Announcements

Apache Tomcat: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

  • 4th August 2026
Apache Tomcat, a widely used tool that powers many websites and web-based applications, has a confirmed security vulnerability. This flaw is classified as missing encryption of sensitive data, meaning the software does not secure private information as intended.The vulnerability allows the EncryptInterceptor, a built-in feature designed to enforce ...
Continue reading

N-able N-central: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

  • 4th August 2026
A security vulnerability has been found in N-able N-central, a remote monitoring and management platform that some hosting clients use to manage their servers and IT infrastructure. The flaw is an authentication bypass, which means an attacker could access a N-able N-central account without a valid username and password by using an alternate, ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 4th August 2026
On July 20, 2026, Malaysia’s national cybersecurity agency MyCERT issued an advisory alerting users to new reported exploitations targeting Microsoft SharePoint. SharePoint is a widely used platform for building internal collaboration sites, document storage portals, and custom business web tools, so these threats pose a potential risk to any ...
Continue reading

MA-1472.072026: MyCERT Advisory - Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

  • 4th August 2026
MyCERT published security advisory MA-1472.072026 on 22 July 2026 at 1:26pm, detailing a vulnerability in Microsoft Active Directory Federation Services (AD FS). The flaw is classified as an insufficient granularity of access control issue, meaning the service’s built-in permission settings are not fine-tuned enough to properly block ...
Continue reading