Author
Abdulaziz Alzamil
Founder & CEO, Fyntralink
Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.
400 articles
Vercel-Context AI OAuth Breach: SaaS Supply Chain Lessons for SAMA Banks
A single employee-installed AI plugin gave attackers OAuth access to Vercel's corporate Google environment. The blast radius reached hundreds of downstream organizations — and exposes a control gap that SAMA-regulated banks routinely overlook.
Malware & Threat ActorsInitial Access Brokers Hit GCC Finance: SAMA Bank Defense Playbook
Threat actor "Crimson" listed super-admin access to a GCC finance department in late April 2026. Here is what SAMA-regulated banks must do to defend against initial access brokers before ransomware affiliates buy in.
VulnerabilitiesFortiClient EMS CVE-2026-35616: Pre-Auth RCE Risk to SAMA Banks
CVE-2026-35616 in Fortinet FortiClient EMS allows pre-auth RCE on endpoint management servers across Saudi banks. Active exploitation confirmed by CISA — patch immediately under SAMA CSCC.
VulnerabilitiescPanel CVE-2026-41940 Auth Bypass: SAMA Bank Hosting Risk
A critical CRLF injection flaw (CVSS 9.8) lets unauthenticated attackers seize root on cPanel and WHM servers. Saudi banks face TPRM and hosting-supply-chain exposure. Here is the action plan.
VulnerabilitiesCisco SD-WAN Manager Exploited Trio (CVE-2026-20122/20128/20133): SAMA Bank Branch Risk
Three actively exploited Cisco Catalyst SD-WAN Manager vulnerabilities (CVE-2026-20122/20128/20133) place Saudi bank branch networks under immediate threat. Here is what SAMA-regulated CISOs must do this week.
RansomwareAkira Ransomware Bypasses MFA on SonicWall VPNs: SAMA Bank Defense Guide
Akira ransomware operators are now bypassing MFA on SonicWall SSL VPNs by exfiltrating OTP seed values from compromised firewalls. SAMA-regulated banks face urgent perimeter risk that demands immediate CSCC-aligned controls.
VulnerabilitiesFortra GoAnywhere MFT Flaws: Pre-CVE Threat to SAMA Banks
New Fortra GoAnywhere MFT vulnerabilities expose Saudi banks' regulated file transfers. Darktrace observed pre-CVE exploitation. SAMA CSCC remediation guide for Saudi CISOs.
RansomwareDragonForce Hits Conrad Capital: 74GB Breach Lessons for SAMA Banks
DragonForce ransomware breached US investment advisor Conrad Capital, exfiltrating 74.23GB and demanding negotiations within five days. We unpack the attack and what SAMA-regulated Saudi institutions must harden in CSCC controls today.
RansomwareScreenConnect CVE-2024-1708: Medusa Ransomware Threat to SAMA Banks
CISA added ConnectWise ScreenConnect CVE-2024-1708 to the KEV catalog on April 28, 2026, after China-linked Storm-1175 and North Korean Kimsuky weaponized the path-traversal flaw to deploy Medusa ransomware and ToddlerShark malware against managed service providers and their downstream customers.
VulnerabilitiesCopy Fail (CVE-2026-31431): 732-Byte Linux Root Escalation Hits Saudi Banks
A 732-byte Python script grants root on every major Linux distribution since 2017. CVE-2026-31431 'Copy Fail' threatens every Saudi bank's Linux infrastructure. Here's what SAMA CSCC requires now.
Breaches & Data LeaksShinyHunters Hits Ameriprise: 200GB SaaS Breach Lessons for SAMA Banks
ShinyHunters claimed 200GB of Ameriprise data, hitting nearly 48,000 customers via Salesforce and SharePoint. What SAMA-regulated Saudi banks must learn about SaaS supply chain risk and detection gaps.
RansomwareEverest Ransomware Hits Frost and Citizens: SAMA CSCC Lessons
Everest's April 2026 attacks on Frost Bank and Citizens Financial expose data-first extortion tactics SAMA-regulated banks must defend against now.