Announcements

TrueConf Server: TrueConf Server Missing Authentication for Critical Function Vulnerability

  • 21st August 2026
A security vulnerability has been found in TrueConf Server, a collaboration and video conferencing platform that some hosting clients may use. The flaw involves a high-risk core function of the server that does not require proper authentication to access.This gap means an unauthorized person who can connect to the server’s 4307/TCP network port ...
Continue reading

TrueConf Server: TrueConf Server Code Injection Vulnerability

  • 21st August 2026
A code injection security flaw has been found in TrueConf Server, a video conferencing tool that some users may run on their hosting accounts. This vulnerability could let an unauthorized remote attacker who is able to reach the server's 4307/TCP network port use a specially crafted script to break out of the tool's isolated protected environment, ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 21st August 2026
On July 20, 2026, a MyCERT advisory was released addressing newly reported exploitation attempts targeting Microsoft SharePoint, a common platform many organizations use for file sharing, team collaboration, and internal content management. The advisory outlines recommended security hardening measures designed to reduce the risk of compromise from ...
Continue reading

MA-1472.072026: MyCERT Advisory - Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

  • 21st August 2026
On July 22, 2026, a security advisory was issued for a vulnerability affecting Microsoft Active Directory Federation Services (ADFS). The issue is classified as insufficient granularity of access control, meaning the service’s access restriction settings are not fine-grained enough to properly block unauthorized users from accessing specific ...
Continue reading