Abdulaziz Alzamil

Author

Abdulaziz Alzamil

Founder & CEO, Fyntralink

Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.

  • Cybersecurity
  • Vulnerabilities & threats
  • NCA Essential Cybersecurity Controls (ECC)
  • Personal Data Protection Law (PDPL)
  • SAMA Cyber Security Framework
  • AI governance
  • Software engineering

400 articles

Vulnerabilities

CVE-2026-20700: Apple dyld Zero-Day Hits Saudi Bank Mobile Fleets

Apple's first actively exploited zero-day of 2026 — CVE-2026-20700 in dyld — was abused in a surveillance-grade chain against specific targets. Here is what Saudi banks under SAMA CSCC must do now.

2 May 2026 4 min
Breaches & Data Leaks

Marquis Software Breach: 80 Banks Hit — A SAMA TPRM Reckoning

When one fintech vendor breach cascades into 80 US banks, regulators take notice. The Marquis ransomware incident shows why SAMA-regulated CISOs must overhaul their third-party risk programs in 2026.

2 May 2026 4 min
Ransomware

Qilin Ransomware Tops Q1 2026: Threat Profile for Saudi Banks

Qilin became Q1 2026's most active ransomware group with 342 victims worldwide and a sharpened focus on financial services. Here is what Saudi CISOs operating under SAMA CSCC need to act on this quarter.

2 May 2026 4 min
Vulnerabilities

CVE-2026-41940: cPanel Zero-Day Threatens Saudi Bank Hosting

A critical cPanel authentication bypass (CVE-2026-41940, CVSS 9.8) was exploited as a zero-day for two months before patch. Saudi banks must act on SAMA CSCC patch governance and third-party hosting risk obligations.

2 May 2026 4 min
Breaches & Data Leaks

ShinyHunters Salesforce Heist Threatens Saudi Bank SaaS Security

The ShinyHunters extortion group has exfiltrated 1.5 billion records from 760 Salesforce tenants through OAuth abuse and vishing—exposing critical TPRM gaps for Saudi SAMA-regulated financial institutions.

2 May 2026 4 min
Vulnerabilities

CVE-2026-20133: Cisco SD-WAN Manager Leak Hits Saudi Bank Branches

CISA added Cisco Catalyst SD-WAN Manager flaw CVE-2026-20133 to KEV. Active exploitation exposes file-system data on the controller binding Saudi bank branches. Patch and assess now.

1 May 2026 4 min
Vulnerabilities

CVE-2026-3854: GitHub RCE via Git Push Threatens Saudi Bank CI/CD

A critical 8.7 CVSS GitHub vulnerability lets any authenticated user execute code through a single git push command. Saudi banks running GHES face full source-code and secrets exposure under SAMA CSCC.

1 May 2026 4 min
Breaches & Data Leaks

PyTorch Lightning PyPI Hack: Shai-Hulud Worm Hits Saudi Bank AI

On April 30, 2026, PyTorch Lightning 2.6.2 and 2.6.3 were compromised by a Mini Shai-Hulud worm stealing credentials and poisoning GitHub. Saudi banks running AI/ML workloads face an urgent SAMA CSCC TPRM event.

1 May 2026 4 min
Vulnerabilities

CVE-2026-27681: Critical SAP BPC SQL Injection Threatens Saudi Bank Financial Reporting

A near-maximum severity SQL injection flaw (CVSS 9.9) in SAP Business Planning and Consolidation lets low-privileged users execute arbitrary database commands — a direct hit on the financial reporting layer Saudi banks rely on for SAMA submissions.

1 May 2026 3 min
Ransomware

Everest Ransomware Hits Frost & Citizens Banks: A Saudi TPRM Wake-Up Call

Everest ransomware listed Frost Bank and Citizens Financial Group on its leak site after compromising a shared third-party vendor. For SAMA-regulated banks, this is a textbook stress test of CSCC Domain 4 controls.

1 May 2026 4 min
Vulnerabilities

CVE-2025-2749: Kentico Xperience RCE Threatens Saudi Bank Web Properties

CISA just added CVE-2025-2749, an authenticated RCE in Kentico Xperience's Staging Sync Server, to the KEV catalog with a May 4, 2026 federal deadline. Here's why Saudi banks running public CMS portals must act now under SAMA CSCC.

1 May 2026 3 min
Vulnerabilities

CVE-2025-32975: Quest KACE SMA Auth Bypass Hits Saudi Bank Endpoint Management

A CVSS 10.0 pre-authentication bypass in Quest KACE SMA is being actively exploited. For Saudi banks running KACE for patching and inventory, the blast radius reaches every managed endpoint. Here is what SAMA-regulated CISOs must do this week.

1 May 2026 4 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality