Topic
Network & Infrastructure
Firewalls, VPNs, intrusion detection and zero trust — the network edge where most intrusions begin.
59 articles in this topic
SonicWall SonicOS Trio (CVE-2026-0204/0205/0206) Threatens Saudi Bank Perimeters
Three newly disclosed SonicOS vulnerabilities — including a CVSS 8.0 access-control bypass — put SonicWall Gen6/7/8 firewalls at risk across Saudi banking perimeters. Here is the SAMA CSCC remediation playbook.
Compliance & RegulationCisco SD-WAN Manager Bugs in CISA KEV Threaten Saudi Banks
CISA flagged three Cisco Catalyst SD-WAN Manager vulnerabilities — CVE-2026-20122, CVE-2026-20128, and CVE-2026-20133 — as actively exploited. Saudi banks running branch SD-WAN must patch immediately to preserve SAMA CSCC and NCA ECC compliance.
VulnerabilitiesCVE-2026-33824: Windows IKE Zero-Click RCE Threatens Saudi Bank VPNs
Microsoft's April 2026 Patch Tuesday disclosed CVE-2026-33824, a critical double-free in Windows IKE Service Extensions (CVSS 9.8) that enables zero-click remote code execution on IPSec endpoints — the exact technology Saudi banks rely on for branch and partner connectivity.
VulnerabilitiesCVE-2026-20133: Cisco SD-WAN Manager Leak Hits Saudi Bank Branches
CISA added Cisco Catalyst SD-WAN Manager flaw CVE-2026-20133 to KEV. Active exploitation exposes file-system data on the controller binding Saudi bank branches. Patch and assess now.
VulnerabilitiesCVE-2026-4112: SonicWall SMA1000 SQL Injection Threatens Saudi Bank VPNs
A newly disclosed SonicWall SMA1000 SQL injection flaw (CVE-2026-4112) lets read-only administrators escalate to primary admin and seize bank VPN gateways. Saudi financial institutions must act under SAMA CSCC.
VulnerabilitiesCVE-2026-20147: Cisco ISE RCE Chain Hits Saudi Bank NAC Backbone
Three critical Cisco ISE vulnerabilities allow authenticated attackers to escalate to root on the very appliance that authorizes every device on a Saudi bank's network — a direct hit on SAMA CSCC segmentation and NCA ECC identity controls.
VulnerabilitiesCVE-2026-33824: Windows IKE Zero-Day Threatens Saudi Bank VPNs
An unauthenticated attacker can take over Windows IKE/IPsec VPN servers via UDP 500/4500 — CVSS 9.8. Saudi banks running Windows IKEv2 must patch immediately.
VulnerabilitiesCVE-2026-1281 & CVE-2026-1340: The Ivanti EPMM Zero-Days Putting Saudi Bank MDM Fleets at Risk
A single bulletproof-hosted IP is driving 83% of active Ivanti EPMM exploitation via CVE-2026-1281 and CVE-2026-1340. Saudi banks running on-prem MDM face direct SAMA CSCC exposure — here is what to patch, hunt, and rotate now.
VulnerabilitiesCVE-2026-21643: The Fortinet FortiClient EMS Zero-Auth SQL Injection CISA Is Flagging — Action Required for Saudi Financial Institutions
CISA confirmed active exploitation of CVE-2026-21643 on April 13, 2026 — a pre-authentication SQL injection in Fortinet FortiClient EMS with a CVSS score of 9.1. Saudi financial institutions running affected versions must patch immediately or face direct risk of unauthorized remote code execution with no credentials required.
RansomwareThe Gentlemen: The RaaS Group That Built a Database of 14,700 FortiGate Devices — and Why Saudi Financial Institutions Are in the Crosshairs
The Gentlemen ransomware group has grown 420% in a single quarter and maintains a database of 14,700 pre-exploited FortiGate devices. Saudi financial institutions running FortiOS must act now — here is what you need to know.
Network & Infrastructure88% of Firewall Brute-Force Attacks Now Originate from the Middle East — Saudi Financial Perimeter Security Under Siege
Barracuda's SOC data reveals that 88% of surging brute-force attacks against SonicWall and FortiGate perimeter devices in Q1 2026 originate from the Middle East — a direct and escalating threat for Saudi financial institutions.
VulnerabilitiesCVE-2026-35616: Fortinet FortiClient EMS Zero-Day Under Active Exploitation — A Direct Risk for Saudi Financial Endpoint Security
A critical pre-authentication bypass in Fortinet FortiClient EMS (CVE-2026-35616, CVSS 9.1) is being actively exploited in the wild. Saudi financial institutions relying on Fortinet for endpoint management must act now — CISA already mandated a patch deadline that has passed.
From reading to doing
Could your systems be exposed to a similar flaw?
A vulnerability assessment finds the weaknesses in your systems before attackers do, and ranks the fixes by risk.
Vulnerability Assessment
Systematic comprehensive scanning of your infrastructure vulnerabilities with a prioritized remediation report for immediate actio...
Internal Penetration Testing
Realistic internal attack simulation to measure your internal network resilience against insider threats
Web Application Penetration Testing
Deep security assessment of web applications following OWASP Top 10 to protect your data and customers