Topic
Network & Infrastructure
Firewalls, VPNs, intrusion detection and zero trust — the network edge where most intrusions begin.
59 articles in this topic
Akira Ransomware vs SonicWall VPN: Critical Risk to SAMA Banks
Akira ransomware affiliates exploit SonicWall SSL VPN to encrypt SAMA banks in under 4 hours, bypassing MFA. See defense steps and CSCC alignment.
VulnerabilitiesIvanti EPMM Zero-Day CVE-2026-6973: RCE Risk for SAMA Banks
An actively exploited zero-day in Ivanti Endpoint Manager Mobile (CVE-2026-6973) enables admin-level remote code execution on the MDM controller — a direct threat to mobile device estates across SAMA-regulated banks.
VulnerabilitiesPAN-OS CVE-2026-0300: Critical RCE Threat to SAMA Banks
CISA added Palo Alto PAN-OS CVE-2026-0300 to its KEV catalog after limited in-the-wild exploitation. Saudi banks exposing the User-ID Authentication Portal face an unauthenticated root RCE on the perimeter — here is what SAMA CSCC requires you to do now.
VulnerabilitiesCitrixBleed 3 (CVE-2026-3055): Critical Risk for SAMA Banks
A critical Citrix NetScaler memory overread (CVE-2026-3055) is being actively exploited against SAML-enabled appliances. Saudi banks must patch and rotate session tokens before attackers harvest more.
VulnerabilitiesCVE-2026-0300: PAN-OS Captive Portal RCE Threat to SAMA Banks
A critical PAN-OS Captive Portal buffer overflow lets unauthenticated attackers gain root on Palo Alto firewalls. SAMA-regulated banks must patch and isolate User-ID portals immediately.
Network & InfrastructureIran's PLC Campaign: OT/IT Convergence Risks for SAMA Banks
CISA's April 2026 advisory reveals an Iranian APT campaign abusing internet-exposed Rockwell PLCs. SAMA-regulated banks run similar OT systems in data centers and branches—here's how to defend them.
Network & InfrastructureCVE-2026-0227: PAN-OS GlobalProtect DoS Threat to SAMA Banks
An unauthenticated DoS flaw in PAN-OS GlobalProtect can force Saudi bank firewalls into maintenance mode. Here's what SAMA-regulated CISOs must do before exploitation goes mainstream.
VulnerabilitiesSonicWall CVE-2026-0204 Triad: Firewall Risk for SAMA Banks
SonicWall's April 29, 2026 advisory disclosed three SonicOS flaws — access bypass, path traversal, and a remote crash — directly threatening the perimeter of SAMA-regulated banks. Here is what Saudi CISOs must do this week.
VulnerabilitiesFortinet CVE-2026-24858: FortiCloud SSO Bypass Hits SAMA Banks
Fortinet's CVE-2026-24858 lets attackers bypass FortiCloud SSO and seize admin control over FortiOS, FortiManager, and FortiProxy. Why SAMA-regulated banks must act before patches arrive.
VulnerabilitiesCVE-2026-33824: Critical Windows IKE RCE Threatens SAMA Bank VPNs
Microsoft's May 2026 Patch Tuesday disclosed CVE-2026-33824, a CVSS 9.8 unauthenticated RCE in Windows IKE Service Extensions. SAMA-regulated banks running IPSec VPNs must patch immediately.
VulnerabilitiesCisco SD-WAN Manager Exploited Trio (CVE-2026-20122/20128/20133): SAMA Bank Branch Risk
Three actively exploited Cisco Catalyst SD-WAN Manager vulnerabilities (CVE-2026-20122/20128/20133) place Saudi bank branch networks under immediate threat. Here is what SAMA-regulated CISOs must do this week.
RansomwareAkira Ransomware Bypasses MFA on SonicWall VPNs: SAMA Bank Defense Guide
Akira ransomware operators are now bypassing MFA on SonicWall SSL VPNs by exfiltrating OTP seed values from compromised firewalls. SAMA-regulated banks face urgent perimeter risk that demands immediate CSCC-aligned controls.
From reading to doing
Could your systems be exposed to a similar flaw?
A vulnerability assessment finds the weaknesses in your systems before attackers do, and ranks the fixes by risk.
Vulnerability Assessment
Systematic comprehensive scanning of your infrastructure vulnerabilities with a prioritized remediation report for immediate actio...
Internal Penetration Testing
Realistic internal attack simulation to measure your internal network resilience against insider threats
Web Application Penetration Testing
Deep security assessment of web applications following OWASP Top 10 to protect your data and customers