Topic
Guides & Lessons
A series of practical lessons and guides in cybersecurity and AI — from fundamentals to practice.
43 articles in this topic
DragonForce Hits Conrad Capital: 74GB Breach Lessons for SAMA Banks
DragonForce ransomware breached US investment advisor Conrad Capital, exfiltrating 74.23GB and demanding negotiations within five days. We unpack the attack and what SAMA-regulated Saudi institutions must harden in CSCC controls today.
Breaches & Data LeaksShinyHunters Hits Ameriprise: 200GB SaaS Breach Lessons for SAMA Banks
ShinyHunters claimed 200GB of Ameriprise data, hitting nearly 48,000 customers via Salesforce and SharePoint. What SAMA-regulated Saudi banks must learn about SaaS supply chain risk and detection gaps.
RansomwareEverest Ransomware Hits Frost and Citizens: SAMA CSCC Lessons
Everest's April 2026 attacks on Frost Bank and Citizens Financial expose data-first extortion tactics SAMA-regulated banks must defend against now.
Compliance & RegulationTrellix Source Code Breach: SAMA CSCC TPRM Lessons for Saudi Banks
Trellix, a major endpoint security vendor used across Saudi banking, disclosed unauthorized access to a portion of its source code repository. Here is what SAMA-regulated institutions must do now under CSCC TPRM controls.
RansomwareDragonForce Hits Conrad Capital: SAMA TPRM Lessons for Saudi Banks
DragonForce ransomware claims 74.23 GB of stolen data from US investment firm Conrad Capital Management. The breach delivers an urgent SAMA CSCC and TPRM wake-up call for Saudi financial institutions.
Breaches & Data Leaks824,000 Customers Exposed: Marquis-SonicWall Lessons for Saudi Banks
An unpatched SonicWall firewall at a trusted banking vendor cascaded into an Akira ransomware breach affecting 80 banks and 824,000 customers. Saudi financial institutions face the same third-party exposure under SAMA CSCC.
Phishing & FraudW3LL Phishing Marketplace Dismantled: How a $500 Kit Bypassed MFA at Scale — Lessons for Saudi Financial CISOs
FBI Atlanta and Indonesian National Police seized the W3LL phishing marketplace on April 10, 2026 — a platform that sold MFA-bypassing phishing kits for $500 and enabled over $20M in fraud across 17,000 victims. Here's what SAMA-regulated institutions must do now.
Guides & LessonsLesson 48: Privileged Access Management (PAM) — Securing the Keys to Your Kingdom
Lesson 48 in Fyntralink's Advanced Cybersecurity series: Learn how to secure privileged accounts with PAM — vaulting, session management, and just-in-time access for SAMA-regulated institutions.
Guides & LessonsLesson 46: Insider Threat Management — Detecting and Preventing Internal Risks in Financial Institutions
Advanced Cybersecurity — Lesson 46 of the Fyntralink series. Build an insider threat program that satisfies SAMA and NCA requirements while protecting your institution from within.
Guides & LessonsLesson 44: Ransomware Defense and Recovery — A Practical Guide for Saudi Financial Institutions
Lesson 44 in our cybersecurity series: a practical guide to ransomware defense, incident response, and recovery for SAMA-regulated financial institutions.
Guides & LessonsLesson 42: Threat Intelligence — Building a Proactive Defense for Saudi Financial Institutions
Lesson 42 in the Fyntralink cybersecurity series. Learn to build a proactive Threat Intelligence program — from feeds and tools to SAMA compliance — for Saudi financial institutions.
Reports & TrendsLesson 40: The Future of Cybersecurity — Trends Shaping 2026-2030 for Saudi Financial Institutions
Security Leadership Path — Lesson 10 of 10. Discover the key cybersecurity trends that will define the next five years for Saudi financial institutions and how to prepare today.