Topic
Vulnerabilities
Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.
228 articles in this topic
CVE-2026-21643: FortiClient EMS SQL Injection Under Active Attack — Patch Before Attackers Steal Your Endpoint Inventory
A pre-auth SQL injection in FortiClient EMS 7.4.4 lets attackers dump admin credentials and endpoint policies with a single HTTP request. Exploitation began March 26 — here's what Saudi CISOs must do now.
Network & InfrastructureCitrix NetScaler CVE-2026-3055: CISA KEV-Listed Memory Leak Hitting Financial Gateways
CISA added CVE-2026-3055 to its Known Exploited Vulnerabilities catalog on March 30. Attackers are already harvesting credentials from unpatched NetScaler gateways — here's what Saudi financial CISOs must do before the April 2 deadline.
Malware & Threat ActorsOperation TrueChaos: How a Video Conferencing Zero-Day Turned Trusted Updates into Malware
A zero-day in TrueConf's update mechanism let attackers push malware to every connected endpoint. Here's what Operation TrueChaos means for SAMA-regulated institutions and how to harden your internal software supply chain.
VulnerabilitiesOracle Identity Manager CVE-2026-21992: Emergency RCE Patch Every Saudi Bank Must Apply Now
Oracle issues rare emergency patch for CVE-2026-21992 — a CVSS 9.8 pre-auth RCE flaw in Identity Manager. Saudi financial institutions using Oracle IAM must act immediately.
VulnerabilitiesCVE-2026-33017: Langflow AI Pipeline RCE Exploited in 20 Hours — What CISOs Must Know
A critical code injection flaw in Langflow was weaponized within 20 hours of disclosure. If your organization runs AI workflow platforms, here's what you need to do immediately.
VulnerabilitiesAPT28 Weaponizes MSHTML Zero-Day CVE-2026-21513: What Saudi Financial CISOs Must Do Now
Russia-linked APT28 exploited a critical MSHTML zero-day for weeks before Microsoft patched it. Saudi financial institutions running Windows infrastructure face direct exposure — here's the technical breakdown and remediation playbook.
VulnerabilitiesInterlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026-20131: Urgent Action for Financial Institutions
Interlock ransomware exploited a CVSS 10.0 Cisco Firewall Management Center zero-day for over a month before disclosure. Here's what Saudi financial institutions must do immediately.
Guides & LessonsLesson 8: Application Security — OWASP Top 10 Vulnerabilities
Path 1: Cybersecurity Fundamentals — Lesson 8 of 10. Master the OWASP Top 10 vulnerabilities and learn how to protect your organization's web applications from the most critical security risks.
VulnerabilitiesCisco SD-WAN Zero-Day CVE-2026-20127: A CVSS 10.0 Threat Hiding Since 2023
A maximum-severity authentication bypass in Cisco Catalyst SD-WAN has been silently exploited by threat actor UAT-8616 since 2023. With CISA mandating emergency remediation, Saudi financial institutions running SD-WAN must act immediately.
VulnerabilitiesCVE-2026-32746: A 32-Year-Old Telnetd Bug Now Threatens Saudi Financial Infrastructure
A 32-year-old buffer overflow in GNU InetUtils telnetd (CVE-2026-32746, CVSS 9.8) is now actively exploited — and it affects network appliances running inside Saudi financial networks. Here's what CISOs need to do today.
VulnerabilitiesLangflow AI Exploited in 20 Hours: Why Saudi Financial Institutions Must Secure AI Pipelines
A critical unauthenticated RCE flaw in Langflow was weaponized within 20 hours of disclosure. Here's what SAMA-regulated institutions adopting AI must do immediately.
Network & InfrastructureCitrix NetScaler Under Active Attack: What Saudi Financial Institutions Must Do Now
Critical Citrix NetScaler vulnerability CVE-2026-3055 is under active exploitation. Response guide for Saudi financial institutions subject to SAMA CSCC compliance.
From reading to doing
Could your systems be exposed to a similar flaw?
A vulnerability assessment finds the weaknesses in your systems before attackers do, and ranks the fixes by risk.
Vulnerability Assessment
Systematic comprehensive scanning of your infrastructure vulnerabilities with a prioritized remediation report for immediate actio...
Internal Penetration Testing
Realistic internal attack simulation to measure your internal network resilience against insider threats
Web Application Penetration Testing
Deep security assessment of web applications following OWASP Top 10 to protect your data and customers