Announcements

TrueConf Server: TrueConf Server Missing Authentication for Critical Function Vulnerability

  • 23rd August 2026
A security flaw has been identified in TrueConf Server. The issue is a missing authentication check for a critical server function, meaning no valid login is required to access this sensitive feature. If you run TrueConf Server on your hosting account, an attacker with network access to your server’s 4307/TCP port could exploit this gap to run ...
Continue reading

TrueConf Server: TrueConf Server Code Injection Vulnerability

  • 23rd August 2026
A code injection vulnerability has been identified in TrueConf Server, a service some customers may run on their hosting accounts. This flaw poses a security risk for anyone using this software as part of their hosted setup.The vulnerability can be exploited by an unauthorized remote attacker who has network access to your server's 4307/TCP port. ...
Continue reading

Synacor Zimbra Collaboration Suite (ZCS): Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

  • 23rd August 2026
A security flaw has been identified in the Zimbra Collaboration Suite (ZCS), a popular tool used for email, calendar, and team collaboration features on many hosted websites. This flaw is classified as an operating system command injection vulnerability, a type of security gap that lets unauthorized users run commands on the computer system that ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 23rd August 2026
On 20 July 2026 at 9:43am, MyCERT released advisory MA-1471.072026 to address newly reported exploitation activity targeting Microsoft SharePoint. SharePoint is a popular tool many businesses use to store shared files, collaborate on team projects, and host internal worksites and workflows.The advisory includes official guidance for securing, or ...
Continue reading