Abdulaziz Alzamil

Author

Abdulaziz Alzamil

Founder & CEO, Fyntralink

Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.

  • Cybersecurity
  • Vulnerabilities & threats
  • NCA Essential Cybersecurity Controls (ECC)
  • Personal Data Protection Law (PDPL)
  • SAMA Cyber Security Framework
  • AI governance
  • Software engineering

400 articles

Vulnerabilities

Lesson 24: Vulnerability Analysis — From Discovery to Assessment

Hands-On Cybersecurity Path — Lesson 4 of 10. Master the vulnerability analysis lifecycle: from scanning and discovery to risk-based prioritization aligned with SAMA and NCA requirements.

1 Apr 2026 8 min
Vulnerabilities

CVE-2026-21643: FortiClient EMS SQL Injection Under Active Attack — Patch Before Attackers Steal Your Endpoint Inventory

A pre-auth SQL injection in FortiClient EMS 7.4.4 lets attackers dump admin credentials and endpoint policies with a single HTTP request. Exploitation began March 26 — here's what Saudi CISOs must do now.

1 Apr 2026 5 min
Guides & Lessons

Lesson 22: Reconnaissance — OSINT Techniques for Beginners

Path 3: Hands-On Cybersecurity — Lesson 2 of 10. Master OSINT reconnaissance techniques to map an organization's digital footprint before a penetration test.

1 Apr 2026 7 min
Network & Infrastructure

Citrix NetScaler CVE-2026-3055: CISA KEV-Listed Memory Leak Hitting Financial Gateways

CISA added CVE-2026-3055 to its Known Exploited Vulnerabilities catalog on March 30. Attackers are already harvesting credentials from unpatched NetScaler gateways — here's what Saudi financial CISOs must do before the April 2 deadline.

1 Apr 2026 6 min
Compliance & Regulation

Lesson 20: Building an Information Security Governance (GRC) Program from Scratch

Saudi Regulatory Compliance — Lesson 10 of 10. Build a complete GRC program from scratch, aligned with SAMA, NCA, and PDPL requirements for Saudi financial institutions.

1 Apr 2026 8 min
Malware & Threat Actors

Operation TrueChaos: How a Video Conferencing Zero-Day Turned Trusted Updates into Malware

A zero-day in TrueConf's update mechanism let attackers push malware to every connected endpoint. Here's what Operation TrueChaos means for SAMA-regulated institutions and how to harden your internal software supply chain.

1 Apr 2026 5 min
Compliance & Regulation

Lesson 18: Cybersecurity Maturity Assessment — How to Measure Your Current Posture

Path 2: Saudi Regulatory Compliance — Lesson 8 of 10. Learn practical methods to measure your cybersecurity maturity against SAMA CSCC and NCA ECC benchmarks.

1 Apr 2026 8 min
Vulnerabilities

Oracle Identity Manager CVE-2026-21992: Emergency RCE Patch Every Saudi Bank Must Apply Now

Oracle issues rare emergency patch for CVE-2026-21992 — a CVSS 9.8 pre-auth RCE flaw in Identity Manager. Saudi financial institutions using Oracle IAM must act immediately.

1 Apr 2026 4 min
Compliance & Regulation

Lesson 16: ISO 27001:2022 — Key Changes and a Practical Implementation Plan

Saudi Regulatory Compliance Path — Lesson 6 of 10. Master the ISO 27001:2022 transition: new control structure, Annex A changes, and a phased implementation roadmap for Saudi financial institutions.

1 Apr 2026 7 min
Supply Chain & Third Party

Axios npm Supply Chain Attack: RAT Deployed via 100M-Download Package

Attackers hijacked Axios — the most popular npm HTTP client with 100M+ weekly downloads — to deploy a self-destructing RAT. Here's what Saudi financial institutions must do immediately.

1 Apr 2026 5 min
Guides & Lessons

Lesson 14: Saudi Personal Data Protection Law (PDPL) — A Practical Guide

Path 2: Saudi Regulatory Compliance — Lesson 4 of 10. Master PDPL requirements, data subject rights, and build a practical compliance roadmap for your financial institution.

31 Mar 2026 8 min
Vulnerabilities

CVE-2026-33017: Langflow AI Pipeline RCE Exploited in 20 Hours — What CISOs Must Know

A critical code injection flaw in Langflow was weaponized within 20 hours of disclosure. If your organization runs AI workflow platforms, here's what you need to do immediately.

31 Mar 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality