Author
Abdulaziz Alzamil
Founder & CEO, Fyntralink
Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.
400 articles
Marquis Breach Expands to 80 Banks: SonicWall Lessons for SAMA Third-Party Risk
The Marquis ransomware breach has expanded to 80 banks and 824,000 customers — exploited through a SonicWall firewall flaw. Here's what SAMA-regulated banks must do now to harden third-party and perimeter controls.
VulnerabilitiesASP.NET Core CVE-2026-40372: Forged Cookie Threat to SAMA Banks
Microsoft released an out-of-band patch for CVE-2026-40372, a CVSS 9.1 ASP.NET Core flaw that lets attackers forge auth cookies and gain SYSTEM. Direct risk to SAMA bank apps.
Phishing & FraudAccountDumpling: Google AppSheet Phishing Bypasses DMARC — A SAMA Email Risk
Attackers are weaponizing Google AppSheet's noreply@appsheet.com address to send phishing emails that pass SPF, DKIM and DMARC. The AccountDumpling campaign is a wake-up call for every SAMA-regulated bank that treats email authentication as a finished control.
Network & InfrastructureCVE-2026-0227: PAN-OS GlobalProtect DoS Threat to SAMA Banks
An unauthenticated DoS flaw in PAN-OS GlobalProtect can force Saudi bank firewalls into maintenance mode. Here's what SAMA-regulated CISOs must do before exploitation goes mainstream.
RansomwareThe Gentlemen Ransomware Surge: GPO Detonation Threat to SAMA Banks
The Gentlemen RaaS jumped from 35 to 182 victims in one quarter, targeting banks like Warka via SystemBC tunnels and GPO mass-detonation. Defense lessons for SAMA-regulated institutions.
VulnerabilitiesCVE-2026-32202 Zero-Click NTLM Leak: APT28 Threat to SAMA Banks
Microsoft and CISA confirmed active exploitation of CVE-2026-32202, a zero-click Windows Shell flaw leaking NTLM hashes. SAMA banks face urgent endpoint and SMB-egress risk.
VulnerabilitiescPanel CVE-2026-41940 Auth Bypass: SAMA Bank Web Tier and Vendor Risk
CVE-2026-41940 is a CVSS 9.8 cPanel authentication bypass actively weaponised against 1.5M servers worldwide. Here is the SAMA-aligned response Saudi banks need now.
VulnerabilitiesApache HTTP/2 CVE-2026-23918 RCE: SAMA Bank Web Tier Risk
Apache shipped 2.4.67 on May 4, 2026 to fix CVE-2026-23918, an HTTP/2 double-free enabling RCE on millions of servers. Saudi banks face direct exposure on internet-facing web tiers under SAMA CSCC.
Cloud & IdentityVercel-Context AI OAuth Breach: Shadow AI Risk Lessons for SAMA Banks
A single Shadow AI tool installed by one Vercel employee triggered an OAuth supply-chain breach exposing API keys, source code, and customer credentials — a textbook warning for SAMA-regulated banks tightening third-party governance under CSCC and ECC.
Cloud & IdentityCVE-2026-42354: Sentry SAML SSO Bypass Threatens SAMA Bank IAM
A critical Sentry SAML SSO bypass (CVE-2026-42354) enables full account takeover with only the victim's email address. Saudi financial institutions relying on federated identity must act now to align with SAMA CSCC IAM controls.
VulnerabilitiesCVE-2026-42779: Apache MINA Deserialization RCE Hits SAMA Banks
A critical Apache MINA deserialization flaw (CVE-2026-42779, CVSS 9.8) bypasses classname allowlists and enables unauthenticated RCE in financial messaging systems. SAMA CSCC patch guidance inside.
VulnerabilitiesSonicWall CVE-2026-0204 Triad: Firewall Risk for SAMA Banks
SonicWall's April 29, 2026 advisory disclosed three SonicOS flaws — access bypass, path traversal, and a remote crash — directly threatening the perimeter of SAMA-regulated banks. Here is what Saudi CISOs must do this week.