Announcements

WordPress Core: WordPress Core SQL Injection Vulnerability

  • 23rd July 2026
A security flaw has been identified in core WordPress software. This is a SQL injection vulnerability, which occurs when a plugin or theme installed on your WordPress site passes untrusted, unvetted input to a specific parameter built into WordPress core.This flaw can be combined with a separate, known security issue to allow attackers who do not ...
Continue reading

Microsoft SharePoint: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

  • 23rd July 2026
A security vulnerability has been identified in Microsoft SharePoint, a popular platform used to build team collaboration sites, file sharing hubs, and internal company portals. The flaw stems from how SharePoint processes data from untrusted external sources. When exploited, it can allow unauthorized attackers to run harmful code on your network ...
Continue reading

Check Point SmartConsole: Check Point SmartConsole Improper Authentication Vulnerability

  • 23rd July 2026
A security flaw has been identified in Check Point SmartConsole, a tool commonly used to manage network and security settings for connected systems. The issue is an improper authentication vulnerability, meaning the tool fails to properly confirm that a user attempting to log in has valid, authorized access.Because of this weakness, an ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 23rd July 2026
On July 20, 2026, Malaysia’s national cybersecurity emergency response team (MyCERT) released a public security advisory warning of newly observed active attacks targeting Microsoft SharePoint, and is recommending security hardening measures for the platform. Microsoft SharePoint is a widely used web-based tool that many organizations rely on to ...
Continue reading