Abdulaziz Alzamil

Author

Abdulaziz Alzamil

Founder & CEO, Fyntralink

Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.

  • Cybersecurity
  • Vulnerabilities & threats
  • NCA Essential Cybersecurity Controls (ECC)
  • Personal Data Protection Law (PDPL)
  • SAMA Cyber Security Framework
  • AI governance
  • Software engineering

400 articles

Vulnerabilities

April 2026 Patch Tuesday: The Wormable Windows TCP/IP Flaw (CVE-2026-33827) Saudi Financial Teams Cannot Delay

Microsoft's second-largest Patch Tuesday ever drops 168 fixes, including a wormable TCP/IP RCE (CVSS 9.8) and an Active Directory flaw targeting every Windows Server from 2012 R2 to 2025. Here's what Saudi financial CISOs must patch first and why.

16 Apr 2026 5 min
Vulnerabilities

Cisco Patches Four Critical Flaws (CVSS 9.9) in ISE and Webex — Saudi Financial Networks Face Immediate NAC and Collaboration Risk

Cisco has disclosed four critical vulnerabilities — CVSS scores reaching 9.9 — in Identity Services Engine and Webex. For Saudi financial institutions running Cisco ISE as their NAC backbone, these flaws represent a direct path to full network compromise and unauthorized user impersonation.

16 Apr 2026 5 min
Phishing & Fraud

AI-Generated Phishing Is Now the #1 Email Threat of 2026 — A Tactical Response Guide for Saudi Financial CISOs

AI-generated phishing attacks have surged 1,265% since 2023 and now account for 82% of all phishing emails. For Saudi financial institutions under SAMA and NCA oversight, the stakes — and the compliance obligations — have never been higher.

16 Apr 2026 6 min
Compliance & Regulation

Booking.com Breach Forces Global PIN Resets — Third-Party Platform Risk Is Now a SAMA Compliance Issue for Saudi Financial Institutions

Booking.com confirmed hackers accessed customer reservation data on April 13, 2026. Saudi financial CISOs must review third-party risk registers, PDPL obligations, and phishing defences immediately.

16 Apr 2026 5 min
Vulnerabilities

EngageLab SDK Intent Redirection Flaw Exposed 50 Million Android Users — A Third-Party SDK Risk Alarm for Saudi Financial Mobile Apps

Microsoft uncovered an intent redirection vulnerability in EngageLab SDK that silently put 50 million Android users — including 30 million cryptocurrency wallet installs — at risk of private key theft. Saudi financial institutions relying on third-party mobile SDKs need to act now.

16 Apr 2026 6 min
Breaches & Data Leaks

North Korean Hackers Drain $285M from Drift Protocol in 12 Minutes: What Saudi Financial Institutions Must Know

North Korean hackers drained $285M from Drift Protocol in just 12 minutes on April 1, 2026 using fake CVT tokens as collateral. Saudi CISOs must understand what this means for digital asset risk under SAMA's evolving framework.

16 Apr 2026 5 min
Breaches & Data Leaks

ShinyHunters Breach Rockstar via Anodot: Saudi CISO Third-Party Alert

ShinyHunters extracted 78M records from Rockstar via Anodot, a third-party analytics vendor. SAMA CSCC mandates strict third-party risk controls — is your institution compliant?

16 Apr 2026 4 min
Vulnerabilities

CVE-2026-5281: Chrome's Fourth Zero-Day of 2026 Targets WebGPU — Every Saudi Financial Institution's Browser Is at Risk

Google's fourth Chrome zero-day of 2026 exploits Dawn's WebGPU layer to escape the browser sandbox. Every unpatched Chromium-based browser in your environment is a live threat vector.

16 Apr 2026 5 min
Vulnerabilities

CVE-2026-34621: Adobe Acrobat Zero-Day Exploited Since November 2025 — A Wake-Up Call for Saudi Financial PDF Workflows

Adobe's emergency patch for CVE-2026-34621 revealed five months of silent exploitation inside your PDF reader. For Saudi banks and financial institutions that live and breathe PDF documents, the risk is immediate and regulatory implications are real.

16 Apr 2026 6 min
Supply Chain & Third Party

Axios npm Supply Chain Attack by UNC1069: Saudi Financial DevOps Alert

UNC1069 compromised Axios npm with the WAVESHAPER.V2 backdoor, exposing over 100M weekly downloads. Saudi financial institutions must audit dependency trees and CI/CD pipelines immediately.

16 Apr 2026 6 min
Vulnerabilities

Critical FortiSandbox Flaws CVE-2026-39808 & CVE-2026-39813: Unauthenticated RCE That Saudi Financial Teams Cannot Afford to Miss

Fortinet disclosed two CVSS 9.1 vulnerabilities in FortiSandbox on April 15, 2026 — CVE-2026-39808 and CVE-2026-39813 — enabling unauthenticated code execution and privilege escalation. Saudi banks relying on FortiSandbox for SAMA CSCC-mandated malware detection must patch now.

16 Apr 2026 5 min
Vulnerabilities

Microsoft April 2026 Patch Tuesday: CVE-2026-33824 Windows IKE CVSS 9.8 Demands Immediate Action from Saudi Financial Institutions

167 vulnerabilities patched in one update cycle — including a CVSS 9.8 unauthenticated RCE in Windows IKE. Here's exactly what SAMA-regulated institutions must prioritize before this week ends.

15 Apr 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality