Abdulaziz Alzamil

Author

Abdulaziz Alzamil

Founder & CEO, Fyntralink

Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.

  • Cybersecurity
  • Vulnerabilities & threats
  • NCA Essential Cybersecurity Controls (ECC)
  • Personal Data Protection Law (PDPL)
  • SAMA Cyber Security Framework
  • AI governance
  • Software engineering

400 articles

Malware & Threat Actors

CVE-2026-40175: Axios Gets Hit Twice — North Korean Backdoor Then a 9.9 CVSS Flaw That Hands Attackers Your AWS Keys

Axios npm suffered a North Korean supply chain backdoor in March, then a 9.9 CVSS flaw a week later. Saudi open banking teams running Node.js on AWS need to act before threat actors chain both.

14 Apr 2026 6 min
Vulnerabilities

CVE-2026-21643: Fortinet FortiClient EMS Pre-Auth SQL Injection — CISA's 72-Hour Deadline and What Saudi Financial CISOs Must Do Before April 16

CISA confirmed active exploitation of CVE-2026-21643, a CVSS 9.1 pre-auth SQL injection in FortiClient EMS 7.4.4, on April 13 — giving organizations just 72 hours to patch or mitigate. Saudi banks running multi-tenant Fortinet EMS deployments are directly in the crosshairs.

14 Apr 2026 6 min
Reports & Trends

29 Minutes to Lateral Movement: CrowdStrike's 2026 Threat Report and What It Demands from Saudi Financial SOCs

The average time for an attacker to move laterally after initial access is now just 29 minutes. CrowdStrike's 2026 Global Threat Report resets the benchmark — and SAMA-regulated SOCs must answer accordingly.

14 Apr 2026 5 min
Malware & Threat Actors

CPUID Supply Chain Breach: How STX RAT Hijacked CPU-Z & HWMonitor — A Wake-Up Call for Saudi Data Centers

On April 9, 2026, attackers quietly replaced CPUID's legitimate CPU-Z and HWMonitor downloads with trojanized packages delivering STX RAT — a full-featured remote access trojan. If your data center team downloaded hardware monitoring tools that week, read this now.

14 Apr 2026 5 min
Vulnerabilities

Seven in One Blow: CISA's April 13 KEV Update Targets Exchange, Fortinet & Adobe — Saudi Bank Patch Roadmap

CISA added 7 actively exploited vulnerabilities to its KEV catalog on April 13, 2026 — including Fortinet SQL injection, Adobe Acrobat prototype pollution, and Microsoft Exchange deserialization. Saudi financial institutions have until May 4 to comply.

14 Apr 2026 6 min
Vulnerabilities

CVE-2026-39987: Marimo's Pre-Auth RCE Was Weaponized in Under 10 Hours — What Saudi AI Analytics Teams Must Do Now

A critical pre-authenticated RCE in Marimo (CVE-2026-39987, CVSS 9.3) was actively exploited just 9 hours 41 minutes after public disclosure — before any PoC existed. Saudi financial institutions using AI analytics pipelines must act immediately.

12 Apr 2026 5 min
Compliance & Regulation

Microsoft Secure Boot Certificates Expire June 26: The 75-Day Countdown Saudi Bank CISOs Cannot Ignore

Microsoft's 2011-era Secure Boot certificates expire June 26, 2026 — and Windows Server won't update itself. Saudi financial institutions have 75 days to act before losing boot-level protection, BitLocker hardening, and SAMA CSCC compliance posture.

12 Apr 2026 6 min
Breaches & Data Leaks

Mr. Raccoon's Adobe Breach: How One BPO Contractor Exposed 13M Support Tickets

A single malware-infected BPO contractor handed threat actor "Mr. Raccoon" 13 million Adobe support tickets. Here is what Saudi financial institutions relying on outsourced IT support must do right now.

7 Apr 2026 6 min
Vulnerabilities

CVE-2026-3502: The TrueConf Flaw Saudi Banks Must Patch by April 16

CISA added CVE-2026-3502 to its KEV catalog on April 2. The TrueConf Client flaw allows attackers to hijack software updates and deploy the Havoc C2 framework — a critical risk for Saudi banks using TrueConf for communications.

7 Apr 2026 5 min
Vulnerabilities

CVE-2026-35616: The Fortinet FortiClient EMS Zero-Day That CISA Just Added to Its Most-Wanted List

CISA added CVE-2026-35616 to its Known Exploited Vulnerabilities catalog on April 6, 2026. This CVSS-9.1 Fortinet FortiClient EMS flaw has been under active attack since March 31 — Saudi financial institutions must act before the window closes.

7 Apr 2026 6 min
Ransomware

Storm-1175 Deploys Medusa Ransomware in 24 Hours Using Zero-Days in GoAnywhere and SmarterMail

Microsoft's April 2026 alert: Storm-1175 weaponized zero-days in GoAnywhere MFT and SmarterMail to encrypt victim networks within 24 hours — a direct threat to Saudi financial institutions relying on MFT platforms for SAMA-regulated data transfers.

7 Apr 2026 5 min
Vulnerabilities

React2Shell (CVE-2025-55182): The CVSS-10 Flaw Silently Draining API Keys from Financial Web Apps

A CVSS-10 flaw in React Server Components has enabled threat actor UAT-10608 to silently harvest credentials from 766+ hosts. Saudi financial institutions running Next.js-based portals face immediate exposure.

7 Apr 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality