Alerts and Advisories
Alerts & Advisories
Critical Unauthenticated Remote Code Execution Vulnerability in Microsoft SharePoint Server CVE-2026-50522
24 Jul 2026
A critical security vulnerability (CVSS 3.1 score: 9.8) has been identified in on-premises deployments of Microsoft SharePoint Server. This vulnerability allows unauthenticated users to run malicious code on SharePoint servers to steal IIS machine keys which can be used to bypass all login screens and masquerade as administrators. This flaw is caused by the deserialization of untrusted data within SharePoint's core processing components, allowing a remote, unauthenticated attacker to execute malicious code on vulnerable systems.
Global Canvas LMS Data Breach
11 May 2026
A major cybersecurity incident has impacted Canvas Learning Management System (Canvas LMS), affecting thousands of educational institutions worldwide including institutions in Brunei Darussalam. The hacking group ShinyHunters has claimed responsibility for exfiltrating approximately 3.65TB of data, affecting nearly 9,000 educational institutions worldwide.
Critical Privilege Escalation Vulnerability in Zoom Clients for Windows (CVE-2025-49457)
14 Aug 2025
An untrusted search path vulnerability has been found in Zoom Clients for Windows operating system, allowing an unauthenticated attacker to escalate privileges via network access.
Microsoft SharePoint Zero-Day RCE Vulnerability (CVE-2025-53770)
21 Jul 2025
A critical remote code execution vulnerability, tracked as CVE-2025-53770, has been actively exploited in the wild. It targets on-premises Microsoft SharePoint Server deployments.
Phishing Attacks Leveraging Microsoft 365 Infrastructure
24 Mar 2025
A new phishing campaign, including Business Email Compromise (BEC), has been discovered using Microsoft 365’s legitimate infrastructure. It poses a significant threat to user credentials and account security, leading to credential theft, data breaches, financial fraud, and malware spread.
Critical Vulnerability on Synology Products CVE-2024-10441
20 Mar 2025
Synology has disclosed a critical security vulnerability affecting several of its products, including Synology BeeStation Manager (BSM), Synology DiskStation Manager (DSM), and Synology Unified Controller (DSMUC).
Critical Vulnerability in FortiSwitch CVE-2023-37936
17 Jan 2025
Another critical vulnerability addressed by Fortinet is CVE-2023-37936, a hard-coded cryptographic key in Fortinet FortiSwitch. This flaw allows a remote, unauthenticated attacker with access to the hard-coded key to execute unauthorized code via crafted cryptographic requests
Mirai Botnet Targeting Routers and Home Devices
17 Jan 2025
The Mirai botnet has returned, this time targeting vulnerabilities in industrial routers, smart home devices, and DVRs. It spreads using known flaws in internet-exposed devices.
Critical Vulnerability In FortiOS And FortiProxy (CVE-2024-55591)
17 Jan 2025
Critical Fortinet has identified a severe vulnerability in FortiOS and FortiProxy that allows unauthenticated remote attackers to bypass authentication mechanisms and gain “super-admin” privileges.
Address Bar Spoofing on Mozilla Firefox (CVE-2025-0244)
14 Jan 2025
A security vulnerability has been identified in Mozilla Firefox that poses a serious threat to users on Android devices.
Google Chrome Type Confusion Vulnerability (CVE-2025-0291)
14 Jan 2025
CVE-2025-0291 is a high-severity vulnerability identified in Google Chrome's V8 JavaScript engine that can lead to remote code execution.
Apache Tomcat Vulnerability in Dell OpenManage Server Administrator (CVE-2024-52316)
9 Jan 2025
Dell has released a critical security update for Dell OpenManage Server Administrator (OMSA) to address an Apache Tomcat Unchecked Error Condition Vulnerability.