Abdulaziz Alzamil

Author

Abdulaziz Alzamil

Founder & CEO, Fyntralink

Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.

  • Cybersecurity
  • Vulnerabilities & threats
  • NCA Essential Cybersecurity Controls (ECC)
  • Personal Data Protection Law (PDPL)
  • SAMA Cyber Security Framework
  • AI governance
  • Software engineering

400 articles

Vulnerabilities

CVE-2026-34197: 13-Year-Old ActiveMQ RCE Threatens Saudi Banks

CISA added Apache ActiveMQ CVE-2026-34197 (CVSS 8.8) to KEV with an April 30 deadline. With 6,000+ exposed instances and active exploitation, Saudi financial institutions must act now under SAMA CSCC.

30 Apr 2026 4 min
Vulnerabilities

CVE-2026-33824: Windows IKE Zero-Day Threatens Saudi Bank VPNs

An unauthenticated attacker can take over Windows IKE/IPsec VPN servers via UDP 500/4500 — CVSS 9.8. Saudi banks running Windows IKEv2 must patch immediately.

30 Apr 2026 4 min
Vulnerabilities

EngageLab SDK Flaw Exposes 50M Android Users — Saudi Mobile Banking on Alert

A third-party push-notification SDK quietly added an exported activity to 50 million Android installs, including 30 million crypto wallets. Here is what every Saudi bank's mobile security team needs to verify this week.

30 Apr 2026 5 min
Vulnerabilities

CVE-2026-32202: Windows Shell Zero-Click NTLM Leak Hits Saudi Banks

A zero-click Windows Shell flaw silently leaks NTLMv2 hashes the moment a user browses a folder. Saudi financial institutions under SAMA CSCC must patch CVE-2026-32202 by May 12 to avoid credential theft and lateral movement across Active Directory.

29 Apr 2026 4 min
Vulnerabilities

CVE-2026-3854: A Single Git Push Hijacks GitHub — Saudi Banks at Risk

A single git push can now grant full remote code execution on GitHub Enterprise Server. For Saudi financial institutions running internal repositories, CVE-2026-3854 is more than a DevOps incident — it is a SAMA CSCC source-code protection breach waiting to happen.

29 Apr 2026 4 min
Artificial Intelligence

Shadow AI: The Invisible Threat Inside Saudi Banks That No SAMA Audit Will Catch

Three in four CISOs globally have already found unsanctioned AI tools running inside their organizations. In Saudi financial institutions, that means confidential customer data, earnings projections, and audit records may be flowing into AI platforms with no DPA, no access control, and no SAMA oversight.

25 Apr 2026 6 min
Supply Chain & Third Party

Bitwarden CLI Compromised: Supply Chain Attack Puts Saudi Bank CI/CD Secrets at Risk

On April 22, a malicious Bitwarden CLI version was live on npm for 93 minutes — stealing SSH keys, cloud secrets, and CI/CD tokens. Here's what Saudi financial institutions must do immediately.

25 Apr 2026 6 min
Vulnerabilities

CVE-2026-34621: Adobe Reader Zero-Day Targets Saudi Financial PDFs

CVE-2026-34621, an actively exploited Adobe Acrobat Reader zero-day, enables arbitrary code execution via weaponized PDFs. Saudi banks and fintechs face immediate endpoint and SAMA CSCC exposure.

20 Apr 2026 4 min
Breaches & Data Leaks

824,000 Customers Exposed: Marquis-SonicWall Lessons for Saudi Banks

An unpatched SonicWall firewall at a trusted banking vendor cascaded into an Akira ransomware breach affecting 80 banks and 824,000 customers. Saudi financial institutions face the same third-party exposure under SAMA CSCC.

20 Apr 2026 4 min
Vulnerabilities

CVE-2026-32201: SharePoint Zero-Day Exploited — A Direct Threat to Saudi Banks

Microsoft's April 2026 Patch Tuesday fixed 167 flaws — but one actively exploited SharePoint zero-day demands urgent attention from every Saudi bank's CISO and SAMA compliance team.

19 Apr 2026 4 min
Vulnerabilities

CVE-2026-1281 & CVE-2026-1340: The Ivanti EPMM Zero-Days Putting Saudi Bank MDM Fleets at Risk

A single bulletproof-hosted IP is driving 83% of active Ivanti EPMM exploitation via CVE-2026-1281 and CVE-2026-1340. Saudi banks running on-prem MDM face direct SAMA CSCC exposure — here is what to patch, hunt, and rotate now.

19 Apr 2026 4 min
Vulnerabilities

CVE-2026-34197: The 13-Year-Old Apache ActiveMQ Flaw Now Under Active Exploitation — Saudi Financial Institutions Have Until April 30

A 13-year-old RCE flaw in Apache ActiveMQ Classic is now actively exploited via the Jolokia API. CISA added CVE-2026-34197 to its KEV catalog with a federal deadline of April 30. Here's what Saudi financial institutions need to do now.

19 Apr 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality