Announcements

IBM Langflow: IBM Langflow Code Injection Vulnerability

  • 4th August 2026
A security vulnerability has been identified in IBM Langflow, a tool for building workflows and applications that some hosting clients may run on their accounts. The flaw is a code injection issue, which allows unauthenticated attackers (people who do not have valid login credentials for your Langflow instance) to run their own custom code on ...
Continue reading

Apache Tomcat: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

  • 4th August 2026
Apache Tomcat, a widely used tool that powers many websites and web-based applications, has a confirmed security vulnerability. This flaw is classified as missing encryption of sensitive data, meaning the software does not secure private information as intended.The vulnerability allows the EncryptInterceptor, a built-in feature designed to enforce ...
Continue reading

N-able N-central: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

  • 4th August 2026
A security vulnerability has been found in N-able N-central, a remote monitoring and management platform that some hosting clients use to manage their servers and IT infrastructure. The flaw is an authentication bypass, which means an attacker could access a N-able N-central account without a valid username and password by using an alternate, ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 4th August 2026
On July 20, 2026, Malaysia’s national cybersecurity agency MyCERT issued an advisory alerting users to new reported exploitations targeting Microsoft SharePoint. SharePoint is a widely used platform for building internal collaboration sites, document storage portals, and custom business web tools, so these threats pose a potential risk to any ...
Continue reading