Announcements

Broadcom VMware vCenter: Broadcom VMware vCenter Path Traversal Vulnerability

  • 20th August 2026
A security vulnerability has been identified in Broadcom's VMware vCenter software, a platform used by many organizations to manage virtual server infrastructure. This is a path traversal flaw, a type of issue that lets an attacker bypass standard access controls for the system.If a threat actor has network access to your vCenter instance, they ...
Continue reading

Microsoft Internet Key Exchange (IKE) Service Extensions: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

  • 20th August 2026
A security vulnerability has been identified in Microsoft's Internet Key Exchange (IKE) Service Extensions, a Windows system component. The flaw is a memory handling error called a "double free" that disrupts the service's normal operation.If exploited by a remote attacker, this vulnerability could allow them to run unauthorized malicious code on ...
Continue reading

MLflow MLflow: MLflow Server-Side Request Forgery Vulnerability

  • 20th August 2026
A security issue has been found in MLflow, a tool many users run on their hosting accounts to manage machine learning workflows for their websites or applications. This flaw is a server-side request forgery vulnerability, which lets bad actors manipulate the MLflow tool to send requests to internal systems or cloud metadata services that are ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 20th August 2026
On July 20, 2026, cybersecurity agency MyCERT released a new security advisory for users of Microsoft SharePoint, a popular platform many businesses use to run team collaboration sites, store shared documents, and host internal resources.The advisory was issued after new active exploitation attempts were detected targeting unsecured SharePoint ...
Continue reading