical Ollama Flaw Leaks AI Server Memory to Unauthenticated Attackers
A critical out-of-bounds read in Ollama's GGUF loader lets attackers siphon API keys, user prompts, and credentials from 300,000+ exposed AI servers — no authentication required.
VulnerabilitiesGoogle Confirms First AI-Generated Zero-Day Exploit by Criminal Hackers
Google's Threat Intelligence Group has confirmed the first-ever detection of a criminal zero-day exploit built with AI assistance — a milestone that reshapes the threat landscape for Saudi financial institutions.
Breaches & Data LeaksTrellix Source Code Breach: Why Your Security Vendor Could Be Your Biggest Risk
Trellix's source code repository was breached by RansomHouse. For SAMA-regulated banks running Trellix products, this supply chain risk event demands immediate third-party incident response.