A security flaw has been found in the Single Sign On For TNG plugin for WordPress, impacting all versions of the plugin up to and including 2.0.0. This issue allows any person who visits your site (even if they do not have a user account for your WordPress site) to reset the password for any existing account on the site, including administrator ...
Continue reading
A security flaw has been found in the FormGent plugin for WordPress, affecting all versions up to and including 1.9.2. The issue is caused by a file management feature in the plugin that does not require any user authentication or permission checks to access. This lets unauthenticated attackers delete files stored in the FormGent plugin's upload ...
Continue reading
On July 20, 2026, Malaysia’s national cybersecurity response team (MyCERT) released a security advisory focused on strengthening, or “hardening,” Microsoft SharePoint following reports of new active exploitation attempts targeting the platform. SharePoint is a widely used tool for business collaboration, document storage, and internal team ...
Continue reading
On July 22, 2026, cybersecurity authority MyCERT released an advisory about a security flaw in Microsoft Active Directory Federation Services (AD FS), a tool many organizations use to manage user login access and permissions for connected websites, apps, and internal services.The flaw stems from insufficiently strict access control settings, which ...
Continue reading