Author
Abdulaziz Alzamil
Founder & CEO, Fyntralink
Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.
400 articles
Lesson 12: SAMA Cyber Security Framework (CSCC) — Structure, Domains, and Requirements
Path 2: Saudi Regulatory Compliance — Lesson 2 of 10. A practical breakdown of the SAMA CSCC framework every compliance officer in Saudi finance needs to master.
VulnerabilitiesAPT28 Weaponizes MSHTML Zero-Day CVE-2026-21513: What Saudi Financial CISOs Must Do Now
Russia-linked APT28 exploited a critical MSHTML zero-day for weeks before Microsoft patched it. Saudi financial institutions running Windows infrastructure face direct exposure — here's the technical breakdown and remediation playbook.
Guides & LessonsLesson 10: Security Awareness — Building a Security Culture in Your Organization
Path 1 — Cybersecurity Fundamentals, Lesson 10 of 10. Build an effective security awareness program that transforms employees from your weakest link into your strongest defense layer.
VulnerabilitiesInterlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026-20131: Urgent Action for Financial Institutions
Interlock ransomware exploited a CVSS 10.0 Cisco Firewall Management Center zero-day for over a month before disclosure. Here's what Saudi financial institutions must do immediately.
Guides & LessonsLesson 8: Application Security — OWASP Top 10 Vulnerabilities
Path 1: Cybersecurity Fundamentals — Lesson 8 of 10. Master the OWASP Top 10 vulnerabilities and learn how to protect your organization's web applications from the most critical security risks.
VulnerabilitiesCisco SD-WAN Zero-Day CVE-2026-20127: A CVSS 10.0 Threat Hiding Since 2023
A maximum-severity authentication bypass in Cisco Catalyst SD-WAN has been silently exploited by threat actor UAT-8616 since 2023. With CISA mandating emergency remediation, Saudi financial institutions running SD-WAN must act immediately.
VulnerabilitiesCVE-2026-32746: A 32-Year-Old Telnetd Bug Now Threatens Saudi Financial Infrastructure
A 32-year-old buffer overflow in GNU InetUtils telnetd (CVE-2026-32746, CVSS 9.8) is now actively exploited — and it affects network appliances running inside Saudi financial networks. Here's what CISOs need to do today.
Network & InfrastructureLesson 6: Network Security — Firewalls and Intrusion Detection Systems
Cybersecurity Fundamentals – Lesson 6 of 10. Master firewalls, IDS/IPS, and network segmentation to defend your organization's perimeter and internal traffic.
Malware & Threat ActorsDeepLoad Malware: AI-Powered Credential Theft Targeting Financial Enterprises
A newly discovered malware loader called DeepLoad combines ClickFix social engineering with AI-assisted code obfuscation to steal browser credentials from enterprise networks — and it can reinfect clean hosts silently using WMI persistence.
Guides & LessonsLesson 4: Understanding Defense in Depth — A Layered Security Model
Path 1: Cybersecurity Fundamentals — Lesson 4 of 10. Master the Defense in Depth strategy and learn how to build multiple security layers that protect your organization even when one control fails.
VulnerabilitiesLangflow AI Exploited in 20 Hours: Why Saudi Financial Institutions Must Secure AI Pipelines
A critical unauthenticated RCE flaw in Langflow was weaponized within 20 hours of disclosure. Here's what SAMA-regulated institutions adopting AI must do immediately.
Guides & LessonsLesson 2: Types of Cyber Threats — From Phishing to Ransomware
Path 1: Cybersecurity Fundamentals — Lesson 2 of 10. Understand the threat landscape facing Saudi organizations and learn how to recognize and defend against the most dangerous attack types.