If you operate a WordPress site with the Mailgun for WordPress plugin installed, be aware that versions 2.2.0 and older contain a security vulnerability. This flaw allows people who do not have access to your WordPress admin login to send requests using your site’s private Mailgun API key, without your knowledge.Attackers could exploit this to ...
Continue reading
A security vulnerability has been identified in Zimbra Collaboration Suite (ZCS), the email and team collaboration platform used by many of our clients for their business communications and shared work tools.
This flaw is classified as an operating system command injection vulnerability. It creates a path for bad actors to trick the Zimbra system ...
Continue reading
On July 20, 2026, cybersecurity agency MyCERT released advisory MA-1471.072026 for Microsoft SharePoint, after confirming new active exploitation attempts are targeting the platform. If you run a Microsoft SharePoint site, internal workspace, or related tool as part of your hosted services, these ongoing attacks could put your stored content, user ...
Continue reading
On July 22, 2026, cybersecurity authority MyCERT published an advisory for a security vulnerability found in Microsoft Active Directory Federation Services, a Microsoft tool used to manage user access to services. The flaw is an insufficient granularity of access control issue, meaning the service’s access permission rules are not specific ...
Continue reading