Author
Abdulaziz Alzamil
Founder & CEO, Fyntralink
Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.
400 articles
North Korea Stole $285M in 12 Minutes: The DPRK Infiltration Playbook Every Saudi CISO Must Study
North Korean hackers UNC4736 spent six months posing as a legitimate trading firm before draining $285M in 12 minutes. Saudi CISOs must understand this playbook—it maps directly to SAMA CSCC third-party and insider-threat domains.
Cloud & IdentityFBI & CISA Alert: Russian Intelligence Is Hijacking WhatsApp Accounts — Saudi Banks Are a Prime Target
Russian state-sponsored actors are walking around end-to-end encryption by hijacking WhatsApp and Signal accounts directly. Saudi financial institutions — where WhatsApp is the de facto business communication channel — are acutely exposed.
Breaches & Data LeaksThe Lloyds API Glitch That Exposed 450,000 Banking Customers: What Saudi Banks Must Learn Now
On March 12, 2026, a single faulty API update at Lloyds Banking Group exposed the transaction data of 447,936 customers. For Saudi banks, this is not a distant cautionary tale — it is a blueprint of what happens when API security is treated as an afterthought.
RansomwareAkira Ransomware Claims 6 Victims in 96 Hours: A Saudi Financial Sector Alert
Akira ransomware escalated sharply in early April 2026, claiming six victims in under 96 hours including an insurance firm with 63GB of sensitive data stolen. Here is what Saudi financial institutions must do today.
Breaches & Data LeaksShinyHunters Breaches the European Commission: 350GB Exposed and What Saudi Banks Must Learn Now
ShinyHunters breached the European Commission's Europa.eu, exfiltrating 350GB including databases and contracts. Saudi financial institutions must act now on identity controls, data governance, and PDPL breach notification readiness.
Compliance & RegulationNCA's Tier 1 MSOC Licenses: What Saudi Banks Must Do Now
NCA has licensed six Tier 1 MSOC providers — SITE, Sirar by STC, Haboob, Cyberani, TCC, and SAMI-AEC. SAMA-regulated institutions must now align SOC operations with the NCA's new mandatory licensing framework.
Cloud & IdentityHow Social Engineering Hijacks Okta to Breach Every SaaS You Use
A single phone call compromised Hims & Hers' Okta SSO in Feb 2026, exposing 1.8M customer support tickets. Saudi banks using SSO face the same risk — here's how to defend.
RansomwareQilin Ransomware Turned One Compromised MSP Into a Gateway to 28 Financial Firms
One compromised MSP gave Qilin ransomware access to 28 financial firms in a single campaign. Saudi banks must audit their vendor security posture before history repeats itself in the Kingdom.
Malware & Threat ActorsSpyrtacus WhatsApp Clone: Italian Spyware Vendor Weaponized a Fake App to Surveil 200 Targets
Meta warned 200 users that a counterfeit WhatsApp app built by Italian surveillance firm Asigint had been silently harvesting their data. Here's what Saudi CISOs need to know about mobile spyware threats targeting financial institutions.
VulnerabilitiesTrueConf CVE-2026-3502: Video Conferencing Update Hijack Exploited by State-Sponsored Hackers
CISA flags TrueConf Client CVE-2026-3502 after Chinese-linked hackers weaponize its update mechanism. Saudi banks relying on video conferencing must audit software integrity controls immediately.
Software EngineeringTrivy Supply Chain Attack Breaches European Commission — Why Saudi Banks Must Audit Their DevSecOps Tools
A compromised build of Trivy — one of the most trusted open-source vulnerability scanners — gave TeamPCP a backdoor into the European Commission's AWS infrastructure. If your DevSecOps pipeline trusts open-source tools implicitly, your institution could be next.
VulnerabilitiesIvanti EPMM Zero-Days CVE-2026-1281 & CVE-2026-1340: Mass Exploitation Threatens Saudi Bank Mobile Fleets
Two chained Ivanti EPMM zero-days scored CVSS 9.8 are under mass exploitation, giving attackers unauthenticated remote code execution on MDM servers that manage thousands of corporate mobile devices — including those in Saudi financial institutions.