Abdulaziz Alzamil

Author

Abdulaziz Alzamil

Founder & CEO, Fyntralink

Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.

  • Cybersecurity
  • Vulnerabilities & threats
  • NCA Essential Cybersecurity Controls (ECC)
  • Personal Data Protection Law (PDPL)
  • SAMA Cyber Security Framework
  • AI governance
  • Software engineering

400 articles

Supply Chain & Third Party

Fake Ledger Live on Apple's App Store Stole $9.5M in 7 Days — App Supply Chain Risk Is Now a Board-Level Issue for Saudi Financial Institutions

A fraudulent Ledger Live app slipped through Apple's review process and stole $9.5 million from 50+ victims in a single week. Here's what this means for your institution's third-party and app supply chain risk posture.

15 Apr 2026 5 min
Vulnerabilities

CVE-2026-35616: Fortinet FortiClient EMS Zero-Day Now Actively Exploited — Urgent Action Required for Saudi Financial Institutions

A CVSS 9.1 zero-day in Fortinet FortiClient EMS allows unauthenticated attackers to execute code on your endpoint management server — and exploitation has been recorded in the wild since March 31, 2026.

15 Apr 2026 6 min
Malware & Threat Actors

CPUID Supply Chain Attack: How STX RAT Hijacked CPU-Z and HWMonitor — A Warning for Saudi Financial IT Teams

On April 9–10, 2026, attackers hijacked CPUID's official download servers to distribute STX RAT via trojanized CPU-Z and HWMonitor installers. Here's what Saudi financial institutions need to know.

15 Apr 2026 6 min
Artificial Intelligence

Pushpaganda: AI-Generated Fake News in Google Discover Is Now Targeting Your Employees' Phones

HUMAN Security uncovered Pushpaganda — 240M poisoned ad requests exploiting Google Discover to deliver scareware via Android push notifications. Here's what every Saudi financial CISO must act on now.

15 Apr 2026 5 min
Phishing & Fraud

W3LL Phishing Marketplace Dismantled: How a $500 Kit Bypassed MFA at Scale — Lessons for Saudi Financial CISOs

FBI Atlanta and Indonesian National Police seized the W3LL phishing marketplace on April 10, 2026 — a platform that sold MFA-bypassing phishing kits for $500 and enabled over $20M in fraud across 17,000 victims. Here's what SAMA-regulated institutions must do now.

15 Apr 2026 5 min
Cloud & Identity

Scattered Spider Returns: AI-Powered Vishing and Azure AD Hijacking Now Target Saudi Financial Institutions

Scattered Spider has pivoted from retail and tech to financial institutions, deploying AI-powered voice phishing and Azure AD federation backdoors to bypass MFA. Saudi banks under SAMA supervision face immediate exposure — here is what your security team must do now.

15 Apr 2026 5 min
Vulnerabilities

SharePoint Zero-Day CVE-2026-32201: CISA KEV Alert Hits Saudi Banks

CISA's April 14 double-alert: a SharePoint zero-day (CVE-2026-32201) and a resurrected 2009 Office flaw prove old vulnerabilities never die. Saudi banks have a 13-day patch window — here's your action plan.

15 Apr 2026 6 min
Malware & Threat Actors

Adobe's BPO Backdoor: How 'Mr. Raccoon' Stole 13M Support Tickets — and What Saudi Financial Institutions Must Learn About Vendor Risk

A threat actor called "Mr. Raccoon" compromised an Indian BPO contractor via RAT malware, exfiltrating 13M Adobe support tickets, 15K employee records, and unpublished HackerOne vulnerability reports — a masterclass in third-party risk gone wrong.

15 Apr 2026 5 min
Vulnerabilities

CVE-2026-40261 & CVE-2026-40176: PHP Composer's Hidden Command Injection Risk — What Saudi Fintech Dev Teams Must Patch Now

Two command injection flaws in PHP Composer's Perforce VCS driver allow arbitrary code execution — no Perforce installation required. Saudi financial development teams still running Composer 2.0–2.9.5 are exposed right now.

15 Apr 2026 5 min
Vulnerabilities

CVE-2026-25075: The 15-Year strongSwan Flaw That Can Crash Saudi Banks' VPN With One Packet

A single malformed EAP-TTLS packet can crash strongSwan VPN servers across 15+ years of releases. Saudi banks relying on IPsec/IKEv2 tunnels for branch and remote-access connectivity must patch CVE-2026-25075 to avoid an unauthenticated denial-of-service that SAMA CSCC classifies as a critical availability risk.

15 Apr 2026 5 min
Breaches & Data Leaks

Booking.com Breach Fuels Spear-Phishing Against Saudi Bank Employees

Booking.com confirmed hackers accessed customer reservation data. Saudi bank employees are now prime spear-phishing targets — here's your SAMA CSCC-aligned response.

14 Apr 2026 5 min
Artificial Intelligence

Agentic AI: 2026's #1 Cyber Threat and What Saudi Banks Must Do Now

Autonomous AI agents can plan, adapt, and persist inside your environment indefinitely. With 80%+ of Saudi organizations racing to adopt AI tools, the attack surface is expanding faster than most defenses can keep up.

14 Apr 2026 6 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality