Topic
Network & Infrastructure
Firewalls, VPNs, intrusion detection and zero trust — the network edge where most intrusions begin.
59 articles in this topic
CVE-2026-41096: Windows DNS Client RCE Lets Attackers Hijack Every Endpoint Without a Click
Microsoft's May 2026 Patch Tuesday disclosed CVE-2026-41096, a CVSS 9.8 heap overflow in the Windows DNS Client enabling unauthenticated RCE on every Windows endpoint. Here's what Saudi financial institutions must do now.
VulnerabilitiesCVE-2026-20182: Cisco SD-WAN CVSS 10.0 Auth Bypass Actively Exploited — Sixth Zero-Day This Year
Cisco's sixth SD-WAN zero-day in 2026 carries a perfect CVSS 10.0 score and is already being exploited by an advanced threat actor. Saudi financial institutions running SD-WAN fabrics face immediate risk.
VulnerabilitiesCVE-2026-20182: Cisco SD-WAN CVSS 10.0 Auth Bypass Under Active Exploitation
A perfect-score CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN is being actively exploited by UAT-8616. If your WAN fabric runs on Cisco, this is not optional reading.
Network & InfrastructureCVE-2026-0300: Critical PAN-OS Buffer Overflow Grants Root Access to Palo Alto Firewalls
A critical buffer overflow in Palo Alto PAN-OS User-ID Authentication Portal is being exploited in the wild, giving attackers root-level code execution on PA-Series and VM-Series firewalls. Here is what Saudi financial CISOs must do now.
Network & InfrastructureCISA BOD 26-02 Deadline Hits: Why Saudi Financial Institutions Must Audit End-of-Life Edge Devices Now
CISA's May 2026 deadline for BOD 26-02 forces a global reckoning on unsupported edge devices. Saudi financial institutions running end-of-life firewalls and VPN appliances face identical threats from nation-state actors — here's what CISOs must do now.
VulnerabilitiesCVE-2026-20182: Cisco SD-WAN Zero-Day Gives Attackers Full Admin Access Without Credentials
A CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN Controller is under active exploitation, letting attackers seize full admin control of enterprise network fabrics without any credentials.
VulnerabilitiesCVE-2026-41096: Critical Windows DNS Client RCE Threatens Every Endpoint
CVE-2026-41096 scores CVSS 9.8—a heap overflow in Windows DNS Client allows unauthenticated RCE on every Windows machine via a single malicious DNS response. Here's what Saudi financial institutions must do now.
Network & InfrastructureCVE-2026-0300: Palo Alto PAN-OS Zero-Day Gives Attackers Root on Your Perimeter Firewall
A critical buffer overflow in Palo Alto PAN-OS User-ID Authentication Portal is being exploited in the wild—giving attackers root-level code execution on PA-Series and VM-Series firewalls without any credentials.
VulnerabilitiesIvanti EPMM Zero-Day CVE-2026-6973: RCE Hits Enterprise Mobile Management
Ivanti's Endpoint Manager Mobile zero-day CVE-2026-6973 is under active exploitation. Attackers chain stolen credentials with an input validation flaw to achieve full RCE on EPMM appliances managing thousands of corporate devices.
VulnerabilitiesPAN-OS Zero-Day CVE-2026-0300: Root-Level RCE Threatens SAMA-Regulated Firewalls
A critical buffer overflow in Palo Alto PAN-OS (CVSS 9.3) is being exploited in the wild to achieve root-level code execution on firewalls — with no authentication required. SAMA-regulated institutions running PA-Series or VM-Series must mitigate immediately.
VulnerabilitiesIvanti EPMM CVE-2026-6973 RCE Exploited: SAMA Bank MDM Risk
CISA added Ivanti EPMM CVE-2026-6973 to the KEV catalog after confirmed in-the-wild exploitation. Saudi banks running on-prem MDM face severe risk to mobile device fleets and corporate data.
VulnerabilitiesD-Link CVE-2026-0625 Zero-Day: DNS Hijack Risk for SAMA Banks
An unauthenticated RCE in end-of-life D-Link DSL routers (CVE-2026-0625, CVSS 9.3) enables silent DNS redirection. SAMA-regulated banks now face customer-side credential theft and BEC fraud at scale.
From reading to doing
Could your systems be exposed to a similar flaw?
A vulnerability assessment finds the weaknesses in your systems before attackers do, and ranks the fixes by risk.
Vulnerability Assessment
Systematic comprehensive scanning of your infrastructure vulnerabilities with a prioritized remediation report for immediate actio...
Internal Penetration Testing
Realistic internal attack simulation to measure your internal network resilience against insider threats
Web Application Penetration Testing
Deep security assessment of web applications following OWASP Top 10 to protect your data and customers