Author
Abdulaziz Alzamil
Founder & CEO, Fyntralink
Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.
400 articles
CVE-2026-42897: Actively Exploited Exchange Server Zero-Day Hits On-Prem Email with No Patch Available
Microsoft confirms active exploitation of CVE-2026-42897 in Exchange Server OWA — no patch available yet. Here's what Saudi financial institutions must do now to protect their on-prem email infrastructure.
VulnerabilitiesGoogle Catches First AI-Generated Zero-Day Exploit: A New Era of Cyber Threats
Google detected the first confirmed AI-generated zero-day exploit — a 2FA bypass built by the OpenClaw model. Here's why Saudi CISOs need to rethink their threat models immediately.
VulnerabilitiesFragnesia CVE-2026-46300: Linux Kernel Root Exploit Threatens Every Server in Saudi Financial Infrastructure
A new Linux kernel vulnerability lets any unprivileged user gain root access in a single command. Saudi financial institutions running Linux-based core banking, SOC platforms, and API gateways face immediate risk.
VulnerabilitiesNGINX Rift CVE-2026-42945: An 18-Year-Old Zero-Click RCE Flaw Threatening Every API Gateway in Saudi Finance
A single HTTP request can give attackers full control of your NGINX server. CVE-2026-42945 has lurked in NGINX's rewrite module since 2008 — here's what Saudi financial institutions must do immediately.
VulnerabilitiesCVE-2026-40403: Win32K Graphics RCE Lets Attackers Gain Kernel Access Through a Single Malicious Image
A single malicious image or font file can hand attackers full kernel privileges on any unpatched Windows system. CVE-2026-40403 demands immediate action from every Saudi financial institution.
VulnerabilitiesCVE-2026-41940: cPanel Authentication Bypass Exposes 1.5M Hosting Servers to Full Root Takeover
A CRLF injection in cPanel & WHM session handling lets unauthenticated attackers promote themselves to root — bypassing passwords and 2FA entirely. With 1.5 million servers exposed, Saudi organizations must act now.
Network & InfrastructureCVE-2026-0300: Palo Alto PAN-OS Zero-Day Gives Attackers Root on Your Perimeter Firewall
A critical buffer overflow in Palo Alto PAN-OS User-ID Authentication Portal is being exploited in the wild—giving attackers root-level code execution on PA-Series and VM-Series firewalls without any credentials.
RansomwareEverest Ransomware Breaches TSYS and Two Major Banks Through a Single Vendor
The Everest ransomware group compromised a payment processor and two major US banks through a single third-party vendor — exposing 3.6 million records. Here's what Saudi financial institutions must do about third-party risk now.
Breaches & Data LeaksCanvas Breach: How ShinyHunters Stole 275 Million Education Records and What It Means for Saudi Data Protection
ShinyHunters stole 275 million records and 3.65TB of data from Instructure's Canvas LMS — the largest education breach in history. Here's what Saudi CISOs must learn about vendor risk and PDPL obligations.
VulnerabilitiesCVE-2026-23918: Apache HTTP/2 Double-Free Flaw Turns Two Frames into Full Server Takeover
A single TCP connection and two HTTP/2 frames can crash — or fully compromise — Apache web servers running mod_http2. CVE-2026-23918 scored 8.8 CVSS and demands immediate patching across Saudi financial infrastructure.
VulnerabilitiesDead.Letter CVE-2026-45185: Critical Exim RCE Threatens Every Mail Server in Your Financial Infrastructure
A single malformed TLS handshake can give attackers root access to your Exim mail server. CVE-2026-45185 scores 9.8 CVSS and requires no authentication — here's what SAMA-regulated institutions must do now.
VulnerabilitiesCritical SAP Commerce Cloud and S/4HANA Flaws CVE-2026-34263 & CVE-2026-34260: CVSS 9.6 Threats to Saudi ERP Infrastructure
SAP's May 2026 Patch Day fixes two critical CVSS 9.6 vulnerabilities — an unauthenticated RCE in Commerce Cloud and a SQL injection in S/4HANA. Here's why Saudi financial institutions running SAP must patch immediately.