Abdulaziz Alzamil

Author

Abdulaziz Alzamil

Founder & CEO, Fyntralink

Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.

  • Cybersecurity
  • Vulnerabilities & threats
  • NCA Essential Cybersecurity Controls (ECC)
  • Personal Data Protection Law (PDPL)
  • SAMA Cyber Security Framework
  • AI governance
  • Software engineering

400 articles

Vulnerabilities

CVE-2026-20182: Cisco SD-WAN Zero-Day Gives Attackers Full Admin Access Without Credentials

A CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN Controller is under active exploitation, letting attackers seize full admin control of enterprise network fabrics without any credentials.

16 May 2026 4 min
Vulnerabilities

CVE-2026-42897: Actively Exploited Exchange Server Zero-Day Demands Immediate Action

Microsoft confirms active exploitation of CVE-2026-42897 in on-premises Exchange Server. Learn how this OWA XSS zero-day impacts Saudi financial institutions and what immediate mitigations to apply.

16 May 2026 5 min
Vulnerabilities

NGINX Rift: 18-Year-Old Critical RCE Bug Hiding in Every Reverse Proxy

An 18-year-old heap buffer overflow in NGINX's rewrite module (CVE-2026-42945, CVSS 9.2) enables unauthenticated RCE on every unpatched reverse proxy. Here's what Saudi financial institutions must do now.

16 May 2026 5 min
Vulnerabilities

CVE-2026-32201: Unpatched SharePoint Servers Expose Saudi Financial Institutions to Unauthenticated Spoofing

CISA added CVE-2026-32201 to its KEV catalog, yet over 1,300 SharePoint servers remain exposed. For Saudi banks running SharePoint on-prem, the window to patch is closing fast.

16 May 2026 5 min
Vulnerabilities

CVE-2026-41096: Critical Windows DNS Client RCE Threatens Every Endpoint

CVE-2026-41096 scores CVSS 9.8—a heap overflow in Windows DNS Client allows unauthenticated RCE on every Windows machine via a single malicious DNS response. Here's what Saudi financial institutions must do now.

16 May 2026 4 min
Breaches & Data Leaks

The Vercel Breach: How One Forgotten OAuth Token Exposed an Entire Platform

A single employee's forgotten trial of an AI tool handed attackers the keys to Vercel's kingdom. Here's what Saudi financial institutions must learn about OAuth sprawl and shadow AI before it happens to them.

16 May 2026 6 min
Ransomware

Nitrogen Ransomware Hits Foxconn: Supply Chain Lessons for Saudi Financial Institutions

Nitrogen ransomware breached Foxconn, exfiltrating 8TB of confidential data from Apple, Google, and Intel projects. Here's what Saudi financial institutions must learn about supply chain risk under SAMA CSCC.

16 May 2026 5 min
Malware & Threat Actors

MuddyWater's False Flag: Iranian APT Hides Espionage Behind Chaos Ransomware via Microsoft Teams

Iranian state-sponsored group MuddyWater weaponized Microsoft Teams screen-sharing to steal credentials and bypass MFA, planting Chaos ransomware artifacts as a decoy to hide espionage targeting banks and critical infrastructure.

16 May 2026 5 min
Cloud & Identity

CalPhishing: How Hackers Steal M365 Sessions Through Outlook Calendar Invites

A new phishing technique called CalPhishing weaponizes Outlook calendar invites to bypass MFA and steal Microsoft 365 session tokens — with hundreds of organizations compromised daily. Here's what Saudi CISOs need to know.

16 May 2026 6 min
Software Engineering

Mini Shai-Hulud Supply Chain Worm Hits TanStack and Breaches OpenAI Through Trusted CI/CD Pipelines

A self-spreading worm hijacked TanStack's legitimate GitHub Actions pipeline, published malicious packages indistinguishable from real ones, and breached OpenAI — exposing fatal gaps in software supply chain security.

16 May 2026 5 min
Vulnerabilities

CVE-2026-40361: Zero-Click Outlook RCE Lets Attackers Compromise Executives by Simply Sending an Email

A critical zero-click use-after-free vulnerability in Microsoft Outlook lets attackers achieve remote code execution through the Preview Pane alone. Learn why Saudi financial institutions must patch CVE-2026-40361 immediately.

15 May 2026 5 min
Vulnerabilities

CVE-2026-32202: APT28 Exploits Zero-Click Windows Shell Flaw to Steal NTLM Credentials

Russian APT28 weaponizes an incomplete Windows Shell patch to silently harvest NTLM hashes — no clicks required. Here's what Saudi CISOs must do now.

15 May 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality