Abdulaziz Alzamil

Author

Abdulaziz Alzamil

Founder & CEO, Fyntralink

Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.

  • Cybersecurity
  • Vulnerabilities & threats
  • NCA Essential Cybersecurity Controls (ECC)
  • Personal Data Protection Law (PDPL)
  • SAMA Cyber Security Framework
  • AI governance
  • Software engineering

400 articles

Vulnerabilities

CVE-2026-23918: Apache HTTP/2 Double-Free Flaw Enables Remote Code Execution on Millions of Servers

A critical double-free vulnerability in Apache HTTP Server 2.4.66's HTTP/2 module lets attackers crash workers or achieve full RCE — and millions of internet-facing servers remain unpatched.

17 May 2026 5 min
Vulnerabilities

Google Confirms First AI-Written Zero-Day Exploit: 2FA Bypass Weaponized for Mass Exploitation

Google GTIG confirms the first AI-written zero-day exploit bypassing 2FA on a widely used admin tool. Learn what this means for Saudi financial institutions and how to defend against AI-accelerated threats.

17 May 2026 5 min
Vulnerabilities

FunnelKit WooCommerce Checkout Skimmer: How a Plugin Flaw Turns Online Stores Into Card-Harvesting Traps

Attackers exploit a flaw in FunnelKit's WooCommerce plugin to inject invisible payment skimmers on 40,000+ checkout pages. Learn how this impacts PCI-DSS compliance and what Saudi merchants must do now.

17 May 2026 5 min
Vulnerabilities

OpenAI Daybreak: How AI-Powered Vulnerability Detection Changes the Game for Financial CISOs

OpenAI's Daybreak initiative uses GPT-5.5 to detect and patch vulnerabilities in minutes. Here's what Saudi financial CISOs need to know about AI-powered security operations.

17 May 2026 4 min
Breaches & Data Leaks

Instructure Pays ShinyHunters Ransom After 275M Canvas Records Stolen: SaaS Vendor Risk Lessons for Financial Institutions

Instructure paid ShinyHunters after 275M Canvas records were stolen in two breaches within one week. Critical SaaS vendor risk lessons for SAMA-regulated financial institutions.

17 May 2026 6 min
Vulnerabilities

CVE-2026-32202: APT28 Exploits Zero-Click Windows Flaw to Steal Credentials Without User Interaction

An incomplete Microsoft patch left a zero-click credential theft vector wide open — and APT28 is already exploiting it. Here's what Saudi financial institutions need to do right now.

17 May 2026 6 min
Malware & Threat Actors

MuddyWater's False Flag: Iranian APT Hides Espionage Behind Chaos Ransomware

Rapid7 unmasks MuddyWater's Chaos ransomware campaign as Iranian state espionage. Critical lessons for Saudi financial sector CISOs on detecting false-flag operations.

17 May 2026 5 min
Vulnerabilities

CVE-2026-0073: Android Zero-Click RCE Lets Nearby Attackers Gain Shell Access Without User Interaction

Google patches a CVSS 9.8 zero-click RCE in Android's wireless ADB that lets nearby attackers gain full shell access — a direct threat to BYOD-enabled financial institutions.

17 May 2026 4 min
Ransomware

When Your Ransomware Negotiator Works for the Attackers: Insider Threat Lessons from the BlackCat Case

A ransomware negotiator secretly fed attackers his clients' confidential strategy—inflating a $25M payout. This case exposes a critical blind spot in third-party risk management for financial institutions.

17 May 2026 5 min
Ransomware

Vishing and SSO Abuse: How Cybercrime Groups Are Executing Rapid SaaS Extortion in Minutes

Cybercrime groups like ShinyHunters are combining AI-powered vishing calls with SSO exploitation to breach SaaS environments in under 45 minutes. Learn how Saudi financial institutions can defend against this rapidly evolving threat.

17 May 2026 5 min
Artificial Intelligence

Critical Microsoft 365 Copilot Vulnerabilities: AI Assistants Become Data Exfiltration Vectors

Three critical CVEs in Microsoft 365 Copilot allow unauthorized data disclosure through AI injection attacks. Saudi financial institutions face compounded SAMA CSCC and PDPL compliance risks as AI assistants bypass traditional DLP controls.

17 May 2026 4 min
Ransomware

Everest Ransomware Hits Two US Banks via Third-Party Vendor: A Wake-Up Call for Saudi Financial Sector Supply Chain Security

Everest ransomware breached two US banks through a single shared vendor, exposing 250K customer records. Here's what Saudi financial institutions must learn about third-party risk under SAMA CSCC.

16 May 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality