Topic
Cloud & Identity
Cloud misconfiguration risk and the identity and single sign-on systems attackers target.
83 articles in this topic
CVE-2026-3055: Citrix NetScaler's SAML IDP Flaw Is Being Actively Probed — What Saudi Banks Must Act On Now
A CVSS 9.3 memory overread in Citrix NetScaler is being actively probed by threat actors. Saudi banks using NetScaler as a SAML Identity Provider face credential exposure without any authentication required. Patch or isolate today.
Cloud & IdentityShinyHunters' 2026 Vishing Campaign: How Attackers Are Hijacking Okta SSO to Breach Bank-Grade SaaS Platforms
ShinyHunters used real-time voice phishing to steal Okta SSO credentials and MFA codes, then pivoted into Zendesk, Salesforce, and other SaaS platforms to steal millions of support tickets. Saudi banks running the same SaaS stack are directly exposed.
VulnerabilitiesCVE-2026-23813: Critical HPE Aruba AOS-CX Flaw Grants Unauthenticated Admin Access — What Saudi Banks Must Do Now
A CVSS 9.8 authentication bypass in HPE Aruba AOS-CX switches lets any remote attacker reset admin credentials — no authentication required. Saudi banks running this hardware in branch or data-center networks need to act before this changes exploitation status.
Breaches & Data LeaksShinyHunters Salesforce Campaign Hits 400+ Firms: What Saudi Banks Must Do Now
ShinyHunters has breached over 400 organizations through Salesforce Experience Cloud misconfigurations, stealing millions of records. Saudi financial institutions relying on Salesforce must act immediately to lock down guest user permissions and protect customer data.
Cloud & IdentityReact2Shell Exploits Breach 766 Hosts: Massive Credential Theft Campaign Targets Web Apps
A large-scale credential harvesting operation tracked as UAT-10608 is exploiting the React2Shell vulnerability to breach Next.js applications and steal AWS secrets, SSH keys, and database credentials at scale.
VulnerabilitiesOracle Identity Manager CVE-2026-21992: Pre-Auth RCE Threatens Saudi Financial IAM Systems
Oracle issued an emergency out-of-band patch for CVE-2026-21992, a CVSS 9.8 pre-authentication RCE flaw in Identity Manager. Saudi banks running Oracle Fusion Middleware face immediate risk.
Cloud & IdentityLesson 28: Cloud Security — Securing AWS, Azure, and GCP Environments
Hands-On Cybersecurity Path — Lesson 8 of 10. Master cloud security fundamentals across the three major providers and align your cloud posture with SAMA and NCA requirements.
VulnerabilitiesCVE-2026-21643: FortiClient EMS SQL Injection Under Active Attack — Patch Before Attackers Steal Your Endpoint Inventory
A pre-auth SQL injection in FortiClient EMS 7.4.4 lets attackers dump admin credentials and endpoint policies with a single HTTP request. Exploitation began March 26 — here's what Saudi CISOs must do now.
Network & InfrastructureCitrix NetScaler CVE-2026-3055: CISA KEV-Listed Memory Leak Hitting Financial Gateways
CISA added CVE-2026-3055 to its Known Exploited Vulnerabilities catalog on March 30. Attackers are already harvesting credentials from unpatched NetScaler gateways — here's what Saudi financial CISOs must do before the April 2 deadline.
VulnerabilitiesOracle Identity Manager CVE-2026-21992: Emergency RCE Patch Every Saudi Bank Must Apply Now
Oracle issues rare emergency patch for CVE-2026-21992 — a CVSS 9.8 pre-auth RCE flaw in Identity Manager. Saudi financial institutions using Oracle IAM must act immediately.
Malware & Threat ActorsDeepLoad Malware: AI-Powered Credential Theft Targeting Financial Enterprises
A newly discovered malware loader called DeepLoad combines ClickFix social engineering with AI-assisted code obfuscation to steal browser credentials from enterprise networks — and it can reinfect clean hosts silently using WMI persistence.
From reading to doing
How secure is your cloud environment?
A cloud security assessment reviews your account configuration, access rights and exposed data, and sets out what to fix first.
Cloud Security Assessment
Comprehensive security configuration review for AWS, Azure, and GCP cloud environments to ensure your data protection
Security Architecture Review
An in-depth review of your network and systems architecture to ensure security is built into the design, not bolted on later.
Cloud Infrastructure & IaC
We design secure, reproducible cloud infrastructure using infrastructure-as-code.