Author
Abdulaziz Alzamil
Founder & CEO, Fyntralink
Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.
400 articles
CVE-2026-41103: Critical Microsoft SSO Plugin Flaw Lets Attackers Forge Identities in Jira and Confluence
A CVSS 9.1 flaw in Microsoft's SSO Plugin for Jira and Confluence lets unauthenticated attackers forge identities and gain admin access — bypassing Entra ID entirely. Here's what Saudi CISOs must do now.
VulnerabilitiesGoogle Detects First AI-Generated Zero-Day Exploit in the Wild
Google confirms the first zero-day exploit built using artificial intelligence was caught in the wild — a semantic logic flaw designed to bypass two-factor authentication. Here's what it means for Saudi financial institutions.
Breaches & Data LeaksGitHub Breached via Poisoned VS Code Extension: 3,800 Internal Repos Exfiltrated by TeamPCP
A poisoned VS Code extension gave TeamPCP access to 3,800 GitHub internal repositories — exposing Copilot, Actions, and CodeQL source code. Here's what Saudi CISOs must do about developer tool supply chain risk.
Supply Chain & Third PartyMini Shai-Hulud: SAP npm Supply Chain Attack Steals Developer Credentials and CI/CD Secrets
Four official SAP npm packages were compromised with credential-stealing malware in the Mini Shai-Hulud campaign. Here's what Saudi financial CISOs must do to protect their SAP development pipelines.
VulnerabilitiesYellowKey & GreenPlasma: Unpatched Windows Zero-Days Bypass BitLocker and Escalate to SYSTEM
A disgruntled researcher dropped PoC exploits for two unpatched Windows zero-days — one bypasses BitLocker, the other grants SYSTEM privileges via CTFMON. No CVEs, no patches, full impact.
VulnerabilitiesSEPPMail CVSS 10.0 RCE Chain: Four Flaws Turn Your Email Encryption Gateway into an Open Door
Four chained vulnerabilities in SEPPMail Secure E-Mail Gateway — headlined by a CVSS 10.0 path traversal to RCE — let attackers read every encrypted email and persist on the appliance indefinitely. Saudi financial institutions must patch immediately.
VulnerabilitiesCVE-2026-20182: Cisco SD-WAN CVSS 10.0 Auth Bypass Actively Exploited — Sixth Zero-Day This Year
Cisco's sixth SD-WAN zero-day in 2026 carries a perfect CVSS 10.0 score and is already being exploited by an advanced threat actor. Saudi financial institutions running SD-WAN fabrics face immediate risk.
VulnerabilitiesDrupal Highly Critical Zero-Auth Flaw Drops Today: Patch Your Portals Before Exploits Land
Drupal drops a severity-20 patch today — zero authentication, full database access. Saudi financial institutions must patch before exploits land within hours.
VulnerabilitiesFour Word RCE Flaws Turn Outlook Preview Pane into an Attack Surface
Microsoft's May 2026 Patch Tuesday disclosed four Word RCE flaws exploitable through Outlook's preview pane — no clicks, no macros, no warnings. Here's what Saudi CISOs must do now.
VulnerabilitiesCVE-2026-42945: Critical NGINX Heap Overflow Under Active Exploitation Threatens Every Saudi Enterprise
An 18-year-old flaw in NGINX's rewrite module — CVE-2026-42945 (CVSS 9.2) — is now actively exploited. With NGINX powering the majority of Saudi enterprise web infrastructure, here's what your security team must do immediately.
Breaches & Data LeaksCoinbase Insider Bribery Breach: Why Saudi Financial CISOs Must Rethink Third-Party Personnel Risk
Bribed overseas contractors stole data from 70,000 Coinbase customers — a $400M lesson in why insider threat programs for third-party personnel are non-negotiable under SAMA CSCC and NCA ECC.
VulnerabilitiesCVE-2026-41940: cPanel Zero-Day Authentication Bypass Exposes 1.5 Million Servers to Full Takeover
A CRLF injection flaw in cPanel & WHM let attackers forge root sessions for two months before anyone noticed. With 1.5 million exposed instances globally, Saudi financial institutions hosting client portals and payment gateways on cPanel infrastructure face immediate risk.