Author
Abdulaziz Alzamil
Founder & CEO, Fyntralink
Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.
400 articles
Lesson 48: Privileged Access Management (PAM) — Securing the Keys to Your Kingdom
Lesson 48 in Fyntralink's Advanced Cybersecurity series: Learn how to secure privileged accounts with PAM — vaulting, session management, and just-in-time access for SAMA-regulated institutions.
VulnerabilitiesCisco IMC CVE-2026-20093: Critical 9.8 Auth Bypass Threatens Data Center Infrastructure
Cisco discloses CVE-2026-20093, a CVSS 9.8 authentication bypass in IMC affecting UCS servers. Saudi financial institutions must patch immediately — one HTTP request can hijack admin access to your data center hardware.
Guides & LessonsLesson 46: Insider Threat Management — Detecting and Preventing Internal Risks in Financial Institutions
Advanced Cybersecurity — Lesson 46 of the Fyntralink series. Build an insider threat program that satisfies SAMA and NCA requirements while protecting your institution from within.
VulnerabilitiesCritical Mbed TLS RCE Flaw CVE-2026-34877: ATMs, POS Terminals, and IoT at Risk
A CVSS 9.8 remote code execution flaw in Mbed TLS threatens the cryptographic backbone of ATMs, payment terminals, and embedded banking systems across Saudi Arabia's financial sector.
Guides & LessonsLesson 44: Ransomware Defense and Recovery — A Practical Guide for Saudi Financial Institutions
Lesson 44 in our cybersecurity series: a practical guide to ransomware defense, incident response, and recovery for SAMA-regulated financial institutions.
Breaches & Data LeaksShinyHunters Salesforce Campaign Hits 400+ Firms: What Saudi Banks Must Do Now
ShinyHunters has breached over 400 organizations through Salesforce Experience Cloud misconfigurations, stealing millions of records. Saudi financial institutions relying on Salesforce must act immediately to lock down guest user permissions and protect customer data.
Guides & LessonsLesson 42: Threat Intelligence — Building a Proactive Defense for Saudi Financial Institutions
Lesson 42 in the Fyntralink cybersecurity series. Learn to build a proactive Threat Intelligence program — from feeds and tools to SAMA compliance — for Saudi financial institutions.
Cloud & IdentityReact2Shell Exploits Breach 766 Hosts: Massive Credential Theft Campaign Targets Web Apps
A large-scale credential harvesting operation tracked as UAT-10608 is exploiting the React2Shell vulnerability to breach Next.js applications and steal AWS secrets, SSH keys, and database credentials at scale.
Reports & TrendsLesson 40: The Future of Cybersecurity — Trends Shaping 2026-2030 for Saudi Financial Institutions
Security Leadership Path — Lesson 10 of 10. Discover the key cybersecurity trends that will define the next five years for Saudi financial institutions and how to prepare today.
Malware & Threat ActorsOperation NoVoice: Android Rootkit on Google Play Threatens Mobile Banking Security
McAfee uncovers Operation NoVoice — a rootkit infecting 2.3M Android devices via Google Play that survives factory resets and clones WhatsApp sessions. Critical implications for Saudi financial institutions.
Compliance & RegulationLesson 38: AI in Cybersecurity — Opportunities and Risks for Saudi Financial Institutions
Security Leadership Path — Lesson 8 of 10. Explore how AI enhances threat detection, automates SOC operations, and introduces new risks that Saudi financial institutions must address under SAMA CSCC and NCA ECC.
Supply Chain & Third PartyAxios NPM Supply Chain Attack: North Korean Hackers Weaponize JavaScript's Most Popular HTTP Client
North Korean threat actors hijacked the Axios npm package — 100 million weekly downloads — to deploy a cross-platform RAT. Here's what Saudi financial institutions need to know and do right now.