Abdulaziz Alzamil

Author

Abdulaziz Alzamil

Founder & CEO, Fyntralink

Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.

  • Cybersecurity
  • Vulnerabilities & threats
  • NCA Essential Cybersecurity Controls (ECC)
  • Personal Data Protection Law (PDPL)
  • SAMA Cyber Security Framework
  • AI governance
  • Software engineering

400 articles

Vulnerabilities

CVE-2026-41103: Critical Microsoft SSO Plugin Flaw Lets Attackers Forge Identities in Jira and Confluence

A CVSS 9.1 flaw in Microsoft's SSO Plugin for Jira and Confluence lets unauthenticated attackers forge identities and gain admin access — bypassing Entra ID entirely. Here's what Saudi CISOs must do now.

20 May 2026 5 min
Vulnerabilities

Google Detects First AI-Generated Zero-Day Exploit in the Wild

Google confirms the first zero-day exploit built using artificial intelligence was caught in the wild — a semantic logic flaw designed to bypass two-factor authentication. Here's what it means for Saudi financial institutions.

20 May 2026 5 min
Breaches & Data Leaks

GitHub Breached via Poisoned VS Code Extension: 3,800 Internal Repos Exfiltrated by TeamPCP

A poisoned VS Code extension gave TeamPCP access to 3,800 GitHub internal repositories — exposing Copilot, Actions, and CodeQL source code. Here's what Saudi CISOs must do about developer tool supply chain risk.

20 May 2026 5 min
Supply Chain & Third Party

Mini Shai-Hulud: SAP npm Supply Chain Attack Steals Developer Credentials and CI/CD Secrets

Four official SAP npm packages were compromised with credential-stealing malware in the Mini Shai-Hulud campaign. Here's what Saudi financial CISOs must do to protect their SAP development pipelines.

20 May 2026 5 min
Vulnerabilities

YellowKey & GreenPlasma: Unpatched Windows Zero-Days Bypass BitLocker and Escalate to SYSTEM

A disgruntled researcher dropped PoC exploits for two unpatched Windows zero-days — one bypasses BitLocker, the other grants SYSTEM privileges via CTFMON. No CVEs, no patches, full impact.

20 May 2026 5 min
Vulnerabilities

SEPPMail CVSS 10.0 RCE Chain: Four Flaws Turn Your Email Encryption Gateway into an Open Door

Four chained vulnerabilities in SEPPMail Secure E-Mail Gateway — headlined by a CVSS 10.0 path traversal to RCE — let attackers read every encrypted email and persist on the appliance indefinitely. Saudi financial institutions must patch immediately.

20 May 2026 4 min
Vulnerabilities

CVE-2026-20182: Cisco SD-WAN CVSS 10.0 Auth Bypass Actively Exploited — Sixth Zero-Day This Year

Cisco's sixth SD-WAN zero-day in 2026 carries a perfect CVSS 10.0 score and is already being exploited by an advanced threat actor. Saudi financial institutions running SD-WAN fabrics face immediate risk.

20 May 2026 5 min
Vulnerabilities

Drupal Highly Critical Zero-Auth Flaw Drops Today: Patch Your Portals Before Exploits Land

Drupal drops a severity-20 patch today — zero authentication, full database access. Saudi financial institutions must patch before exploits land within hours.

20 May 2026 5 min
Vulnerabilities

Four Word RCE Flaws Turn Outlook Preview Pane into an Attack Surface

Microsoft's May 2026 Patch Tuesday disclosed four Word RCE flaws exploitable through Outlook's preview pane — no clicks, no macros, no warnings. Here's what Saudi CISOs must do now.

20 May 2026 5 min
Vulnerabilities

CVE-2026-42945: Critical NGINX Heap Overflow Under Active Exploitation Threatens Every Saudi Enterprise

An 18-year-old flaw in NGINX's rewrite module — CVE-2026-42945 (CVSS 9.2) — is now actively exploited. With NGINX powering the majority of Saudi enterprise web infrastructure, here's what your security team must do immediately.

20 May 2026 5 min
Breaches & Data Leaks

Coinbase Insider Bribery Breach: Why Saudi Financial CISOs Must Rethink Third-Party Personnel Risk

Bribed overseas contractors stole data from 70,000 Coinbase customers — a $400M lesson in why insider threat programs for third-party personnel are non-negotiable under SAMA CSCC and NCA ECC.

20 May 2026 5 min
Vulnerabilities

CVE-2026-41940: cPanel Zero-Day Authentication Bypass Exposes 1.5 Million Servers to Full Takeover

A CRLF injection flaw in cPanel & WHM let attackers forge root sessions for two months before anyone noticed. With 1.5 million exposed instances globally, Saudi financial institutions hosting client portals and payment gateways on cPanel infrastructure face immediate risk.

20 May 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality