Topic
Cloud & Identity
Cloud misconfiguration risk and the identity and single sign-on systems attackers target.
83 articles in this topic
EvilTokens PhaaS: Device Code Phishing Bypasses MFA to Hijack Microsoft 365 Accounts
EvilTokens PhaaS platform has compromised 340+ Microsoft 365 orgs by abusing OAuth device code flow to bypass MFA. Learn how Saudi financial institutions can defend against this active threat.
VulnerabilitiesCVE-2026-41096: Windows DNS Client RCE Lets Attackers Hijack Every Endpoint Without a Click
Microsoft's May 2026 Patch Tuesday disclosed CVE-2026-41096, a CVSS 9.8 heap overflow in the Windows DNS Client enabling unauthenticated RCE on every Windows endpoint. Here's what Saudi financial institutions must do now.
VulnerabilitiesCVE-2026-0073: Android Zero-Click RCE Lets Attackers Hijack Devices Over Wi-Fi
A CVSS 9.8 zero-click flaw in Android's wireless ADB lets nearby attackers gain full shell access — no tap required. Saudi financial institutions running BYOD and mobile banking must patch immediately.
VulnerabilitiesCVE-2026-41103: Critical Microsoft SSO Plugin Flaw Lets Attackers Forge Identities in Jira and Confluence
A CVSS 9.1 flaw in Microsoft's SSO Plugin for Jira and Confluence lets unauthenticated attackers forge identities and gain admin access — bypassing Entra ID entirely. Here's what Saudi CISOs must do now.
Supply Chain & Third PartyMini Shai-Hulud: SAP npm Supply Chain Attack Steals Developer Credentials and CI/CD Secrets
Four official SAP npm packages were compromised with credential-stealing malware in the Mini Shai-Hulud campaign. Here's what Saudi financial CISOs must do to protect their SAP development pipelines.
Breaches & Data LeaksShinyHunters' 2026 Breach Spree: How One Group Compromised Billions of Records Across Six Sectors
ShinyHunters breached the EU Commission, Medtronic, Rockstar Games, and 8,809 universities in five months — all through OAuth misconfigurations and supply chain trust. Here's what Saudi financial CISOs must do now.
VulnerabilitiesCVE-2026-41103: Microsoft SSO Plugin Flaw Gives Attackers Admin Access to Your Jira and Confluence
A CVSS 9.1 flaw in Microsoft's SSO Plugin lets unauthenticated attackers forge SAML responses and gain admin access to Jira and Confluence—exposing compliance data, security findings, and internal documentation across SAMA-regulated institutions.
VulnerabilitiesCVE-2026-42897: Exchange OWA Zero-Day Turns a Single Email into Full Browser Hijack
Microsoft confirms active exploitation of CVE-2026-42897, a stored XSS in Exchange OWA that hijacks authenticated sessions via a single crafted email. CISA KEV-listed with a May 29 deadline—Saudi financial institutions must patch within 48 hours to meet SAMA CSCC requirements.
Cloud & IdentityTycoon2FA Rebounds: Device-Code Phishing Bypasses MFA to Hijack Microsoft 365 Accounts
The Tycoon2FA phishing-as-a-service kit has rebounded after a March takedown, now weaponizing OAuth device-code flows to steal Microsoft 365 tokens — rendering traditional MFA useless. Here's what Saudi CISOs need to know.
Software EngineeringGrafana GitHub Token Breach: How a CI/CD Misconfiguration Exposed the Codebase Behind Your SOC Dashboards
A single misconfigured GitHub Action let attackers steal Grafana's entire codebase. For Saudi financial institutions relying on Grafana for SOC dashboards, the breach raises urgent questions about CI/CD pipeline security and open-source supply chain risk.
VulnerabilitiesMicrosoft May 2026 Patch Tuesday: Azure DevOps CVSS 10.0 and Netlogon RCE Demand Immediate Action
Microsoft patched 118 vulnerabilities in May 2026, including CVE-2026-42826 — a perfect CVSS 10.0 Azure DevOps information disclosure flaw exploitable without authentication. Here's what Saudi financial institutions must patch first.
Artificial IntelligenceClaw Chain: Four OpenClaw Flaws Let Attackers Hijack AI Agents from Inside the Sandbox
Four chainable vulnerabilities in OpenClaw AI agent platform — dubbed Claw Chain — allow sandbox escape, data theft, and persistent backdoors across 245,000 exposed servers. Critical implications for Saudi financial institutions under SAMA CSCC.
From reading to doing
How secure is your cloud environment?
A cloud security assessment reviews your account configuration, access rights and exposed data, and sets out what to fix first.
Cloud Security Assessment
Comprehensive security configuration review for AWS, Azure, and GCP cloud environments to ensure your data protection
Security Architecture Review
An in-depth review of your network and systems architecture to ensure security is built into the design, not bolted on later.
Cloud Infrastructure & IaC
We design secure, reproducible cloud infrastructure using infrastructure-as-code.