Announcements

Microsoft Internet Key Exchange (IKE) Service Extensions: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

  • 21st August 2026
A security vulnerability has been identified in Microsoft's Internet Key Exchange (IKE) Service Extensions, a component used to set up secure, encrypted connections for networked systems and services. The flaw is categorized as a "double free" vulnerability, a type of memory error that can cause systems to crash or behave unexpectedly.If exploited ...
Continue reading

MLflow MLflow: MLflow Server-Side Request Forgery Vulnerability

  • 21st August 2026
A security flaw has been found in MLflow, a tool many hosting clients use to manage machine learning projects on their accounts. This is a server-side request forgery vulnerability, a type of issue that lets bad actors trick the MLflow software into sending requests to private, internal parts of your hosting environment or cloud metadata services ...
Continue reading

TrueConf Server: TrueConf Server Missing Authentication for Critical Function Vulnerability

  • 21st August 2026
A security vulnerability has been discovered in TrueConf Server, a platform commonly used for video conferencing and team communication. The flaw is caused by a missing authentication check for a critical, high-risk function of the software.This issue means that any unauthorized person who can connect to the service’s port 4307/TCP over a ...
Continue reading

TrueConf Server: TrueConf Server Code Injection Vulnerability

  • 21st August 2026
If you run TrueConf Server on your hosted account, a code injection security flaw has been found in the platform. This issue could allow an unauthorized remote attacker who can access port 4307/TCP on your server to send a specially crafted script that breaks out of the platform’s isolated security environment, and run unapproved code directly ...
Continue reading