Announcements

CVE-2026-16098 (matched: wordpress)

  • 18th August 2026
A security flaw has been identified in the ProSolution WP Client plugin for WordPress, affecting all versions up to and including 2.0.10. The vulnerability allows unauthenticated visitors (people who do not have login access to your WordPress dashboard) to upload files to your website.This is possible due to gaps in two key security safeguards for ...
Continue reading

Ray-Project Ray: Ray-Project Ray Code Injection Vulnerability

  • 18th August 2026
A security vulnerability has been identified in Ray, a development tool used by many people building applications and online services. This is a code injection flaw, which means an unauthorized attacker could potentially run harmful code on systems that use the tool, a risk referred to as remote code execution.The issue can be exploited when ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 18th August 2026
On July 20, 2026, Malaysia’s national cybersecurity agency MyCERT published an advisory addressing new active exploits targeting Microsoft SharePoint, a widely used platform for building internal team sites, sharing business documents, and managing team collaborative workflows. These newly identified exploits pose a risk to unsecured SharePoint ...
Continue reading

MA-1472.072026: MyCERT Advisory - Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

  • 18th August 2026
A new security advisory (reference MA-1472.072026) from MyCERT was published on 22 July 2026, detailing a vulnerability in Microsoft Active Directory Federation Services (ADFS). ADFS is a common tool used by organizations to manage user access to websites, internal tools, and cloud services, so this issue may be relevant if your business uses this ...
Continue reading