On 26 July 2026, Malaysia’s national cybersecurity agency (MyCERT) published an advisory alerting website owners to a recent rise in ransomware attacks targeting online platforms. Ransomware is a type of malicious software that locks access to your site, its stored data, or admin tools, and demands payment to restore control; a successful attack ...
Continue reading
A security flaw has been found in Apache HTTP Server, the common software that powers many websites including those hosted on our platform. The issue affects the mod_proxy component, which is designed to pass web requests between your site and its backend servers.
A specially crafted, malicious web request can trick this component into sending the ...
Continue reading
A security vulnerability has been discovered in the WooCommerce Social Login plugin for WordPress, impacting all versions up to and including 2.8.7.
The flaw affects the plugin's Apple sign-in functionality. It fails to properly confirm that login tokens sent from Apple are valid, and a private security check meant to protect the login flow is ...
Continue reading
A security vulnerability, tracked as CVE-2026-15964, has been discovered in the Single Sign On For TNG plugin for WordPress, impacting all versions up to and including version 2.0.0. This flaw allows anyone who is not logged into your website to reset the password for any WordPress account on the site, including administrator accounts, without ...
Continue reading