Author
Abdulaziz Alzamil
Founder & CEO, Fyntralink
Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.
400 articles
CVE-2026-41940: cPanel Zero-Day Exploited for Months Puts 1.5 Million Servers at Risk
A CVSS 9.8 authentication bypass in cPanel & WHM was exploited as a zero-day for two months before patching. With 1.5M servers exposed, Saudi financial institutions must act now.
VulnerabilitiesMiniPlasma Zero-Day: A Six-Year-Old Windows Flaw Returns to Grant SYSTEM Access on Fully Patched Machines
A weaponized PoC exploit dubbed MiniPlasma grants SYSTEM privileges on fully patched Windows 11 by abusing a Cloud Filter driver flaw Microsoft supposedly fixed in 2020. No patch exists today.
VulnerabilitiesSEPPmail Gateway Flaws CVE-2026-2743: When Your Email Security Becomes the Attack Vector
Seven critical SEPPMail flaws — including CVSS 10.0 RCE — turn secure email gateways into wiretaps. Here's what Saudi financial institutions must do now.
VulnerabilitiesCVE-2026-21858: Critical n8n RCE Flaw Gives Attackers Full Control of Your Automation Pipelines
A perfect CVSS 10.0 unauthenticated RCE in n8n lets attackers hijack automation pipelines and every system they connect to. Here's what Saudi institutions must do now.
VulnerabilitiesYellowKey BitLocker Bypass CVE-2026-45585: A USB Drive Is All It Takes to Unlock Your Encrypted Data
A researcher's frustration with Microsoft's bug bounty process led to the public release of YellowKey — a BitLocker bypass that decrypts protected volumes with nothing more than a USB stick and a reboot. Here's what Saudi financial institutions need to do right now.
VulnerabilitiesCVE-2026-23918: Apache HTTP/2 Double-Free Flaw Crashes Servers and Opens the Door to RCE
Critical Apache HTTP/2 double-free vulnerability CVE-2026-23918 is actively exploited for DoS with RCE potential. Saudi financial institutions must patch to 2.4.67 immediately to meet SAMA CSCC and NCA ECC requirements.
Cloud & IdentityEvilTokens PhaaS: Device Code Phishing Bypasses MFA to Hijack Microsoft 365 Accounts
EvilTokens PhaaS platform has compromised 340+ Microsoft 365 orgs by abusing OAuth device code flow to bypass MFA. Learn how Saudi financial institutions can defend against this active threat.
VulnerabilitiesCVE-2026-31431 Copy Fail: 732 Bytes to Root on Every Linux Server Since 2017
A 732-byte Python script can root nearly every Linux distribution shipped since 2017. CVE-2026-31431 exploits a logic flaw in the kernel's crypto API — and it escapes containers too.
VulnerabilitiesDrupal SA-CORE-2026-004: No-Auth SQL Injection Threatens Every PostgreSQL-Backed Site
Drupal released emergency patches for a highly critical SQL injection that requires zero authentication. If your organization runs Drupal on PostgreSQL, you have hours — not days — before weaponized exploits hit the wild.
VulnerabilitiesCVE-2026-42897: Exchange Server Zero-Day Turns Your Inbox Into an Attack Surface
Microsoft confirms active exploitation of CVE-2026-42897, a zero-day XSS flaw in Exchange Server OWA. No patch available yet — here's what Saudi financial institutions must do now.
VulnerabilitiesCVE-2026-41096: Windows DNS Client RCE Lets Attackers Hijack Every Endpoint Without a Click
Microsoft's May 2026 Patch Tuesday disclosed CVE-2026-41096, a CVSS 9.8 heap overflow in the Windows DNS Client enabling unauthenticated RCE on every Windows endpoint. Here's what Saudi financial institutions must do now.
VulnerabilitiesCVE-2026-0073: Android Zero-Click RCE Lets Attackers Hijack Devices Over Wi-Fi
A CVSS 9.8 zero-click flaw in Android's wireless ADB lets nearby attackers gain full shell access — no tap required. Saudi financial institutions running BYOD and mobile banking must patch immediately.