Announcements

MA-1479.072026: MyCERT Advisory - Recent Ransomware Activities Observed: Best Practices for Prevention and Mitigation

  • 2nd August 2026
On 26 July 2026, Malaysia’s national cybersecurity agency (MyCERT) published an advisory alerting website owners to a recent rise in ransomware attacks targeting online platforms. Ransomware is a type of malicious software that locks access to your site, its stored data, or admin tools, and demands payment to restore control; a successful attack ...
Continue reading

CVE-2021-40438 (matched: apache http server)

  • 2nd August 2026
A security flaw has been found in Apache HTTP Server, the common software that powers many websites including those hosted on our platform. The issue affects the mod_proxy component, which is designed to pass web requests between your site and its backend servers. A specially crafted, malicious web request can trick this component into sending the ...
Continue reading

CVE-2026-8457 (matched: wordpress)

  • 2nd August 2026
A security vulnerability has been discovered in the WooCommerce Social Login plugin for WordPress, impacting all versions up to and including 2.8.7. The flaw affects the plugin's Apple sign-in functionality. It fails to properly confirm that login tokens sent from Apple are valid, and a private security check meant to protect the login flow is ...
Continue reading

CVE-2026-15964 (matched: wordpress)

  • 2nd August 2026
A security vulnerability, tracked as CVE-2026-15964, has been discovered in the Single Sign On For TNG plugin for WordPress, impacting all versions up to and including version 2.0.0. This flaw allows anyone who is not logged into your website to reset the password for any WordPress account on the site, including administrator accounts, without ...
Continue reading