Announcements

WordPress Core: WordPress Core Interpretation Conflict Vulnerability

  • 22nd July 2026
A security flaw has been identified in WordPress Core, the base software that powers WordPress websites. This is an interpretation conflict vulnerability that could be exploited by attackers to carry out SQL injection attacks and gain remote control of your website. SQL injection attacks let bad actors access, modify, or delete data stored in your ...
Continue reading

WordPress Core: WordPress Core SQL Injection Vulnerability

  • 22nd July 2026
A security flaw has been found in WordPress core that can be triggered when a theme or plugin installed on your site passes unscreened, untrusted user input to a specific core setting. This is a SQL injection vulnerability, a type of flaw that allows bad actors to run unauthorized commands on your site’s internal database.When combined with a ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 22nd July 2026
On July 20, 2026, Malaysia’s national cybersecurity agency MyCERT issued advisory MA-1471.072026 to address newly reported exploitation activity targeting Microsoft SharePoint, a widely used platform many businesses rely on for team collaboration, document sharing, and internal workflow management.The advisory outlines recommended security ...
Continue reading

CVE-2026-48687 (matched: php)

  • 21st July 2026
A security vulnerability affects FastNetMon Community Edition versions 1.2.9 and earlier, specifically in its Juniper router integration plugin. The plugin’s logging function builds system commands using unvetted input that hasn't been checked for malicious content, which can be exploited to run unauthorized, arbitrary code on the server where ...
Continue reading