Author
Abdulaziz Alzamil
Founder & CEO, Fyntralink
Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.
400 articles
CVE-2026-20182: Cisco SD-WAN Zero-Day Gives Attackers Full Admin Access Without Credentials
A CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN Controller is under active exploitation, letting attackers seize full admin control of enterprise network fabrics without any credentials.
VulnerabilitiesCVE-2026-42897: Actively Exploited Exchange Server Zero-Day Demands Immediate Action
Microsoft confirms active exploitation of CVE-2026-42897 in on-premises Exchange Server. Learn how this OWA XSS zero-day impacts Saudi financial institutions and what immediate mitigations to apply.
VulnerabilitiesNGINX Rift: 18-Year-Old Critical RCE Bug Hiding in Every Reverse Proxy
An 18-year-old heap buffer overflow in NGINX's rewrite module (CVE-2026-42945, CVSS 9.2) enables unauthenticated RCE on every unpatched reverse proxy. Here's what Saudi financial institutions must do now.
VulnerabilitiesCVE-2026-32201: Unpatched SharePoint Servers Expose Saudi Financial Institutions to Unauthenticated Spoofing
CISA added CVE-2026-32201 to its KEV catalog, yet over 1,300 SharePoint servers remain exposed. For Saudi banks running SharePoint on-prem, the window to patch is closing fast.
VulnerabilitiesCVE-2026-41096: Critical Windows DNS Client RCE Threatens Every Endpoint
CVE-2026-41096 scores CVSS 9.8—a heap overflow in Windows DNS Client allows unauthenticated RCE on every Windows machine via a single malicious DNS response. Here's what Saudi financial institutions must do now.
Breaches & Data LeaksThe Vercel Breach: How One Forgotten OAuth Token Exposed an Entire Platform
A single employee's forgotten trial of an AI tool handed attackers the keys to Vercel's kingdom. Here's what Saudi financial institutions must learn about OAuth sprawl and shadow AI before it happens to them.
RansomwareNitrogen Ransomware Hits Foxconn: Supply Chain Lessons for Saudi Financial Institutions
Nitrogen ransomware breached Foxconn, exfiltrating 8TB of confidential data from Apple, Google, and Intel projects. Here's what Saudi financial institutions must learn about supply chain risk under SAMA CSCC.
Malware & Threat ActorsMuddyWater's False Flag: Iranian APT Hides Espionage Behind Chaos Ransomware via Microsoft Teams
Iranian state-sponsored group MuddyWater weaponized Microsoft Teams screen-sharing to steal credentials and bypass MFA, planting Chaos ransomware artifacts as a decoy to hide espionage targeting banks and critical infrastructure.
Cloud & IdentityCalPhishing: How Hackers Steal M365 Sessions Through Outlook Calendar Invites
A new phishing technique called CalPhishing weaponizes Outlook calendar invites to bypass MFA and steal Microsoft 365 session tokens — with hundreds of organizations compromised daily. Here's what Saudi CISOs need to know.
Software EngineeringMini Shai-Hulud Supply Chain Worm Hits TanStack and Breaches OpenAI Through Trusted CI/CD Pipelines
A self-spreading worm hijacked TanStack's legitimate GitHub Actions pipeline, published malicious packages indistinguishable from real ones, and breached OpenAI — exposing fatal gaps in software supply chain security.
VulnerabilitiesCVE-2026-40361: Zero-Click Outlook RCE Lets Attackers Compromise Executives by Simply Sending an Email
A critical zero-click use-after-free vulnerability in Microsoft Outlook lets attackers achieve remote code execution through the Preview Pane alone. Learn why Saudi financial institutions must patch CVE-2026-40361 immediately.
VulnerabilitiesCVE-2026-32202: APT28 Exploits Zero-Click Windows Shell Flaw to Steal NTLM Credentials
Russian APT28 weaponizes an incomplete Windows Shell patch to silently harvest NTLM hashes — no clicks required. Here's what Saudi CISOs must do now.