Announcements

Arista VeloCloud Orchestrator: Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

  • 29th July 2026
A security vulnerability has been identified in the Arista VeloCloud Orchestrator On-Prem platform. This flaw is a type of system weakness that could allow an outside, unauthorized attacker to send malicious commands to the underlying technology.If successfully exploited, the flaw could let the attacker access restricted internal features of the ...
Continue reading

Fortinet FortiOS: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

  • 29th July 2026
A security flaw has been discovered in Fortinet FortiOS, the software that runs many common network security devices. This vulnerability could let unauthorized people access sensitive information stored on affected devices.To exploit this flaw, an attacker would first need to have already compromised the device using a separate, unrelated security ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 29th July 2026
On July 20, 2026, cybersecurity authority MyCERT released an advisory warning of newly confirmed active exploits targeting Microsoft SharePoint. SharePoint is a widely used Microsoft tool that many businesses run on their web hosting to build internal team sites, share documents, and manage collaborative work processes.These active attacks target ...
Continue reading

MA-1472.072026: MyCERT Advisory - Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

  • 29th July 2026
A security advisory was published by MyCERT (Malaysia’s national cybersecurity emergency response team) on 22 July 2026 at 1:26 pm, regarding a vulnerability in Microsoft Active Directory Federation Services (AD FS). AD FS is a tool many organizations use to let users log in once to access multiple connected websites, online services, and ...
Continue reading