On 26 July 2026, Malaysia’s national cybersecurity agency MyCERT published an advisory noting recent observed ransomware activity, alongside recommended best practices for prevention and mitigation. Ransomware is a type of malicious software that locks access to important files and systems, with attackers typically demanding payment to restore ...
Continue reading
If your website uses MariaDB database software, there is a security issue that impacts specific versions when a feature called wsrep_notify_cmd is enabled. This flaw lets shell commands hidden in the name of a node that joins a MariaDB cluster run automatically on the server, which could be exploited by unauthorized users to take unwanted actions ...
Continue reading
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and ...
Continue reading
A security flaw has been found in AlanWeb SCADA software. The software fails to require proper authorization to access certain folders on systems where it is installed. This means unauthorized users could read every file stored in those folders, and even run some of the files, including PHP scripts linked to the system's connected database.This ...
Continue reading