Announcements

IBM Langflow: IBM Langflow Code Injection Vulnerability

  • 5th August 2026
A security flaw has been identified in IBM Langflow, a low-code tool commonly used to build and manage custom AI workflows. This is a code injection vulnerability: attackers do not need any login credentials or pre-authorized access to exploit the flaw on default Langflow deployments. If successfully exploited, an attacker can run any code they ...
Continue reading

Apache Tomcat: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

  • 5th August 2026
A security vulnerability has been found in Apache Tomcat. The flaw is a missing encryption of sensitive data issue, which means sensitive information processed by the platform is not secured as it should be.This vulnerability allows unauthorized parties to bypass the EncryptInterceptor, a built-in Tomcat security feature designed to protect ...
Continue reading

N-able N-central: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

  • 5th August 2026
A security vulnerability has been identified in N-able N-central, a tool many organizations and hosting providers use to remotely manage servers and IT infrastructure. The flaw is an authentication bypass that uses an alternate, unintended access path or channel, which could allow someone to access the N-central system without entering valid login ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 5th August 2026
On July 20, 2026, Malaysia’s national cybersecurity response team (MyCERT) published a security advisory alerting users to newly discovered active attacks targeting Microsoft SharePoint. SharePoint is a popular platform many organizations use to host collaborative team sites, share internal documents, and run business-facing content tools.These ...
Continue reading