Announcements

TrueConf Server: TrueConf Server Code Injection Vulnerability

  • 23rd August 2026
A code injection security flaw has been identified in TrueConf Server, a communication tool that some users run on their hosted servers. This type of vulnerability allows unauthorized parties to insert malicious, unapproved commands into the affected system.The flaw can be exploited by any remote attacker who has network access to port 4307/TCP, ...
Continue reading

Synacor Zimbra Collaboration Suite (ZCS): Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

  • 23rd August 2026
A security vulnerability has been identified in Zimbra Collaboration Suite (ZCS), the email and collaboration platform many of our clients use for team communication, contact storage, and shared file management. This is an OS command injection flaw, which means an attacker does not need a valid account on your Zimbra instance to exploit it: they ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 23rd August 2026
On July 20, 2026, Malaysia’s national cybersecurity response team MyCERT published an advisory responding to new, active attempts to exploit Microsoft SharePoint, a popular tool many businesses use for team collaboration, document sharing, and internal workflows that may be hosted on your web server. The advisory outlines recommended security ...
Continue reading

MA-1472.072026: MyCERT Advisory - Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

  • 23rd August 2026
Malaysia’s national cybersecurity agency (MyCERT) issued an advisory on July 22, 2026, identifying a security vulnerability in Microsoft Active Directory Federation Services (AD FS), a tool many organizations use to let users log in once to access multiple websites, apps and internal systems. The flaw stems from the service’s access control ...
Continue reading