Author
Abdulaziz Alzamil
Founder & CEO, Fyntralink
Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.
400 articles
CVE-2026-23918: Apache HTTP/2 Double-Free Flaw Enables Remote Code Execution on Millions of Servers
A critical double-free vulnerability in Apache HTTP Server 2.4.66's HTTP/2 module lets attackers crash workers or achieve full RCE — and millions of internet-facing servers remain unpatched.
VulnerabilitiesGoogle Confirms First AI-Written Zero-Day Exploit: 2FA Bypass Weaponized for Mass Exploitation
Google GTIG confirms the first AI-written zero-day exploit bypassing 2FA on a widely used admin tool. Learn what this means for Saudi financial institutions and how to defend against AI-accelerated threats.
VulnerabilitiesFunnelKit WooCommerce Checkout Skimmer: How a Plugin Flaw Turns Online Stores Into Card-Harvesting Traps
Attackers exploit a flaw in FunnelKit's WooCommerce plugin to inject invisible payment skimmers on 40,000+ checkout pages. Learn how this impacts PCI-DSS compliance and what Saudi merchants must do now.
VulnerabilitiesOpenAI Daybreak: How AI-Powered Vulnerability Detection Changes the Game for Financial CISOs
OpenAI's Daybreak initiative uses GPT-5.5 to detect and patch vulnerabilities in minutes. Here's what Saudi financial CISOs need to know about AI-powered security operations.
Breaches & Data LeaksInstructure Pays ShinyHunters Ransom After 275M Canvas Records Stolen: SaaS Vendor Risk Lessons for Financial Institutions
Instructure paid ShinyHunters after 275M Canvas records were stolen in two breaches within one week. Critical SaaS vendor risk lessons for SAMA-regulated financial institutions.
VulnerabilitiesCVE-2026-32202: APT28 Exploits Zero-Click Windows Flaw to Steal Credentials Without User Interaction
An incomplete Microsoft patch left a zero-click credential theft vector wide open — and APT28 is already exploiting it. Here's what Saudi financial institutions need to do right now.
Malware & Threat ActorsMuddyWater's False Flag: Iranian APT Hides Espionage Behind Chaos Ransomware
Rapid7 unmasks MuddyWater's Chaos ransomware campaign as Iranian state espionage. Critical lessons for Saudi financial sector CISOs on detecting false-flag operations.
VulnerabilitiesCVE-2026-0073: Android Zero-Click RCE Lets Nearby Attackers Gain Shell Access Without User Interaction
Google patches a CVSS 9.8 zero-click RCE in Android's wireless ADB that lets nearby attackers gain full shell access — a direct threat to BYOD-enabled financial institutions.
RansomwareWhen Your Ransomware Negotiator Works for the Attackers: Insider Threat Lessons from the BlackCat Case
A ransomware negotiator secretly fed attackers his clients' confidential strategy—inflating a $25M payout. This case exposes a critical blind spot in third-party risk management for financial institutions.
RansomwareVishing and SSO Abuse: How Cybercrime Groups Are Executing Rapid SaaS Extortion in Minutes
Cybercrime groups like ShinyHunters are combining AI-powered vishing calls with SSO exploitation to breach SaaS environments in under 45 minutes. Learn how Saudi financial institutions can defend against this rapidly evolving threat.
Artificial IntelligenceCritical Microsoft 365 Copilot Vulnerabilities: AI Assistants Become Data Exfiltration Vectors
Three critical CVEs in Microsoft 365 Copilot allow unauthorized data disclosure through AI injection attacks. Saudi financial institutions face compounded SAMA CSCC and PDPL compliance risks as AI assistants bypass traditional DLP controls.
RansomwareEverest Ransomware Hits Two US Banks via Third-Party Vendor: A Wake-Up Call for Saudi Financial Sector Supply Chain Security
Everest ransomware breached two US banks through a single shared vendor, exposing 250K customer records. Here's what Saudi financial institutions must learn about third-party risk under SAMA CSCC.