Topic
Compliance & Regulation
Saudi regulatory frameworks — NCA controls, the SAMA framework and the Personal Data Protection Law.
80 articles in this topic
DAEMON Tools Supply Chain Backdoor: SAMA Bank Endpoint Risk
Kaspersky uncovered a trojanized DAEMON Tools installer distributing a Chinese-linked backdoor through the vendor's official domain since April 8, 2026 — a direct test of SAMA CSCC software supply chain controls.
VulnerabilitiesCopy Fail CVE-2026-31431: Linux Root Threat to SAMA Banks
A 732-byte exploit grants root on every major Linux distribution since 2017. Saudi banks running RHEL, Ubuntu, or Amazon Linux face urgent SAMA CSCC patching obligations.
Cloud & IdentityOracle Identity Manager CVE-2026-21992: Critical IAM Threat to SAMA Banks
A pre-authentication RCE in Oracle Identity Manager (CVSS 9.8) gives attackers direct control of the IAM core that Saudi banks rely on for SAMA CSCC compliance. Here is how to detect, patch, and respond.
VulnerabilitiesAndroid Zero-Click CVE-2026-0073: Mobile Banking Threat to SAMA Banks
A critical zero-click flaw in Android's wireless ADB daemon (CVE-2026-0073) allows attackers in Wi-Fi proximity to obtain a remote shell without any user interaction — a direct threat to Saudi mobile banking and BYOD fleets under SAMA CSCC.
Breaches & Data LeaksItron Utility Breach: Critical Infrastructure Lessons for SAMA Banks
Utility tech giant Itron disclosed an intrusion into internal systems. For Saudi banks under SAMA CSCC, this is a sharp reminder: third-party assurance is non-negotiable.
VulnerabilitiesApache HTTP/2 CVE-2026-23918 RCE: SAMA Bank Web Tier Risk
Apache shipped 2.4.67 on May 4, 2026 to fix CVE-2026-23918, an HTTP/2 double-free enabling RCE on millions of servers. Saudi banks face direct exposure on internet-facing web tiers under SAMA CSCC.
Cloud & IdentityCVE-2026-42354: Sentry SAML SSO Bypass Threatens SAMA Bank IAM
A critical Sentry SAML SSO bypass (CVE-2026-42354) enables full account takeover with only the victim's email address. Saudi financial institutions relying on federated identity must act now to align with SAMA CSCC IAM controls.
VulnerabilitiesCVE-2026-42779: Apache MINA Deserialization RCE Hits SAMA Banks
A critical Apache MINA deserialization flaw (CVE-2026-42779, CVSS 9.8) bypasses classname allowlists and enables unauthenticated RCE in financial messaging systems. SAMA CSCC patch guidance inside.
Breaches & Data LeaksMarquis Breach Hits 80 Banks: SAMA Vendor Risk Lessons for Saudi CISOs
The Marquis Software ransomware breach exposed 824,000 customers across 80 US banks via a single SonicWall CVE. Here is the SAMA CSCC 3.4 vendor-risk playbook every Saudi CISO must apply now.
VulnerabilitiesBlueHammer CVE-2026-33825: Defender Zero-Day Hits SAMA Banks
A leaked Microsoft Defender exploit known as BlueHammer (CVE-2026-33825) escalates any unprivileged user to SYSTEM on fully patched Windows. What SAMA-regulated banks must do now to stay aligned with CSCC endpoint controls.
VulnerabilitiesCVE-2026-3854: GitHub RCE Threatens SAMA Bank Source Code
A single crafted git push gave attackers cross-tenant RCE on GitHub, exposing millions of private repositories. With 88% of self-hosted GHES still vulnerable, SAMA-regulated banks face a direct threat to their source code crown jewels and CSCC compliance posture.
VulnerabilitiesCVE-2026-32201: SharePoint Zero-Day Hits SAMA Bank Collaboration
Microsoft confirms active exploitation of SharePoint zero-day CVE-2026-32201. Over 1,300 servers remain exposed online. Here is what SAMA-regulated banks must do this week to stay aligned with CSCC controls.
From reading to doing
How ready are you for ECC-2:2024?
Assess your organisation against the NCA Essential Cybersecurity Controls in minutes. It is free and asks for no personal data.
NCA ECC Compliance
Assessment and preparation for compliance with the Essential Cybersecurity Controls (ECC) issued by the National Cybersecurity Aut...
SAMA CSF Compliance
Assessment and preparation for compliance with the Cybersecurity Framework (CSF) issued by the Saudi Central Bank (SAMA)
ISO 27001 Compliance & Certification
Prepare your organization to achieve ISO 27001 certification — the international standard for Information Security Management Syst...