Announcements

WordPress Core: WordPress Core SQL Injection Vulnerability

  • 22nd July 2026
A security flaw has been identified in standard WordPress core software. This flaw can trigger a SQL injection attack if any plugin or theme installed on your site sends untrusted, unvetted data to a specific site parameter. SQL injection is a type of attack that lets bad actors access or tamper with the database your WordPress site uses to store ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 22nd July 2026
A cybersecurity advisory (ID MA-1471.072026) from Malaysia’s national incident response team MyCERT was published on 20 July 2026, warning that new active exploits targeting Microsoft SharePoint are currently being observed. The advisory recommends security hardening for SharePoint to address these new exploitation methods. If you use Microsoft ...
Continue reading

MA-1472.072026: MyCERT Advisory - Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

  • 22nd July 2026
On 22 July 2026, cybersecurity agency MyCERT published advisory MA-1472.072026 regarding a security vulnerability found in Microsoft Active Directory Federation Services (AD FS), a tool many organizations use to manage user login access to connected websites and online business tools. The issue stems from access control settings that are not ...
Continue reading

MA-1473.072026: MyCERT Advisory - Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

  • 22nd July 2026
A security advisory published July 22, 2026 identifies a vulnerability in Microsoft SharePoint Server, where a critical function of the software is missing required authentication checks. This means an attacker would not need valid login credentials to access this unprotected critical function. For customers running SharePoint Server, this could ...
Continue reading