Announcements

WordPress Core: WordPress Core Interpretation Conflict Vulnerability

  • 22nd July 2026
WordPress core, the foundational software that powers all standard WordPress websites, has a security flaw called an interpretation conflict vulnerability. This flaw stems from a mismatch in how the software processes certain types of input, which malicious actors can take advantage of.If exploited, this vulnerability could allow attackers to ...
Continue reading

WordPress Core: WordPress Core SQL Injection Vulnerability

  • 22nd July 2026
A security flaw has been identified in standard WordPress core software. This flaw can trigger a SQL injection attack if any plugin or theme installed on your site sends untrusted, unvetted data to a specific site parameter. SQL injection is a type of attack that lets bad actors access or tamper with the database your WordPress site uses to store ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 22nd July 2026
A cybersecurity advisory (ID MA-1471.072026) from Malaysia’s national incident response team MyCERT was published on 20 July 2026, warning that new active exploits targeting Microsoft SharePoint are currently being observed. The advisory recommends security hardening for SharePoint to address these new exploitation methods. If you use Microsoft ...
Continue reading

MA-1472.072026: MyCERT Advisory - Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

  • 22nd July 2026
On 22 July 2026, cybersecurity agency MyCERT published advisory MA-1472.072026 regarding a security vulnerability found in Microsoft Active Directory Federation Services (AD FS), a tool many organizations use to manage user login access to connected websites and online business tools. The issue stems from access control settings that are not ...
Continue reading