Author
Abdulaziz Alzamil
Founder & CEO, Fyntralink
Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.
400 articles
CVE-2026-20700: Apple dyld Zero-Day Hits Saudi Bank Mobile Fleets
Apple's first actively exploited zero-day of 2026 — CVE-2026-20700 in dyld — was abused in a surveillance-grade chain against specific targets. Here is what Saudi banks under SAMA CSCC must do now.
Breaches & Data LeaksMarquis Software Breach: 80 Banks Hit — A SAMA TPRM Reckoning
When one fintech vendor breach cascades into 80 US banks, regulators take notice. The Marquis ransomware incident shows why SAMA-regulated CISOs must overhaul their third-party risk programs in 2026.
RansomwareQilin Ransomware Tops Q1 2026: Threat Profile for Saudi Banks
Qilin became Q1 2026's most active ransomware group with 342 victims worldwide and a sharpened focus on financial services. Here is what Saudi CISOs operating under SAMA CSCC need to act on this quarter.
VulnerabilitiesCVE-2026-41940: cPanel Zero-Day Threatens Saudi Bank Hosting
A critical cPanel authentication bypass (CVE-2026-41940, CVSS 9.8) was exploited as a zero-day for two months before patch. Saudi banks must act on SAMA CSCC patch governance and third-party hosting risk obligations.
Breaches & Data LeaksShinyHunters Salesforce Heist Threatens Saudi Bank SaaS Security
The ShinyHunters extortion group has exfiltrated 1.5 billion records from 760 Salesforce tenants through OAuth abuse and vishing—exposing critical TPRM gaps for Saudi SAMA-regulated financial institutions.
VulnerabilitiesCVE-2026-20133: Cisco SD-WAN Manager Leak Hits Saudi Bank Branches
CISA added Cisco Catalyst SD-WAN Manager flaw CVE-2026-20133 to KEV. Active exploitation exposes file-system data on the controller binding Saudi bank branches. Patch and assess now.
VulnerabilitiesCVE-2026-3854: GitHub RCE via Git Push Threatens Saudi Bank CI/CD
A critical 8.7 CVSS GitHub vulnerability lets any authenticated user execute code through a single git push command. Saudi banks running GHES face full source-code and secrets exposure under SAMA CSCC.
Breaches & Data LeaksPyTorch Lightning PyPI Hack: Shai-Hulud Worm Hits Saudi Bank AI
On April 30, 2026, PyTorch Lightning 2.6.2 and 2.6.3 were compromised by a Mini Shai-Hulud worm stealing credentials and poisoning GitHub. Saudi banks running AI/ML workloads face an urgent SAMA CSCC TPRM event.
VulnerabilitiesCVE-2026-27681: Critical SAP BPC SQL Injection Threatens Saudi Bank Financial Reporting
A near-maximum severity SQL injection flaw (CVSS 9.9) in SAP Business Planning and Consolidation lets low-privileged users execute arbitrary database commands — a direct hit on the financial reporting layer Saudi banks rely on for SAMA submissions.
RansomwareEverest Ransomware Hits Frost & Citizens Banks: A Saudi TPRM Wake-Up Call
Everest ransomware listed Frost Bank and Citizens Financial Group on its leak site after compromising a shared third-party vendor. For SAMA-regulated banks, this is a textbook stress test of CSCC Domain 4 controls.
VulnerabilitiesCVE-2025-2749: Kentico Xperience RCE Threatens Saudi Bank Web Properties
CISA just added CVE-2025-2749, an authenticated RCE in Kentico Xperience's Staging Sync Server, to the KEV catalog with a May 4, 2026 federal deadline. Here's why Saudi banks running public CMS portals must act now under SAMA CSCC.
VulnerabilitiesCVE-2025-32975: Quest KACE SMA Auth Bypass Hits Saudi Bank Endpoint Management
A CVSS 10.0 pre-authentication bypass in Quest KACE SMA is being actively exploited. For Saudi banks running KACE for patching and inventory, the blast radius reaches every managed endpoint. Here is what SAMA-regulated CISOs must do this week.