Topic
Supply Chain & Third Party
Attacks that arrive through vendors, software packages and the third-party platforms you trust.
40 articles in this topic
Booking.com's ClickFix Supply Chain Breach: The Third-Party Vendor Risk Every Saudi Financial CISO Must Address Now
Booking.com confirmed a breach exposing millions of customers' reservation data — attackers never touched Booking.com directly. They compromised hotel partners using ClickFix malware. Saudi financial institutions face identical third-party exposure under SAMA CSCC.
Compliance & RegulationBooking.com Breach Forces Global PIN Resets — Third-Party Platform Risk Is Now a SAMA Compliance Issue for Saudi Financial Institutions
Booking.com confirmed hackers accessed customer reservation data on April 13, 2026. Saudi financial CISOs must review third-party risk registers, PDPL obligations, and phishing defences immediately.
VulnerabilitiesEngageLab SDK Intent Redirection Flaw Exposed 50 Million Android Users — A Third-Party SDK Risk Alarm for Saudi Financial Mobile Apps
Microsoft uncovered an intent redirection vulnerability in EngageLab SDK that silently put 50 million Android users — including 30 million cryptocurrency wallet installs — at risk of private key theft. Saudi financial institutions relying on third-party mobile SDKs need to act now.
Breaches & Data LeaksShinyHunters Breach Rockstar via Anodot: Saudi CISO Third-Party Alert
ShinyHunters extracted 78M records from Rockstar via Anodot, a third-party analytics vendor. SAMA CSCC mandates strict third-party risk controls — is your institution compliant?
Supply Chain & Third PartyAxios npm Supply Chain Attack by UNC1069: Saudi Financial DevOps Alert
UNC1069 compromised Axios npm with the WAVESHAPER.V2 backdoor, exposing over 100M weekly downloads. Saudi financial institutions must audit dependency trees and CI/CD pipelines immediately.
Supply Chain & Third PartyFake Ledger Live on Apple's App Store Stole $9.5M in 7 Days — App Supply Chain Risk Is Now a Board-Level Issue for Saudi Financial Institutions
A fraudulent Ledger Live app slipped through Apple's review process and stole $9.5 million from 50+ victims in a single week. Here's what this means for your institution's third-party and app supply chain risk posture.
Malware & Threat ActorsCPUID Supply Chain Attack: How STX RAT Hijacked CPU-Z and HWMonitor — A Warning for Saudi Financial IT Teams
On April 9–10, 2026, attackers hijacked CPUID's official download servers to distribute STX RAT via trojanized CPU-Z and HWMonitor installers. Here's what Saudi financial institutions need to know.
Malware & Threat ActorsCPUID Supply Chain Breach: How STX RAT Hijacked CPU-Z & HWMonitor — A Wake-Up Call for Saudi Data Centers
On April 9, 2026, attackers quietly replaced CPUID's legitimate CPU-Z and HWMonitor downloads with trojanized packages delivering STX RAT — a full-featured remote access trojan. If your data center team downloaded hardware monitoring tools that week, read this now.
Software EngineeringTrivy Supply Chain Attack Breaches European Commission — Why Saudi Banks Must Audit Their DevSecOps Tools
A compromised build of Trivy — one of the most trusted open-source vulnerability scanners — gave TeamPCP a backdoor into the European Commission's AWS infrastructure. If your DevSecOps pipeline trusts open-source tools implicitly, your institution could be next.
Artificial IntelligenceLiteLLM Supply Chain Attack: How TeamPCP and Lapsus$ Breached 500,000 Machines Through an AI Library Saudi Banks May Be Running
A 40-minute window was all it took. TeamPCP poisoned LiteLLM's PyPI packages and set off a cascade that compromised 500,000 machines, 1,000+ SaaS environments, and handed Lapsus$ 4TB of data from AI startup Mercor.
Software EngineeringTeamPCP's Trivy Supply Chain Attack Exposed 30 EU Entities — Is Your CI/CD Pipeline the Next Target?
A single compromised open-source tool gave attackers access to AWS secrets across 1,000+ SaaS environments. Saudi financial institutions running similar CI/CD pipelines face the same exposure.
Supply Chain & Third PartyAxios NPM Supply Chain Attack: North Korean Hackers Weaponize JavaScript's Most Popular HTTP Client
North Korean threat actors hijacked the Axios npm package — 100 million weekly downloads — to deploy a cross-platform RAT. Here's what Saudi financial institutions need to know and do right now.
From reading to doing
Your suppliers’ risk is your risk
A third-party audit assesses the vendors and service providers with access to your systems and data.
3rd Party Audit / Third Party Risk Assessment
Assessment and audit of vendor and third-party risk to protect your organization from breaches that arrive through the supply chai...
Security Risk Assessment
Comprehensive cybersecurity risk assessment and professional risk register aligned with your strategic decisions
Cybersecurity Consulting
Strategic security consulting from experts who understand the Saudi financial sector and its regulatory requirements