Author
Abdulaziz Alzamil
Founder & CEO, Fyntralink
Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.
400 articles
AiTM Phishing Campaign 2026: 35,000-Victim MFA Bypass Threatens SAMA Banks
Microsoft Defender Research uncovered a multi-stage AiTM phishing campaign that hit 35,000 users across 26 countries — financial services was 18% of victims. What SAMA-regulated banks must do today.
VulnerabilitiesCVE-2026-32202: APT28's Zero-Click Windows Shell Threat to SAMA Banks
A zero-click Windows Shell vulnerability (CVE-2026-32202) is being weaponized by Russian APT28 to silently harvest NTLMv2 credentials. Saudi banks face an urgent patching window before May 12.
VulnerabilitiesCopy Fail CVE-2026-31431: Linux Root Threat to SAMA Banks
A 732-byte exploit grants root on every major Linux distribution since 2017. Saudi banks running RHEL, Ubuntu, or Amazon Linux face urgent SAMA CSCC patching obligations.
Cloud & IdentityOracle Identity Manager CVE-2026-21992: Critical IAM Threat to SAMA Banks
A pre-authentication RCE in Oracle Identity Manager (CVSS 9.8) gives attackers direct control of the IAM core that Saudi banks rely on for SAMA CSCC compliance. Here is how to detect, patch, and respond.
VulnerabilitiesFortiClient EMS CVE-2026-35616: Critical RCE Threat to SAMA Banks
Fortinet disclosed a critical pre-authentication RCE flaw in FortiClient EMS (CVSS 9.1). For SAMA-regulated Saudi banks running Fortinet endpoint management, immediate patching is non-negotiable.
VulnerabilitiesAndroid Zero-Click CVE-2026-0073: Mobile Banking Threat to SAMA Banks
A critical zero-click flaw in Android's wireless ADB daemon (CVE-2026-0073) allows attackers in Wi-Fi proximity to obtain a remote shell without any user interaction — a direct threat to Saudi mobile banking and BYOD fleets under SAMA CSCC.
Malware & Threat ActorsMuddyWater's Teams Attack: Iranian APT Threat to SAMA Banks
Iranian state-sponsored MuddyWater is exploiting Microsoft Teams screen-share to harvest credentials and bypass MFA, while masking espionage as Chaos ransomware. Implications for SAMA-regulated banks.
VulnerabilitiesLangflow CVE-2026-33017 RCE: AI Pipeline Threat to SAMA Banks
An unauthenticated RCE in Langflow's public flow endpoint puts AI orchestration pipelines at Saudi financial institutions in the crosshairs. Here is what SAMA-regulated banks must do this week.
Breaches & Data LeaksItron Utility Breach: Critical Infrastructure Lessons for SAMA Banks
Utility tech giant Itron disclosed an intrusion into internal systems. For Saudi banks under SAMA CSCC, this is a sharp reminder: third-party assurance is non-negotiable.
Breaches & Data LeaksShinyHunters' 9M-Record Medtronic Hack: SAMA Bank Lessons
ShinyHunters claimed 9 million records stolen from Medtronic, then quietly delisted the victim. Saudi banks face the same pure-extortion playbook — here is how to prepare.
VulnerabilitiesMOVEit Automation CVE-2026-4670: Critical Auth Bypass Threatens SAMA Banks
Progress disclosed CVE-2026-4670 — a CVSS 9.8 authentication bypass in MOVEit Automation. Here is what SAMA-regulated banks must do this week to protect interbank file transfers and meet third-party risk obligations.
VulnerabilitiesArgo CD CVE-2026-43824: Read-Only RBAC Bypass Threatens SAMA Banks
A new Argo CD flaw (CVE-2026-43824) lets read-only users extract plaintext Kubernetes secrets via the ServerSideDiff API. Saudi banks running GitOps must patch and audit RBAC immediately.