Author
Abdulaziz Alzamil
Founder & CEO, Fyntralink
Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.
400 articles
Operation PowerOFF Dismantles 53 DDoS-for-Hire Platforms: A Wake-Up Call for Saudi Financial Institutions
Europol's Operation PowerOFF seized 53 DDoS booter domains and warned 75,000 users in April 2026. Here is what Saudi banks and financial institutions must do to meet SAMA CSCC and NCA ECC availability requirements.
Phishing & FraudThe Deepfake Threat Saudi Financial CISOs Can No Longer Ignore: AI Voice Cloning, CEO Fraud, and KYC Bypass in 2026
A darknet actor is selling real-time deepfake tools that defeat bank KYC in seconds. Across the GCC, fraudsters are impersonating CEOs with AI-cloned voices to authorize wire transfers. Saudi financial institutions need a response framework — now.
Cloud & IdentityEvilToken: The AI-Powered Phishing Kit That Defeats MFA and Targets Saudi Financial M365 Environments
A new phishing-as-a-service toolkit called EvilToken is bypassing MFA at scale using AI-generated lures and OAuth device code abuse, targeting M365 users across the UAE and beyond — a direct risk to Saudi financial institutions.
Supply Chain & Third PartyBooking.com's ClickFix Supply Chain Breach: The Third-Party Vendor Risk Every Saudi Financial CISO Must Address Now
Booking.com confirmed a breach exposing millions of customers' reservation data — attackers never touched Booking.com directly. They compromised hotel partners using ClickFix malware. Saudi financial institutions face identical third-party exposure under SAMA CSCC.
Compliance & RegulationNIST Stops Enriching Most CVEs: Saudi Financial Institutions Must Rebuild Their Vulnerability Management Strategy Now
On April 15, 2026, NIST quietly changed the rules of vulnerability management. Most CVEs will no longer receive severity scores or product details from NVD — and Saudi financial institutions that rely on NVD enrichment for SAMA CSCC compliance are directly exposed.
Compliance & RegulationSDAIA's 48 PDPL Enforcement Decisions: Saudi Financial Institutions Now Face Real Legal Exposure
SDAIA has formally issued 48 enforcement decisions under Saudi Arabia's PDPL. For financial institutions regulated by SAMA, this marks a decisive shift from documentation-based compliance to operational accountability — and the window to self-correct is closing.
Breaches & Data LeaksShinyHunters Hits McGraw-Hill via Salesforce Misconfiguration: 13.5M Records and a Warning Saudi Financial CISOs Must Heed
No malware, no CVE, no phishing — just a Salesforce misconfiguration. ShinyHunters walked out with 13.5 million McGraw-Hill records. Saudi banks running Salesforce or Dynamics 365 hold far more sensitive data and face identical exposure under PDPL and SAMA CSCC.
VulnerabilitiesCVE-2026-32201: Microsoft SharePoint Zero-Day Added to CISA KEV — Saudi Financial Institutions Must Patch Now
Microsoft's April 2026 Patch Tuesday confirmed active exploitation of CVE-2026-32201, a SharePoint Server spoofing zero-day now on CISA's KEV list. Saudi banks and financial firms relying on SharePoint for document management face credential theft and phishing risk until patched.
Network & Infrastructure88% of Firewall Brute-Force Attacks Now Originate from the Middle East — Saudi Financial Perimeter Security Under Siege
Barracuda's SOC data reveals that 88% of surging brute-force attacks against SonicWall and FortiGate perimeter devices in Q1 2026 originate from the Middle East — a direct and escalating threat for Saudi financial institutions.
VulnerabilitiesCVE-2026-34197: A 13-Year-Old Apache ActiveMQ RCE Now on CISA's Most-Wanted List — Saudi Financial Middleware at Risk
CISA has added CVE-2026-34197 — a 13-year-old RCE flaw in Apache ActiveMQ Classic — to its Known Exploited Vulnerabilities catalog. Active exploitation is peaking now, and Saudi financial institutions running ActiveMQ in payment or integration middleware must act before April 30.
VulnerabilitiesCVE-2026-35616: Fortinet FortiClient EMS Zero-Day Under Active Exploitation — A Direct Risk for Saudi Financial Endpoint Security
A critical pre-authentication bypass in Fortinet FortiClient EMS (CVE-2026-35616, CVSS 9.1) is being actively exploited in the wild. Saudi financial institutions relying on Fortinet for endpoint management must act now — CISA already mandated a patch deadline that has passed.
RansomwareAnubis RaaS: When Ransomware Weaponizes the Regulator — A Direct Threat to Saudi Financial Institutions
Anubis ransomware doesn't just encrypt your data — it threatens to report you to your own regulator. Here's why SAMA-regulated institutions face a uniquely dangerous exposure and what your SOC must do now.