Abdulaziz Alzamil

Author

Abdulaziz Alzamil

Founder & CEO, Fyntralink

Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.

  • Cybersecurity
  • Vulnerabilities & threats
  • NCA Essential Cybersecurity Controls (ECC)
  • Personal Data Protection Law (PDPL)
  • SAMA Cyber Security Framework
  • AI governance
  • Software engineering

400 articles

Breaches & Data Leaks

REF6598 & PHANTOMPULSE: How Hackers Are Weaponizing Obsidian's Plugin Ecosystem to Breach Financial Sector Employees

A sophisticated threat actor is abusing the Obsidian note-taking app's community plugin ecosystem to silently install a new RAT on financial employees' machines — no CVE, no exploit, just trusted software turned weapon.

19 Apr 2026 6 min
Cloud & Identity

McGraw-Hill's 13.5M-Record Salesforce Breach: Why Cloud Misconfiguration Is the Silent SAMA CSCC Compliance Failure

A Salesforce misconfiguration exposed 13.5 million records at McGraw-Hill. With 31% of cloud breaches sharing this same root cause, Saudi financial institutions must audit their SaaS posture before their next SAMA review.

19 Apr 2026 6 min
Compliance & Regulation

NIST Stops Scoring Most CVEs: What Saudi Financial Institutions Must Do Before Their Next SAMA Audit

NIST's National Vulnerability Database will no longer enrich most CVEs with CVSS scores effective April 15, 2026. For SAMA-regulated institutions that built patch SLAs around CVSS thresholds, this creates an immediate compliance and operational risk.

19 Apr 2026 6 min
Artificial Intelligence

ClawHavoc: How 1,184 Malicious AI Agent Skills Are Harvesting Credentials from Financial Sector Employees

Attackers poisoned OpenClaw's AI agent marketplace with over 1,184 malicious skills deploying the AMOS credential stealer. 12% of the entire registry was compromised — and Saudi financial institutions adopting agentic AI tools are directly in the crosshairs.

19 Apr 2026 5 min
Breaches & Data Leaks

ShinyHunters Breach Anodot to Compromise Dozens of Snowflake Accounts: A Supply Chain Wake-Up Call for Saudi Financial Institutions

On April 7, 2026, the ShinyHunters gang breached AI analytics firm Anodot and weaponized stolen Snowflake authentication tokens against dozens of companies. Saudi financial institutions using cloud data platforms face direct SAMA CSCC third-party risk exposure — here's what you must do now.

19 Apr 2026 5 min
Ransomware

Payouts King Ransomware Hides Inside QEMU Virtual Machines to Evade Your EDR — A Critical Alert for Saudi Financial Institutions

A ransomware group tracked as STAC4713 is using QEMU — a legitimate open-source emulator — to spin up hidden Linux VMs inside Windows hosts, tunneling out over SSH while your endpoint security sees nothing. Saudi financial institutions are a high-value target.

19 Apr 2026 5 min
Vulnerabilities

CVE-2026-21643: The Fortinet FortiClient EMS Zero-Auth SQL Injection CISA Is Flagging — Action Required for Saudi Financial Institutions

CISA confirmed active exploitation of CVE-2026-21643 on April 13, 2026 — a pre-authentication SQL injection in Fortinet FortiClient EMS with a CVSS score of 9.1. Saudi financial institutions running affected versions must patch immediately or face direct risk of unauthorized remote code execution with no credentials required.

19 Apr 2026 5 min
Vulnerabilities

CVE-2026-34621: The Adobe Acrobat Zero-Day Hidden in Your Financial Institution's PDF Workflow

A critical zero-day in Adobe Acrobat Reader is being weaponized through invoice-themed PDFs targeting financial institutions. CISA's April 27 deadline is live — here's what Saudi CISOs must do immediately.

19 Apr 2026 5 min
Ransomware

The Gentlemen: The RaaS Group That Built a Database of 14,700 FortiGate Devices — and Why Saudi Financial Institutions Are in the Crosshairs

The Gentlemen ransomware group has grown 420% in a single quarter and maintains a database of 14,700 pre-exploited FortiGate devices. Saudi financial institutions running FortiOS must act now — here is what you need to know.

19 Apr 2026 5 min
Vulnerabilities

CVE-2026-39987: Hackers Exploit Marimo AI Notebook to Deploy Blockchain Backdoor via Hugging Face

A CVSS 9.3 RCE flaw in the Marimo AI notebook tool was weaponized within 10 hours of disclosure, delivering NKAbuse — a Go-based backdoor using blockchain C2 — via a typosquatted Hugging Face Space. Saudi financial institutions adopting AI tooling must act now.

18 Apr 2026 5 min
Vulnerabilities

CVE-2026-27681: The CVSS 9.9 SAP Flaw That Puts Saudi Financial Data at Risk Right Now

A CVSS 9.9 SQL injection vulnerability in SAP Business Planning and Consolidation allows a low-privileged attacker to execute arbitrary database commands — a direct threat to the financial planning systems of Saudi SAMA-regulated institutions running SAP.

18 Apr 2026 5 min
Malware & Threat Actors

PHANTOMPULSE RAT: When Your Note-Taking App Becomes a Weapon Against Financial Sector Employees

A new attack campaign (REF6598) weaponizes the Obsidian note-taking app to deliver PHANTOMPULSE RAT against financial sector employees — bypassing EDR entirely by abusing legitimate software. Saudi CISOs must understand this threat now.

18 Apr 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality