Abdulaziz Alzamil

Author

Abdulaziz Alzamil

Founder & CEO, Fyntralink

Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.

  • Cybersecurity
  • Vulnerabilities & threats
  • NCA Essential Cybersecurity Controls (ECC)
  • Personal Data Protection Law (PDPL)
  • SAMA Cyber Security Framework
  • AI governance
  • Software engineering

400 articles

Compliance & Regulation

Lesson 36: Third-Party Risk Management — Securing Your Vendor Ecosystem

Security Leadership Path — Lesson 6 of 10. Build a robust Third-Party Risk Management program that satisfies SAMA CSCC and NCA ECC requirements while protecting your organization from vendor-introduced threats.

3 Apr 2026 8 min
Vulnerabilities

Oracle Identity Manager CVE-2026-21992: Pre-Auth RCE Threatens Saudi Financial IAM Systems

Oracle issued an emergency out-of-band patch for CVE-2026-21992, a CVSS 9.8 pre-authentication RCE flaw in Identity Manager. Saudi banks running Oracle Fusion Middleware face immediate risk.

3 Apr 2026 5 min
Guides & Lessons

Lesson 34: Building a Cybersecurity Team — Hiring and Development

Security Leadership Path — Lesson 4 of 10. A practical guide to recruiting, structuring, and developing a cybersecurity team that meets SAMA CSCC staffing requirements and protects your organization.

1 Apr 2026 8 min
Vulnerabilities

CVE-2026-25075: 15-Year strongSwan VPN Flaw Threatens Saudi Financial Remote Access

A critical integer underflow in strongSwan's EAP-TTLS plugin lets unauthenticated attackers crash VPN gateways. With 15 years of affected versions, Saudi financial institutions must patch immediately to protect remote access infrastructure.

1 Apr 2026 6 min
Guides & Lessons

Lesson 32: Building an Effective Cybersecurity Strategy for Saudi Financial Institutions

Security Leadership Path — Lesson 2 of 10. A step-by-step guide to building a cybersecurity strategy that satisfies regulators, protects the business, and earns board-level support.

1 Apr 2026 8 min
Vulnerabilities

CVE-2026-32746: 32-Year-Old Telnetd Bug Gives Attackers Root Access — Why Saudi Financial Infrastructure Must Act Now

A 32-year-old buffer overflow in GNU telnetd now carries a CVSS 9.8 score and threatens every ICS, OT, and legacy network device still running Telnet on port 23 — including infrastructure inside Saudi financial institutions.

1 Apr 2026 5 min
Guides & Lessons

Lesson 30: Security Operations Center (SOC) — Building and Operating

Hands-On Cybersecurity Path — Lesson 10 of 10. A practical guide to designing, staffing, and running a SOC that meets Saudi regulatory expectations.

1 Apr 2026 9 min
Vulnerabilities

Chrome Zero-Day CVE-2026-5281: WebGPU Flaw Actively Exploited — What Saudi Financial Institutions Must Do Now

Google's fourth Chrome zero-day of 2026 is being exploited in the wild. CVE-2026-5281 targets the Dawn WebGPU engine and can lead to remote code execution — here's what SAMA-regulated organizations need to act on today.

1 Apr 2026 5 min
Cloud & Identity

Lesson 28: Cloud Security — Securing AWS, Azure, and GCP Environments

Hands-On Cybersecurity Path — Lesson 8 of 10. Master cloud security fundamentals across the three major providers and align your cloud posture with SAMA and NCA requirements.

1 Apr 2026 8 min
Supply Chain & Third Party

Trivy Supply Chain Attack CVE-2026-33634: When Your Security Scanner Becomes the Threat

Attackers compromised Aqua Security's Trivy scanner to harvest CI/CD secrets from thousands of pipelines. Here's what happened, who's behind it, and why Saudi financial institutions running Trivy must act immediately.

1 Apr 2026 5 min
Malware & Threat Actors

Lesson 26: Malware Analysis — Tools and Methodologies

Hands-On Cybersecurity Path — Lesson 6 of 10. Master the tools and methodologies used to dissect malicious software, from safe lab setup to behavioral analysis.

1 Apr 2026 8 min
Vulnerabilities

Cisco SD-WAN Zero-Day CVE-2026-20127: CVSS 10 Flaw Exploited Since 2023 Threatens Saudi Network Infrastructure

A CVSS 10.0 zero-day in Cisco Catalyst SD-WAN has been exploited since 2023 by threat actor UAT-8616. CISA mandated emergency patching. Here's what Saudi financial institutions need to do now.

1 Apr 2026 6 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality