Announcements

N-able N-central: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

  • 6th August 2026
We are notifying clients of a security vulnerability discovered in the N-able N-central platform, a tool some users rely on to manage systems and hosting-related services. The flaw is an authentication bypass issue: there is an unapproved, unsecured access route that lets people skip the standard username and password login process entirely to get ...
Continue reading

JetBrains TeamCity: JetBrains TeamCity Deserialization of Untrusted Data Vulnerability

  • 6th August 2026
A security vulnerability has been identified in JetBrains TeamCity, a tool many development and website teams use to automate building, testing, and deploying their digital projects. The flaw is a deserialization of untrusted data issue, meaning the software does not safely process data it receives via its agent polling protocol, a feature used to ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 6th August 2026
MyCERT, Malaysia’s national cybersecurity emergency response team, issued an advisory on 20 July 2026 covering Microsoft SharePoint, a popular platform used for building websites, internal collaboration tools, and document storage systems. The advisory confirms that new methods to exploit vulnerabilities in SharePoint have been identified in ...
Continue reading

MA-1472.072026: MyCERT Advisory - Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

  • 6th August 2026
On July 22, 2026, cybersecurity advisory body MyCERT released a notice for a vulnerability affecting Microsoft Active Directory Federation Services (AD FS), a tool many organizations use to manage user logins and access to web-based services and internal applications. The flaw is classified as insufficient granularity of access control. In simple ...
Continue reading