Topic

Compliance & Regulation

Saudi regulatory frameworks — NCA controls, the SAMA framework and the Personal Data Protection Law.

80 articles in this topic

Malware & Threat Actors

DAEMON Tools Supply Chain Backdoor: SAMA Bank Endpoint Risk

Kaspersky uncovered a trojanized DAEMON Tools installer distributing a Chinese-linked backdoor through the vendor's official domain since April 8, 2026 — a direct test of SAMA CSCC software supply chain controls.

7 May 2026 4 min
Vulnerabilities

Copy Fail CVE-2026-31431: Linux Root Threat to SAMA Banks

A 732-byte exploit grants root on every major Linux distribution since 2017. Saudi banks running RHEL, Ubuntu, or Amazon Linux face urgent SAMA CSCC patching obligations.

7 May 2026 4 min
Cloud & Identity

Oracle Identity Manager CVE-2026-21992: Critical IAM Threat to SAMA Banks

A pre-authentication RCE in Oracle Identity Manager (CVSS 9.8) gives attackers direct control of the IAM core that Saudi banks rely on for SAMA CSCC compliance. Here is how to detect, patch, and respond.

7 May 2026 4 min
Vulnerabilities

Android Zero-Click CVE-2026-0073: Mobile Banking Threat to SAMA Banks

A critical zero-click flaw in Android's wireless ADB daemon (CVE-2026-0073) allows attackers in Wi-Fi proximity to obtain a remote shell without any user interaction — a direct threat to Saudi mobile banking and BYOD fleets under SAMA CSCC.

6 May 2026 4 min
Breaches & Data Leaks

Itron Utility Breach: Critical Infrastructure Lessons for SAMA Banks

Utility tech giant Itron disclosed an intrusion into internal systems. For Saudi banks under SAMA CSCC, this is a sharp reminder: third-party assurance is non-negotiable.

6 May 2026 4 min
Vulnerabilities

Apache HTTP/2 CVE-2026-23918 RCE: SAMA Bank Web Tier Risk

Apache shipped 2.4.67 on May 4, 2026 to fix CVE-2026-23918, an HTTP/2 double-free enabling RCE on millions of servers. Saudi banks face direct exposure on internet-facing web tiers under SAMA CSCC.

5 May 2026 4 min
Cloud & Identity

CVE-2026-42354: Sentry SAML SSO Bypass Threatens SAMA Bank IAM

A critical Sentry SAML SSO bypass (CVE-2026-42354) enables full account takeover with only the victim's email address. Saudi financial institutions relying on federated identity must act now to align with SAMA CSCC IAM controls.

5 May 2026 4 min
Vulnerabilities

CVE-2026-42779: Apache MINA Deserialization RCE Hits SAMA Banks

A critical Apache MINA deserialization flaw (CVE-2026-42779, CVSS 9.8) bypasses classname allowlists and enables unauthenticated RCE in financial messaging systems. SAMA CSCC patch guidance inside.

5 May 2026 4 min
Breaches & Data Leaks

Marquis Breach Hits 80 Banks: SAMA Vendor Risk Lessons for Saudi CISOs

The Marquis Software ransomware breach exposed 824,000 customers across 80 US banks via a single SonicWall CVE. Here is the SAMA CSCC 3.4 vendor-risk playbook every Saudi CISO must apply now.

5 May 2026 5 min
Vulnerabilities

BlueHammer CVE-2026-33825: Defender Zero-Day Hits SAMA Banks

A leaked Microsoft Defender exploit known as BlueHammer (CVE-2026-33825) escalates any unprivileged user to SYSTEM on fully patched Windows. What SAMA-regulated banks must do now to stay aligned with CSCC endpoint controls.

5 May 2026 4 min
Vulnerabilities

CVE-2026-3854: GitHub RCE Threatens SAMA Bank Source Code

A single crafted git push gave attackers cross-tenant RCE on GitHub, exposing millions of private repositories. With 88% of self-hosted GHES still vulnerable, SAMA-regulated banks face a direct threat to their source code crown jewels and CSCC compliance posture.

4 May 2026 4 min
Vulnerabilities

CVE-2026-32201: SharePoint Zero-Day Hits SAMA Bank Collaboration

Microsoft confirms active exploitation of SharePoint zero-day CVE-2026-32201. Over 1,300 servers remain exposed online. Here is what SAMA-regulated banks must do this week to stay aligned with CSCC controls.

4 May 2026 4 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality