Topic
Cloud & Identity
Cloud misconfiguration risk and the identity and single sign-on systems attackers target.
83 articles in this topic
MuddyWater Targets Microsoft Teams MFA: SAMA Bank Defense Guide
Iranian state-sponsored MuddyWater is exploiting Microsoft Teams social engineering to harvest credentials and manipulate MFA at financial institutions, then planting Chaos ransomware as a false flag. Here is what SAMA-regulated banks must do.
Malware & Threat ActorsGopherWhisper APT: Slack & Microsoft 365 C2 Risk to SAMA Banks
ESET unveils GopherWhisper — a China-aligned APT using Discord, Slack and Microsoft 365 Outlook as covert C2. SAMA-regulated banks face the same legitimate-service abuse risk and must rethink detection.
Cloud & IdentityPCPJack Cloud Worm: Credential Theft Threat to SAMA Banks
SentinelLabs has uncovered PCPJack, a self-propagating cloud worm that hijacks TeamPCP infrastructure and steals credentials at scale. Saudi financial institutions running cloud workloads face urgent SAMA CSCC exposure.
Cloud & IdentityTeamPCP Cloud Compromise: CI/CD Threat for SAMA Banks
TeamPCP weaponized open-source security tools (Trivy, LiteLLM, KICS) to harvest CI/CD secrets and pivot into AWS, Azure and SaaS environments. SAMA-regulated banks must reassess third-party and pipeline trust now.
Phishing & FraudAiTM Phishing Campaign 2026: 35,000-Victim MFA Bypass Threatens SAMA Banks
Microsoft Defender Research uncovered a multi-stage AiTM phishing campaign that hit 35,000 users across 26 countries — financial services was 18% of victims. What SAMA-regulated banks must do today.
VulnerabilitiesCVE-2026-32202: APT28's Zero-Click Windows Shell Threat to SAMA Banks
A zero-click Windows Shell vulnerability (CVE-2026-32202) is being weaponized by Russian APT28 to silently harvest NTLMv2 credentials. Saudi banks face an urgent patching window before May 12.
Cloud & IdentityOracle Identity Manager CVE-2026-21992: Critical IAM Threat to SAMA Banks
A pre-authentication RCE in Oracle Identity Manager (CVSS 9.8) gives attackers direct control of the IAM core that Saudi banks rely on for SAMA CSCC compliance. Here is how to detect, patch, and respond.
Malware & Threat ActorsMuddyWater's Teams Attack: Iranian APT Threat to SAMA Banks
Iranian state-sponsored MuddyWater is exploiting Microsoft Teams screen-share to harvest credentials and bypass MFA, while masking espionage as Chaos ransomware. Implications for SAMA-regulated banks.
Cloud & IdentityVercel-Context AI OAuth Breach: Shadow AI Risk Lessons for SAMA Banks
A single Shadow AI tool installed by one Vercel employee triggered an OAuth supply-chain breach exposing API keys, source code, and customer credentials — a textbook warning for SAMA-regulated banks tightening third-party governance under CSCC and ECC.
Cloud & IdentityCVE-2026-42354: Sentry SAML SSO Bypass Threatens SAMA Bank IAM
A critical Sentry SAML SSO bypass (CVE-2026-42354) enables full account takeover with only the victim's email address. Saudi financial institutions relying on federated identity must act now to align with SAMA CSCC IAM controls.
VulnerabilitiesFortinet CVE-2026-24858: FortiCloud SSO Bypass Hits SAMA Banks
Fortinet's CVE-2026-24858 lets attackers bypass FortiCloud SSO and seize admin control over FortiOS, FortiManager, and FortiProxy. Why SAMA-regulated banks must act before patches arrive.
VulnerabilitiesMOVEit CVE-2026-4670 Auth Bypass: SAMA Bank File Transfer Risk
Progress Software patched a critical MOVEit Automation auth bypass (CVE-2026-4670) that exposes credentials and financial files. Saudi banks must act before exploitation hits SAMA-regulated MFT flows.
From reading to doing
How secure is your cloud environment?
A cloud security assessment reviews your account configuration, access rights and exposed data, and sets out what to fix first.
Cloud Security Assessment
Comprehensive security configuration review for AWS, Azure, and GCP cloud environments to ensure your data protection
Security Architecture Review
An in-depth review of your network and systems architecture to ensure security is built into the design, not bolted on later.
Cloud Infrastructure & IaC
We design secure, reproducible cloud infrastructure using infrastructure-as-code.