Abdulaziz Alzamil

Author

Abdulaziz Alzamil

Founder & CEO, Fyntralink

Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.

  • Cybersecurity
  • Vulnerabilities & threats
  • NCA Essential Cybersecurity Controls (ECC)
  • Personal Data Protection Law (PDPL)
  • SAMA Cyber Security Framework
  • AI governance
  • Software engineering

400 articles

Compliance & Regulation

Operation PowerOFF Dismantles 53 DDoS-for-Hire Platforms: A Wake-Up Call for Saudi Financial Institutions

Europol's Operation PowerOFF seized 53 DDoS booter domains and warned 75,000 users in April 2026. Here is what Saudi banks and financial institutions must do to meet SAMA CSCC and NCA ECC availability requirements.

18 Apr 2026 5 min
Phishing & Fraud

The Deepfake Threat Saudi Financial CISOs Can No Longer Ignore: AI Voice Cloning, CEO Fraud, and KYC Bypass in 2026

A darknet actor is selling real-time deepfake tools that defeat bank KYC in seconds. Across the GCC, fraudsters are impersonating CEOs with AI-cloned voices to authorize wire transfers. Saudi financial institutions need a response framework — now.

18 Apr 2026 6 min
Cloud & Identity

EvilToken: The AI-Powered Phishing Kit That Defeats MFA and Targets Saudi Financial M365 Environments

A new phishing-as-a-service toolkit called EvilToken is bypassing MFA at scale using AI-generated lures and OAuth device code abuse, targeting M365 users across the UAE and beyond — a direct risk to Saudi financial institutions.

18 Apr 2026 5 min
Supply Chain & Third Party

Booking.com's ClickFix Supply Chain Breach: The Third-Party Vendor Risk Every Saudi Financial CISO Must Address Now

Booking.com confirmed a breach exposing millions of customers' reservation data — attackers never touched Booking.com directly. They compromised hotel partners using ClickFix malware. Saudi financial institutions face identical third-party exposure under SAMA CSCC.

18 Apr 2026 6 min
Compliance & Regulation

NIST Stops Enriching Most CVEs: Saudi Financial Institutions Must Rebuild Their Vulnerability Management Strategy Now

On April 15, 2026, NIST quietly changed the rules of vulnerability management. Most CVEs will no longer receive severity scores or product details from NVD — and Saudi financial institutions that rely on NVD enrichment for SAMA CSCC compliance are directly exposed.

18 Apr 2026 5 min
Compliance & Regulation

SDAIA's 48 PDPL Enforcement Decisions: Saudi Financial Institutions Now Face Real Legal Exposure

SDAIA has formally issued 48 enforcement decisions under Saudi Arabia's PDPL. For financial institutions regulated by SAMA, this marks a decisive shift from documentation-based compliance to operational accountability — and the window to self-correct is closing.

18 Apr 2026 5 min
Breaches & Data Leaks

ShinyHunters Hits McGraw-Hill via Salesforce Misconfiguration: 13.5M Records and a Warning Saudi Financial CISOs Must Heed

No malware, no CVE, no phishing — just a Salesforce misconfiguration. ShinyHunters walked out with 13.5 million McGraw-Hill records. Saudi banks running Salesforce or Dynamics 365 hold far more sensitive data and face identical exposure under PDPL and SAMA CSCC.

18 Apr 2026 7 min
Vulnerabilities

CVE-2026-32201: Microsoft SharePoint Zero-Day Added to CISA KEV — Saudi Financial Institutions Must Patch Now

Microsoft's April 2026 Patch Tuesday confirmed active exploitation of CVE-2026-32201, a SharePoint Server spoofing zero-day now on CISA's KEV list. Saudi banks and financial firms relying on SharePoint for document management face credential theft and phishing risk until patched.

18 Apr 2026 5 min
Network & Infrastructure

88% of Firewall Brute-Force Attacks Now Originate from the Middle East — Saudi Financial Perimeter Security Under Siege

Barracuda's SOC data reveals that 88% of surging brute-force attacks against SonicWall and FortiGate perimeter devices in Q1 2026 originate from the Middle East — a direct and escalating threat for Saudi financial institutions.

18 Apr 2026 4 min
Vulnerabilities

CVE-2026-34197: A 13-Year-Old Apache ActiveMQ RCE Now on CISA's Most-Wanted List — Saudi Financial Middleware at Risk

CISA has added CVE-2026-34197 — a 13-year-old RCE flaw in Apache ActiveMQ Classic — to its Known Exploited Vulnerabilities catalog. Active exploitation is peaking now, and Saudi financial institutions running ActiveMQ in payment or integration middleware must act before April 30.

17 Apr 2026 5 min
Vulnerabilities

CVE-2026-35616: Fortinet FortiClient EMS Zero-Day Under Active Exploitation — A Direct Risk for Saudi Financial Endpoint Security

A critical pre-authentication bypass in Fortinet FortiClient EMS (CVE-2026-35616, CVSS 9.1) is being actively exploited in the wild. Saudi financial institutions relying on Fortinet for endpoint management must act now — CISA already mandated a patch deadline that has passed.

17 Apr 2026 5 min
Ransomware

Anubis RaaS: When Ransomware Weaponizes the Regulator — A Direct Threat to Saudi Financial Institutions

Anubis ransomware doesn't just encrypt your data — it threatens to report you to your own regulator. Here's why SAMA-regulated institutions face a uniquely dangerous exposure and what your SOC must do now.

16 Apr 2026 6 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality