Author
Abdulaziz Alzamil
Founder & CEO, Fyntralink
Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.
400 articles
CVE-2026-40175: Axios Gets Hit Twice — North Korean Backdoor Then a 9.9 CVSS Flaw That Hands Attackers Your AWS Keys
Axios npm suffered a North Korean supply chain backdoor in March, then a 9.9 CVSS flaw a week later. Saudi open banking teams running Node.js on AWS need to act before threat actors chain both.
VulnerabilitiesCVE-2026-21643: Fortinet FortiClient EMS Pre-Auth SQL Injection — CISA's 72-Hour Deadline and What Saudi Financial CISOs Must Do Before April 16
CISA confirmed active exploitation of CVE-2026-21643, a CVSS 9.1 pre-auth SQL injection in FortiClient EMS 7.4.4, on April 13 — giving organizations just 72 hours to patch or mitigate. Saudi banks running multi-tenant Fortinet EMS deployments are directly in the crosshairs.
Reports & Trends29 Minutes to Lateral Movement: CrowdStrike's 2026 Threat Report and What It Demands from Saudi Financial SOCs
The average time for an attacker to move laterally after initial access is now just 29 minutes. CrowdStrike's 2026 Global Threat Report resets the benchmark — and SAMA-regulated SOCs must answer accordingly.
Malware & Threat ActorsCPUID Supply Chain Breach: How STX RAT Hijacked CPU-Z & HWMonitor — A Wake-Up Call for Saudi Data Centers
On April 9, 2026, attackers quietly replaced CPUID's legitimate CPU-Z and HWMonitor downloads with trojanized packages delivering STX RAT — a full-featured remote access trojan. If your data center team downloaded hardware monitoring tools that week, read this now.
VulnerabilitiesSeven in One Blow: CISA's April 13 KEV Update Targets Exchange, Fortinet & Adobe — Saudi Bank Patch Roadmap
CISA added 7 actively exploited vulnerabilities to its KEV catalog on April 13, 2026 — including Fortinet SQL injection, Adobe Acrobat prototype pollution, and Microsoft Exchange deserialization. Saudi financial institutions have until May 4 to comply.
VulnerabilitiesCVE-2026-39987: Marimo's Pre-Auth RCE Was Weaponized in Under 10 Hours — What Saudi AI Analytics Teams Must Do Now
A critical pre-authenticated RCE in Marimo (CVE-2026-39987, CVSS 9.3) was actively exploited just 9 hours 41 minutes after public disclosure — before any PoC existed. Saudi financial institutions using AI analytics pipelines must act immediately.
Compliance & RegulationMicrosoft Secure Boot Certificates Expire June 26: The 75-Day Countdown Saudi Bank CISOs Cannot Ignore
Microsoft's 2011-era Secure Boot certificates expire June 26, 2026 — and Windows Server won't update itself. Saudi financial institutions have 75 days to act before losing boot-level protection, BitLocker hardening, and SAMA CSCC compliance posture.
Breaches & Data LeaksMr. Raccoon's Adobe Breach: How One BPO Contractor Exposed 13M Support Tickets
A single malware-infected BPO contractor handed threat actor "Mr. Raccoon" 13 million Adobe support tickets. Here is what Saudi financial institutions relying on outsourced IT support must do right now.
VulnerabilitiesCVE-2026-3502: The TrueConf Flaw Saudi Banks Must Patch by April 16
CISA added CVE-2026-3502 to its KEV catalog on April 2. The TrueConf Client flaw allows attackers to hijack software updates and deploy the Havoc C2 framework — a critical risk for Saudi banks using TrueConf for communications.
VulnerabilitiesCVE-2026-35616: The Fortinet FortiClient EMS Zero-Day That CISA Just Added to Its Most-Wanted List
CISA added CVE-2026-35616 to its Known Exploited Vulnerabilities catalog on April 6, 2026. This CVSS-9.1 Fortinet FortiClient EMS flaw has been under active attack since March 31 — Saudi financial institutions must act before the window closes.
RansomwareStorm-1175 Deploys Medusa Ransomware in 24 Hours Using Zero-Days in GoAnywhere and SmarterMail
Microsoft's April 2026 alert: Storm-1175 weaponized zero-days in GoAnywhere MFT and SmarterMail to encrypt victim networks within 24 hours — a direct threat to Saudi financial institutions relying on MFT platforms for SAMA-regulated data transfers.
VulnerabilitiesReact2Shell (CVE-2025-55182): The CVSS-10 Flaw Silently Draining API Keys from Financial Web Apps
A CVSS-10 flaw in React Server Components has enabled threat actor UAT-10608 to silently harvest credentials from 766+ hosts. Saudi financial institutions running Next.js-based portals face immediate exposure.