Announcements

WordPress Core: WordPress Core SQL Injection Vulnerability

  • 23rd July 2026
A security flaw has been found in standard WordPress core software, the base system that powers all basic WordPress websites. This is a SQL injection vulnerability that can be triggered when a WordPress plugin or theme you have installed passes unvetted, untrusted user input to a specific core parameter.This vulnerability can be combined with a ...
Continue reading

Microsoft SharePoint: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

  • 23rd July 2026
A security vulnerability has been identified in Microsoft SharePoint, a popular platform for team collaboration and document management. The flaw is a deserialization of untrusted data issue, meaning the software fails to safely handle data from unvetted, external sources.If an unauthorized attacker can access your SharePoint instance over a ...
Continue reading

Check Point SmartConsole: Check Point SmartConsole Improper Authentication Vulnerability

  • 23rd July 2026
There is a security flaw in Check Point SmartConsole, a tool commonly used to manage network and security settings for systems and services. The flaw relates to how the tool verifies that users attempting to log in are authorized to access it.This issue could allow an unapproved person accessing the tool remotely, with no valid login credentials ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 23rd July 2026
On July 20, 2026, Malaysia’s national cybersecurity agency MyCERT released an advisory warning of new, active exploitation attempts targeting Microsoft SharePoint, the common platform many businesses use for internal file sharing, team collaboration, and client-facing portals. These active exploitation attempts can allow unauthorized parties to ...
Continue reading