Topic
Compliance & Regulation
Saudi regulatory frameworks — NCA controls, the SAMA framework and the Personal Data Protection Law.
80 articles in this topic
CVE-2026-20700: Apple dyld Zero-Day Hits Saudi Bank Mobile Fleets
Apple's first actively exploited zero-day of 2026 — CVE-2026-20700 in dyld — was abused in a surveillance-grade chain against specific targets. Here is what Saudi banks under SAMA CSCC must do now.
RansomwareQilin Ransomware Tops Q1 2026: Threat Profile for Saudi Banks
Qilin became Q1 2026's most active ransomware group with 342 victims worldwide and a sharpened focus on financial services. Here is what Saudi CISOs operating under SAMA CSCC need to act on this quarter.
VulnerabilitiesCVE-2026-41940: cPanel Zero-Day Threatens Saudi Bank Hosting
A critical cPanel authentication bypass (CVE-2026-41940, CVSS 9.8) was exploited as a zero-day for two months before patch. Saudi banks must act on SAMA CSCC patch governance and third-party hosting risk obligations.
VulnerabilitiesCVE-2026-3854: GitHub RCE via Git Push Threatens Saudi Bank CI/CD
A critical 8.7 CVSS GitHub vulnerability lets any authenticated user execute code through a single git push command. Saudi banks running GHES face full source-code and secrets exposure under SAMA CSCC.
RansomwareEverest Ransomware Hits Frost & Citizens Banks: A Saudi TPRM Wake-Up Call
Everest ransomware listed Frost Bank and Citizens Financial Group on its leak site after compromising a shared third-party vendor. For SAMA-regulated banks, this is a textbook stress test of CSCC Domain 4 controls.
VulnerabilitiesCVE-2025-2749: Kentico Xperience RCE Threatens Saudi Bank Web Properties
CISA just added CVE-2025-2749, an authenticated RCE in Kentico Xperience's Staging Sync Server, to the KEV catalog with a May 4, 2026 federal deadline. Here's why Saudi banks running public CMS portals must act now under SAMA CSCC.
VulnerabilitiesCVE-2026-33825: Microsoft Defender Privilege Escalation Hits Saudi Bank Endpoints
Microsoft Defender's CVE-2026-33825 (CVSS 7.8) is being actively exploited as a zero-day for local privilege escalation. Here's what Saudi banks running Defender for Endpoint must do under SAMA CSCC.
Compliance & RegulationSimpleHelp RMM Hits CISA KEV: A Wake-Up Call for Saudi Bank Vendor Risk
On April 24, 2026, CISA added the SimpleHelp RMM authorization chain to its KEV catalog after confirmed ransomware exploitation. For Saudi banks relying on MSPs and remote support vendors, this is a direct SAMA CSCC TPRM trigger.
VulnerabilitiesCVE-2026-34621: Adobe Reader Zero-Day Hits Saudi Bank PDF Workflows
Adobe rushed an emergency fix for CVE-2026-34621, an Acrobat Reader prototype pollution flaw exploited via weaponized PDFs since late 2025. For Saudi banks where PDF is the universal currency of statements, KYC, and regulatory filings, the patch window has already closed under SAMA CSCC and CISA KEV mandates.
VulnerabilitiesCVE-2026-32201: SharePoint Zero-Day Threatens Saudi Bank Intranets
Microsoft's actively exploited SharePoint zero-day CVE-2026-32201 puts Saudi bank intranets and document portals at risk. Over 1,300 servers remain exposed. Here is what Saudi CISOs must do now under SAMA CSCC.
VulnerabilitiesCVE-2026-27681: SAP BPC SQL Injection Endangers Saudi Bank Regulatory Reporting
A CVSS 9.9 SQL injection flaw in SAP Business Planning and Consolidation lets low-privileged users alter financial data — a direct threat to SAMA reporting integrity at Saudi banks.
VulnerabilitiesCVE-2026-4112: SonicWall SMA1000 SQL Injection Threatens Saudi Bank VPNs
A newly disclosed SonicWall SMA1000 SQL injection flaw (CVE-2026-4112) lets read-only administrators escalate to primary admin and seize bank VPN gateways. Saudi financial institutions must act under SAMA CSCC.
From reading to doing
How ready are you for ECC-2:2024?
Assess your organisation against the NCA Essential Cybersecurity Controls in minutes. It is free and asks for no personal data.
NCA ECC Compliance
Assessment and preparation for compliance with the Essential Cybersecurity Controls (ECC) issued by the National Cybersecurity Aut...
SAMA CSF Compliance
Assessment and preparation for compliance with the Cybersecurity Framework (CSF) issued by the Saudi Central Bank (SAMA)
ISO 27001 Compliance & Certification
Prepare your organization to achieve ISO 27001 certification — the international standard for Information Security Management Syst...