Author
Abdulaziz Alzamil
Founder & CEO, Fyntralink
Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.
400 articles
Dirty Frag: Linux Kernel Zero-Day Grants Root Access Across Cloud and Banking Infrastructure
Two chained Linux kernel flaws — CVE-2026-43284 and CVE-2026-43500 — let any unprivileged user reach root. Active exploitation confirmed. Here's what SAMA-regulated institutions must do now.
VulnerabilitiescPanel Auth Bypass CVE-2026-41940: 1.5M Servers at Risk, Ransomware in the Wild
A CVSS 9.8 authentication bypass in cPanel & WHM has been weaponized since February 2026. With 1.5 million exposed instances and ransomware already deploying, Saudi financial institutions must audit their hosting infrastructure now.
Breaches & Data LeaksCanvas LMS Mega-Breach: Lessons in Third-Party SaaS Risk for Saudi Institutions
ShinyHunters compromised Instructure's Canvas LMS, exposing data from 8,800+ institutions and 275 million users — the largest educational breach in history. Here's what Saudi organizations must learn about third-party SaaS risk.
Cloud & IdentityMicrosoft Edge Stores Passwords in Plaintext RAM: Enterprise Risk for SAMA Banks
Microsoft confirms Edge loads every saved password into plaintext RAM at launch — by design. For SAMA-regulated banks, this turns every endpoint into a credential extraction target.
Breaches & Data LeaksShinyHunters Vishing-to-Salesforce Attack Chain: What SAMA Banks Must Know
ShinyHunters breached 500K+ Salesforce records via vishing and OAuth hijacking. Saudi financial institutions face the same attack pattern — here's how to defend under SAMA CSCC and NCA ECC.
VulnerabilitiesPAN-OS Zero-Day CVE-2026-0300: Root-Level RCE Threatens SAMA-Regulated Firewalls
A critical buffer overflow in Palo Alto PAN-OS (CVSS 9.3) is being exploited in the wild to achieve root-level code execution on firewalls — with no authentication required. SAMA-regulated institutions running PA-Series or VM-Series must mitigate immediately.
RansomwareRansomware Negotiator Convicted of Aiding BlackCat: Third-Party IR Vendor Risk for SAMA Banks
A ransomware negotiator pleaded guilty to feeding victim secrets to BlackCat operators — exposing a $75M insider threat that SAMA-regulated banks cannot ignore.
Malware & Threat ActorsTCLBANKER Trojan Spreads via WhatsApp to Target 59 Financial Platforms
A new banking trojan called TCLBANKER hijacks WhatsApp and Outlook to spread across 3,000 contacts per victim, targeting 59 financial platforms with full-screen credential overlays.
Artificial IntelligenceIMF Warns AI-Powered Cyberattacks Threaten Financial Stability: SAMA Banks Must Act
The IMF issued a stark warning: AI-fueled cyberattacks now threaten financial stability at a systemic level. Here's what Saudi banks under SAMA oversight must do before agentic AI threats outpace their defenses.
Breaches & Data LeaksVerizon 2026 DBIR: What Saudi Banks Must Learn from 12,195 Breaches
Verizon's 2026 DBIR reveals third-party breaches doubled to 30%, vulnerability exploitation overtook phishing, and ransomware hit 44% of cases. Here's what SAMA-regulated banks must do now.
Malware & Threat ActorsJDownloader Python RAT Supply Chain Attack: SAMA Bank Risk
Attackers compromised the official JDownloader website between May 6 and May 7, 2026, swapping legitimate Windows and Linux installers with a modular Python RAT. Here is what SAMA-regulated banks must do now.
VulnerabilitiesDefender Zero-Days BlueHammer & RedSun: SAMA Bank EDR Risk
Three Microsoft Defender zero-days are being actively exploited. BlueHammer (CVE-2026-33825) is in CISA KEV; RedSun and UnDefend remain unpatched. What SAMA banks must do this week.