Abdulaziz Alzamil

Author

Abdulaziz Alzamil

Founder & CEO, Fyntralink

Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.

  • Cybersecurity
  • Vulnerabilities & threats
  • NCA Essential Cybersecurity Controls (ECC)
  • Personal Data Protection Law (PDPL)
  • SAMA Cyber Security Framework
  • AI governance
  • Software engineering

400 articles

Supply Chain & Third Party

Mini Shai-Hulud Supply Chain Attack: SAMA Bank DevSecOps Risk

A new worm campaign compromised PyTorch Lightning, intercom-client and 1,800+ developer repos across npm, PyPI and PHP. Here is what SAMA-regulated banks must do now.

10 May 2026 4 min
Vulnerabilities

Ivanti EPMM CVE-2026-6973 RCE Exploited: SAMA Bank MDM Risk

CISA added Ivanti EPMM CVE-2026-6973 to the KEV catalog after confirmed in-the-wild exploitation. Saudi banks running on-prem MDM face severe risk to mobile device fleets and corporate data.

10 May 2026 3 min
Vulnerabilities

SharePoint CVE-2026-32201 Zero-Day RCE: Critical Risk to SAMA Banks

A new SharePoint zero-day vulnerability (CVE-2026-32201) is being actively exploited, exposing more than 1,300 internet-facing servers to unauthenticated remote code execution. SAMA-regulated banks must act now.

10 May 2026 3 min
Ransomware

Everest Ransomware Hits US Banks: Vendor Risk Lessons for SAMA

Everest ransomware claimed breaches at Frost Bank and Citizens Financial Group through a shared third-party vendor, exposing 250K+ customer records. SAMA-regulated banks face the same supply chain exposure — here is what every CISO must do now.

10 May 2026 4 min
Vulnerabilities

Apache HTTP/2 CVE-2026-23918 Double-Free RCE: SAMA Bank Risk

Apache HTTP Server 2.4.66 contains a critical HTTP/2 double-free vulnerability (CVE-2026-23918) enabling unauthenticated RCE — a direct threat to SAMA-regulated banking web infrastructure.

10 May 2026 4 min
Vulnerabilities

D-Link CVE-2026-0625 Zero-Day: DNS Hijack Risk for SAMA Banks

An unauthenticated RCE in end-of-life D-Link DSL routers (CVE-2026-0625, CVSS 9.3) enables silent DNS redirection. SAMA-regulated banks now face customer-side credential theft and BEC fraud at scale.

10 May 2026 4 min
Ransomware

Anubis Ransomware Adds Wiper: Critical Risk to SAMA Banks

Anubis ransomware-as-a-service now includes a destructive wiper alongside double extortion, breaking the traditional ransomware bargain. Saudi banks must adapt SAMA CSCC defenses immediately.

10 May 2026 4 min
Ransomware

NightSpire Ransomware Targets Financial Sector: SAMA Bank Defense Guide

NightSpire is rewriting double-extortion playbooks against the financial sector. Here is what SAMA-regulated banks must do to harden Fortinet edges, blunt CVE-2024-55591, and survive 48-hour ransom deadlines.

9 May 2026 4 min
Vulnerabilities

Weaver E-cology CVE-2026-22679: Unauthenticated RCE Risk to SAMA Banks

A CVSS 9.8 unauthenticated RCE flaw in Weaver E-cology is being actively exploited via an exposed Dubbo debug endpoint. SAMA-regulated banks running this enterprise collaboration platform face direct threats to integrity and availability obligations under CSCC.

9 May 2026 4 min
Vulnerabilities

cPanel CVE-2026-41940 Auth Bypass: Risk to SAMA Banks

A critical CRLF-injection auth bypass in cPanel & WHM (CVSS 9.8) is under mass exploitation, putting Saudi banks' supply chains and PCI-DSS scope at risk.

9 May 2026 4 min
Cloud & Identity

MuddyWater Targets Microsoft Teams MFA: SAMA Bank Defense Guide

Iranian state-sponsored MuddyWater is exploiting Microsoft Teams social engineering to harvest credentials and manipulate MFA at financial institutions, then planting Chaos ransomware as a false flag. Here is what SAMA-regulated banks must do.

9 May 2026 4 min
Guides & Lessons

DigitalMint Insider Threat: $75M Lesson for SAMA Banks

A trusted ransomware negotiator betrayed his clients and funneled $75.25M to BlackCat. Here's what SAMA-regulated banks must change in their incident response vendor due diligence today.

9 May 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality