A security vulnerability has been identified in Broadcom's VMware vCenter software, a platform used by many organizations to manage virtual server infrastructure. This is a path traversal flaw, a type of issue that lets an attacker bypass standard access controls for the system.If a threat actor has network access to your vCenter instance, they ...
Continue reading
A security vulnerability has been identified in Microsoft's Internet Key Exchange (IKE) Service Extensions, a Windows system component. The flaw is a memory handling error called a "double free" that disrupts the service's normal operation.If exploited by a remote attacker, this vulnerability could allow them to run unauthorized malicious code on ...
Continue reading
A security issue has been found in MLflow, a tool many users run on their hosting accounts to manage machine learning workflows for their websites or applications. This flaw is a server-side request forgery vulnerability, which lets bad actors manipulate the MLflow tool to send requests to internal systems or cloud metadata services that are ...
Continue reading
On July 20, 2026, cybersecurity agency MyCERT released a new security advisory for users of Microsoft SharePoint, a popular platform many businesses use to run team collaboration sites, store shared documents, and host internal resources.The advisory was issued after new active exploitation attempts were detected targeting unsecured SharePoint ...
Continue reading