Announcements

Microsoft SharePoint: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

  • 22nd July 2026
We’re sharing a security notice related to Microsoft SharePoint, a common platform many organizations use for document management, team collaboration, and internal content hosting. The service has a known flaw where it improperly processes untrusted, unvetted data sent to it. If a bad actor successfully exploits this flaw, they can run ...
Continue reading

Check Point SmartConsole: Check Point SmartConsole Improper Authentication Vulnerability

  • 22nd July 2026
A security vulnerability has been identified in Check Point SmartConsole, a tool used to manage network security systems for websites and online services.This is an improper authentication flaw. It allows an unauthenticated remote attacker to obtain a valid login token for the SmartConsole application, which they can then use to access the tool ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 22nd July 2026
On July 20, 2026, Malaysia’s national cybersecurity agency MyCERT issued a security advisory for Microsoft SharePoint, following reports of new active exploitation attempts targeting the platform. SharePoint is a common tool used by organizations to host websites, share internal files, and manage collaborative work content. These newly observed ...
Continue reading

MA-1472.072026: MyCERT Advisory - Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

  • 22nd July 2026
On July 22, 2026, a security advisory was released identifying a vulnerability in Microsoft Active Directory Federation Services (ADFS). The issue stems from the service’s access control settings not having enough precise, fine-tuned options to properly restrict who can access specific functions and data within the platform.If your website uses ...
Continue reading