Topic
Cloud & Identity
Cloud misconfiguration risk and the identity and single sign-on systems attackers target.
83 articles in this topic
W3LL Phishing Marketplace Dismantled: How a $500 Kit Bypassed MFA at Scale — Lessons for Saudi Financial CISOs
FBI Atlanta and Indonesian National Police seized the W3LL phishing marketplace on April 10, 2026 — a platform that sold MFA-bypassing phishing kits for $500 and enabled over $20M in fraud across 17,000 victims. Here's what SAMA-regulated institutions must do now.
Cloud & IdentityScattered Spider Returns: AI-Powered Vishing and Azure AD Hijacking Now Target Saudi Financial Institutions
Scattered Spider has pivoted from retail and tech to financial institutions, deploying AI-powered voice phishing and Azure AD federation backdoors to bypass MFA. Saudi banks under SAMA supervision face immediate exposure — here is what your security team must do now.
Malware & Threat ActorsCVE-2026-40175: Axios Gets Hit Twice — North Korean Backdoor Then a 9.9 CVSS Flaw That Hands Attackers Your AWS Keys
Axios npm suffered a North Korean supply chain backdoor in March, then a 9.9 CVSS flaw a week later. Saudi open banking teams running Node.js on AWS need to act before threat actors chain both.
VulnerabilitiesReact2Shell (CVE-2025-55182): The CVSS-10 Flaw Silently Draining API Keys from Financial Web Apps
A CVSS-10 flaw in React Server Components has enabled threat actor UAT-10608 to silently harvest credentials from 766+ hosts. Saudi financial institutions running Next.js-based portals face immediate exposure.
Cloud & IdentityFBI & CISA Alert: Russian Intelligence Is Hijacking WhatsApp Accounts — Saudi Banks Are a Prime Target
Russian state-sponsored actors are walking around end-to-end encryption by hijacking WhatsApp and Signal accounts directly. Saudi financial institutions — where WhatsApp is the de facto business communication channel — are acutely exposed.
Cloud & IdentityHow Social Engineering Hijacks Okta to Breach Every SaaS You Use
A single phone call compromised Hims & Hers' Okta SSO in Feb 2026, exposing 1.8M customer support tickets. Saudi banks using SSO face the same risk — here's how to defend.
VulnerabilitiesTrueConf CVE-2026-3502: Video Conferencing Update Hijack Exploited by State-Sponsored Hackers
CISA flags TrueConf Client CVE-2026-3502 after Chinese-linked hackers weaponize its update mechanism. Saudi banks relying on video conferencing must audit software integrity controls immediately.
Cloud & IdentityEverest Ransomware Steals 910GB from Nissan via Stale FTP Credentials — A Third-Party Risk Wake-Up Call for Saudi Banks
Everest ransomware exfiltrated 910GB of Nissan customer and loan data through a vendor FTP server with 3-year-old credentials and no MFA. Here's what Saudi financial institutions must learn about third-party risk management.
VulnerabilitiesProgress ShareFile Pre-Auth RCE Chain: 30,000 Servers Exposed and Saudi Banks Must Patch Now
Two chained ShareFile flaws give attackers full server control without credentials. With 30,000 instances exposed globally, Saudi financial institutions running on-premise ShareFile must act before exploitation campaigns begin.
VulnerabilitiesMicrosoft Patches Four Critical Azure Flaws at CVSS 10.0 — Saudi Banks on Azure Must Act Now
Microsoft disclosed four critical Azure vulnerabilities — two scoring a perfect CVSS 10.0 — affecting AI Foundry, Kubernetes Service, Custom Locations, and MCP Server. Saudi banks running workloads on Azure face urgent remediation requirements under SAMA CSCC.
Malware & Threat ActorsHandala Wiped 200,000 Stryker Devices in Minutes — The Intune Attack Vector Saudi Banks Cannot Ignore
On March 11, 2026, Iran-linked Handala triggered simultaneous factory resets on 200,000+ corporate devices at Stryker using Microsoft Intune. If your bank runs Azure AD, this attack vector is already in your environment.
Breaches & Data LeaksShinyHunters Claims 3M+ Cisco Salesforce Records: The CRM Security Crisis Saudi Banks Must Act On Now
ShinyHunters claims 3 million Cisco Salesforce records stolen — FBI, NASA, and government agency data included. Saudi financial institutions using Cisco products face cascading vendor risk right now.
From reading to doing
How secure is your cloud environment?
A cloud security assessment reviews your account configuration, access rights and exposed data, and sets out what to fix first.
Cloud Security Assessment
Comprehensive security configuration review for AWS, Azure, and GCP cloud environments to ensure your data protection
Security Architecture Review
An in-depth review of your network and systems architecture to ensure security is built into the design, not bolted on later.
Cloud Infrastructure & IaC
We design secure, reproducible cloud infrastructure using infrastructure-as-code.