Author
Abdulaziz Alzamil
Founder & CEO, Fyntralink
Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.
400 articles
BlueHammer, RedSun, and UnDefend: Three Windows Defender Zero-Days Turn Your Endpoint Shield into an Attack Vector
Three zero-day exploits targeting Windows Defender surfaced within 13 days. BlueHammer is patched, but RedSun and UnDefend remain open — and threat actors are chaining all three in live intrusions against enterprise networks.
VulnerabilitiesMicrosoft May 2026 Patch Tuesday: Netlogon RCE Flaw CVE-2026-41089 Threatens Every Domain Controller
Microsoft patched 137 vulnerabilities in May 2026 — but one stands out: CVE-2026-41089 lets unauthenticated attackers execute code as SYSTEM on domain controllers via a single network request.
VulnerabilitiesCopy Fail CVE-2026-31431: 732 Bytes to Root on Every Linux Server in Your Financial Infrastructure
A nine-year-old Linux kernel flaw dubbed "Copy Fail" lets any unprivileged user escalate to root with a 732-byte script. Every major distribution since 2017 is affected — here's what Saudi financial institutions must do now.
VulnerabilitiesCVE-2026-3854: Critical GitHub RCE Flaw Exposed Millions of Repositories via Single Git Push
A single git push command was all it took to execute arbitrary code on GitHub's backend servers. CVE-2026-3854 exposed millions of public and private repositories — here's what Saudi financial institutions must do now.
VulnerabilitiesCVE-2026-41940: cPanel Zero-Day Auth Bypass Exposes 1.5M Hosting Servers to Root Takeover
A CVSS 9.8 zero-day in cPanel & WHM lets unauthenticated attackers gain root-level WHM access via CRLF injection — exploited in the wild since February 2026 across 1.5 million exposed servers.
Breaches & Data LeaksCushman & Wakefield Vishing Breach: How One Phone Call Exposed 500K Salesforce Records
A single vishing call gave ShinyHunters access to 500,000 Salesforce records at Cushman & Wakefield. Two ransomware groups now claim the data. Here's what went wrong and why Saudi institutions must act now.
Supply Chain & Third PartyMini Shai-Hulud Worm Hits TanStack and 170+ Packages: The Largest npm Supply Chain Attack of 2026
TeamPCP weaponized GitHub Actions OIDC tokens to publish 401 malicious package versions across TanStack, Mistral AI, and UiPath — stealing credentials from cloud providers, crypto wallets, and CI systems. Here's what happened and how to respond.
Software EngineeringRubyGems Shuts Down Signups After BufferZoneCorp Supply Chain Attack Hits CI/CD Pipelines
RubyGems suspended new registrations after hundreds of malicious sleeper packages drained AWS keys, SSH credentials, and GitHub tokens from CI/CD pipelines — a wake-up call for every organization running open-source dependencies.
VulnerabilitiesCritical n8n Workflow Automation Flaws CVE-2026-42231 & CVE-2026-42232: Chained Prototype Pollution to Full RCE
Two prototype pollution vulnerabilities in n8n can be chained for full remote code execution with a CVSS 9.4 score. If your organization uses workflow automation, here's what you need to do now.
Cloud & IdentityFortinet 2026 Threat Report: 389% Ransomware Surge, 1.7B Stolen Credentials, and What It Means for Saudi Finance
Fortinet's FortiGuard Labs confirms 7,831 ransomware victims in 2025 — a 389% spike — fueled by AI-assisted tools and 1.7 billion stolen credentials on the dark web. Saudi financial institutions face unique exposure.
VulnerabilitiesSAP S/4HANA and Commerce Cloud Hit with CVSS 9.6 Critical Flaws — Patch Now Before Attackers Move First
SAP released 15 security patches including two CVSS 9.6 critical flaws in S/4HANA and Commerce Cloud. Here's why Saudi banks and financial institutions running SAP must act within hours, not days.
VulnerabilitiesGoogle Confirms Hackers Used AI to Build a Zero-Day Exploit — What Saudi Financial Institutions Must Do Now
Google's Threat Intelligence Group confirmed that hackers used AI to find and exploit a zero-day vulnerability targeting a widely used admin tool. For SAMA-regulated institutions, this marks a turning point in threat modeling.