Author
Abdulaziz Alzamil
Founder & CEO, Fyntralink
Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.
400 articles
REF6598 & PHANTOMPULSE: How Hackers Are Weaponizing Obsidian's Plugin Ecosystem to Breach Financial Sector Employees
A sophisticated threat actor is abusing the Obsidian note-taking app's community plugin ecosystem to silently install a new RAT on financial employees' machines — no CVE, no exploit, just trusted software turned weapon.
Cloud & IdentityMcGraw-Hill's 13.5M-Record Salesforce Breach: Why Cloud Misconfiguration Is the Silent SAMA CSCC Compliance Failure
A Salesforce misconfiguration exposed 13.5 million records at McGraw-Hill. With 31% of cloud breaches sharing this same root cause, Saudi financial institutions must audit their SaaS posture before their next SAMA review.
Compliance & RegulationNIST Stops Scoring Most CVEs: What Saudi Financial Institutions Must Do Before Their Next SAMA Audit
NIST's National Vulnerability Database will no longer enrich most CVEs with CVSS scores effective April 15, 2026. For SAMA-regulated institutions that built patch SLAs around CVSS thresholds, this creates an immediate compliance and operational risk.
Artificial IntelligenceClawHavoc: How 1,184 Malicious AI Agent Skills Are Harvesting Credentials from Financial Sector Employees
Attackers poisoned OpenClaw's AI agent marketplace with over 1,184 malicious skills deploying the AMOS credential stealer. 12% of the entire registry was compromised — and Saudi financial institutions adopting agentic AI tools are directly in the crosshairs.
Breaches & Data LeaksShinyHunters Breach Anodot to Compromise Dozens of Snowflake Accounts: A Supply Chain Wake-Up Call for Saudi Financial Institutions
On April 7, 2026, the ShinyHunters gang breached AI analytics firm Anodot and weaponized stolen Snowflake authentication tokens against dozens of companies. Saudi financial institutions using cloud data platforms face direct SAMA CSCC third-party risk exposure — here's what you must do now.
RansomwarePayouts King Ransomware Hides Inside QEMU Virtual Machines to Evade Your EDR — A Critical Alert for Saudi Financial Institutions
A ransomware group tracked as STAC4713 is using QEMU — a legitimate open-source emulator — to spin up hidden Linux VMs inside Windows hosts, tunneling out over SSH while your endpoint security sees nothing. Saudi financial institutions are a high-value target.
VulnerabilitiesCVE-2026-21643: The Fortinet FortiClient EMS Zero-Auth SQL Injection CISA Is Flagging — Action Required for Saudi Financial Institutions
CISA confirmed active exploitation of CVE-2026-21643 on April 13, 2026 — a pre-authentication SQL injection in Fortinet FortiClient EMS with a CVSS score of 9.1. Saudi financial institutions running affected versions must patch immediately or face direct risk of unauthorized remote code execution with no credentials required.
VulnerabilitiesCVE-2026-34621: The Adobe Acrobat Zero-Day Hidden in Your Financial Institution's PDF Workflow
A critical zero-day in Adobe Acrobat Reader is being weaponized through invoice-themed PDFs targeting financial institutions. CISA's April 27 deadline is live — here's what Saudi CISOs must do immediately.
RansomwareThe Gentlemen: The RaaS Group That Built a Database of 14,700 FortiGate Devices — and Why Saudi Financial Institutions Are in the Crosshairs
The Gentlemen ransomware group has grown 420% in a single quarter and maintains a database of 14,700 pre-exploited FortiGate devices. Saudi financial institutions running FortiOS must act now — here is what you need to know.
VulnerabilitiesCVE-2026-39987: Hackers Exploit Marimo AI Notebook to Deploy Blockchain Backdoor via Hugging Face
A CVSS 9.3 RCE flaw in the Marimo AI notebook tool was weaponized within 10 hours of disclosure, delivering NKAbuse — a Go-based backdoor using blockchain C2 — via a typosquatted Hugging Face Space. Saudi financial institutions adopting AI tooling must act now.
VulnerabilitiesCVE-2026-27681: The CVSS 9.9 SAP Flaw That Puts Saudi Financial Data at Risk Right Now
A CVSS 9.9 SQL injection vulnerability in SAP Business Planning and Consolidation allows a low-privileged attacker to execute arbitrary database commands — a direct threat to the financial planning systems of Saudi SAMA-regulated institutions running SAP.
Malware & Threat ActorsPHANTOMPULSE RAT: When Your Note-Taking App Becomes a Weapon Against Financial Sector Employees
A new attack campaign (REF6598) weaponizes the Obsidian note-taking app to deliver PHANTOMPULSE RAT against financial sector employees — bypassing EDR entirely by abusing legitimate software. Saudi CISOs must understand this threat now.