Topic
Supply Chain & Third Party
Attacks that arrive through vendors, software packages and the third-party platforms you trust.
40 articles in this topic
Lesson 36: Third-Party Risk Management — Securing Your Vendor Ecosystem
Security Leadership Path — Lesson 6 of 10. Build a robust Third-Party Risk Management program that satisfies SAMA CSCC and NCA ECC requirements while protecting your organization from vendor-introduced threats.
Supply Chain & Third PartyTrivy Supply Chain Attack CVE-2026-33634: When Your Security Scanner Becomes the Threat
Attackers compromised Aqua Security's Trivy scanner to harvest CI/CD secrets from thousands of pipelines. Here's what happened, who's behind it, and why Saudi financial institutions running Trivy must act immediately.
Supply Chain & Third PartyAxios npm Supply Chain Attack: RAT Deployed via 100M-Download Package
Attackers hijacked Axios — the most popular npm HTTP client with 100M+ weekly downloads — to deploy a self-destructing RAT. Here's what Saudi financial institutions must do immediately.
Supply Chain & Third PartySoftware Supply Chain Attacks Surge: GlassWorm and LiteLLM Compromises Sound the Alarm
Two massive supply chain attacks in March 2026 — GlassWorm (9M+ installs via malicious IDE extensions) and LiteLLM (backdoored Python library with 3M daily downloads) — expose critical gaps in software development security for Saudi financial institutions.
From reading to doing
Your suppliers’ risk is your risk
A third-party audit assesses the vendors and service providers with access to your systems and data.
3rd Party Audit / Third Party Risk Assessment
Assessment and audit of vendor and third-party risk to protect your organization from breaches that arrive through the supply chai...
Security Risk Assessment
Comprehensive cybersecurity risk assessment and professional risk register aligned with your strategic decisions
Cybersecurity Consulting
Strategic security consulting from experts who understand the Saudi financial sector and its regulatory requirements