Abdulaziz Alzamil

Author

Abdulaziz Alzamil

Founder & CEO, Fyntralink

Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.

  • Cybersecurity
  • Vulnerabilities & threats
  • NCA Essential Cybersecurity Controls (ECC)
  • Personal Data Protection Law (PDPL)
  • SAMA Cyber Security Framework
  • AI governance
  • Software engineering

400 articles

Breaches & Data Leaks

ShinyHunters Breach Instructure Canvas: 275 Million Records Expose Education Sector's Blind Spot

ShinyHunters breached Instructure's Canvas LMS twice in ten days, stealing 275 million records from 8,800+ institutions. Here's what went wrong and why Saudi organizations must reassess cloud vendor risk under PDPL.

12 May 2026 6 min
Vulnerabilities

CVE-2026-32202: APT28 Exploits Zero-Click Windows Flaw to Steal NTLM Credentials — CISA Deadline Hits Today

A zero-click Windows shortcut flaw lets APT28 steal NTLM credentials without user interaction. Microsoft's incomplete patch left millions exposed — and CISA's remediation deadline expires today.

12 May 2026 4 min
Vulnerabilities

BlueHammer, RedSun, UnDefend: Three Windows Defender Zero-Days That Turned Your Shield Into a Weapon

One researcher, three zero-days, 13 days. BlueHammer, RedSun, and UnDefend exploited Windows Defender's own remediation engine to escalate privileges to SYSTEM — and only one has been patched.

12 May 2026 5 min
Software Engineering

Checkmarx Jenkins Plugin Backdoored by TeamPCP: CI/CD Supply Chain Under Siege

A rogue version of the Checkmarx Jenkins AST plugin was uploaded to the Jenkins Marketplace, turning trusted security tooling into an infostealer. Here's what happened and why SAMA-regulated institutions must audit their pipelines immediately.

12 May 2026 5 min
Vulnerabilities

Ivanti EPMM Zero-Day CVE-2026-6973: RCE Hits Enterprise Mobile Management

Ivanti's Endpoint Manager Mobile zero-day CVE-2026-6973 is under active exploitation. Attackers chain stolen credentials with an input validation flaw to achieve full RCE on EPMM appliances managing thousands of corporate devices.

12 May 2026 5 min
Supply Chain & Third Party

TanStack NPM Supply Chain Attack CVE-2026-45321: Trusted Packages Weaponized to Steal Developer Secrets

A self-spreading worm hijacked TanStack's trusted CI/CD pipeline, publishing 84 malicious npm packages that exfiltrated GitHub tokens, SSH keys, and cloud credentials. CVSS 9.6 — here's what SAMA-regulated institutions need to check immediately.

12 May 2026 5 min
Vulnerabilities

Apache HTTP/2 Double-Free CVE-2026-23918: Two Frames, Zero Auth, Full RCE

A double-free in Apache mod_http2 lets attackers crash or take over servers with just two HTTP/2 frames and zero authentication. Here's what Saudi financial institutions need to do immediately.

12 May 2026 6 min
Cloud & Identity

Fake OpenAI Model on Hugging Face Steals Credentials: AI Supply Chain Risk for Financial Institutions

A fake OpenAI model on Hugging Face reached 244K downloads before removal, deploying a Rust infostealer that harvested browser credentials and SSH keys. Here's what Saudi financial institutions must do now.

12 May 2026 4 min
Vulnerabilities

FortiClient EMS Zero-Day CVE-2026-35616: Pre-Auth API Bypass Hits Endpoint Management at Scale

A critical pre-authentication API bypass in FortiClient EMS was exploited as a zero-day before Fortinet disclosed it. Here's what SAMA-regulated institutions must do now.

12 May 2026 5 min
Vulnerabilities

Bleeding Llama: Critical Ollama Flaw Leaks AI Server Memory to Unauthenticated Attackers

A critical out-of-bounds read in Ollama's GGUF loader lets attackers siphon API keys, user prompts, and credentials from 300,000+ exposed AI servers — no authentication required.

12 May 2026 6 min
Vulnerabilities

Google Confirms First AI-Generated Zero-Day Exploit by Criminal Hackers

Google's Threat Intelligence Group has confirmed the first-ever detection of a criminal zero-day exploit built with AI assistance — a milestone that reshapes the threat landscape for Saudi financial institutions.

12 May 2026 5 min
Breaches & Data Leaks

Trellix Source Code Breach: Why Your Security Vendor Could Be Your Biggest Risk

Trellix's source code repository was breached by RansomHouse. For SAMA-regulated banks running Trellix products, this supply chain risk event demands immediate third-party incident response.

11 May 2026 6 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality