Announcements

TrueConf Server: TrueConf Server Code Injection Vulnerability

  • 20th August 2026
A code injection vulnerability has been found in TrueConf Server. This flaw lets an unauthorized remote attacker with network access to the server's port 4307 send a specially crafted script to break out of the server's isolated security environment. If the flaw is exploited, the attacker can run any code they want on the server's host system. If ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 20th August 2026
A cybersecurity advisory from MyCERT (reference number MA-1471.072026) was published on 20 July 2026 at 9:43am. The advisory outlines recommended security hardening steps for Microsoft SharePoint, following confirmed new active exploits targeting the platform. For anyone using Microsoft SharePoint to run a public website or manage internal ...
Continue reading

MA-1472.072026: MyCERT Advisory - Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

  • 20th August 2026
On July 22, 2026, cybersecurity authority MyCERT released an advisory for a security vulnerability found in Microsoft Active Directory Federation Services (AD FS), a widely used tool that organizations rely on to manage user sign-ins and control access to apps, websites and other digital resources. The flaw stems from access controls that are not ...
Continue reading

MA-1473.072026: MyCERT Advisory - Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

  • 20th August 2026
A security advisory was released on July 22, 2026, covering a vulnerability in Microsoft SharePoint Server, a tool many organizations use for document sharing, team collaboration, and internal workflow management.The flaw is categorized as missing authentication for a critical server function. This means the function does not verify that users ...
Continue reading