Skip to main content

Business

View all

Alerts & Advisories

Critical Unauthenticated Remote Code Execution Vulnerability in Microsoft SharePoint Server CVE-2026-50522

24 Jul 2026

A critical security vulnerability (CVSS 3.1 score: 9.8) has been identified in on-premises deployments of Microsoft SharePoint Server. This vulnerability allows unauthenticated users to run malicious code on SharePoint servers to steal IIS machine keys which can be used to bypass all login screens and masquerade as administrators. This flaw is caused by the deserialization of untrusted data within SharePoint's core processing components, allowing a remote, unauthenticated attacker to execute malicious code on vulnerable systems.

See more

Global Canvas LMS Data Breach

11 May 2026

A major cybersecurity incident has impacted Canvas Learning Management System (Canvas LMS), affecting thousands of educational institutions worldwide including institutions in Brunei Darussalam. The hacking group ShinyHunters has claimed responsibility for exfiltrating approximately 3.65TB of data, affecting nearly 9,000 educational institutions worldwide.

See more

Critical Privilege Escalation Vulnerability in Zoom Clients for Windows (CVE-2025-49457)

14 Aug 2025

An untrusted search path vulnerability has been found in Zoom Clients for Windows operating system, allowing an unauthenticated attacker to escalate privileges via network access.

See more

Schedule an awareness talk for your organization

BruCERT offers awareness talks to educate the public and organizations on the importance of cybersecurity and safe online practices.

Outreach

Our roadshows include interactive activities and demonstrations, and can be customized to suit your organization.

Learn more
View all

Is your company prepared for cybersecurity threats?

Use this self-assessment questionnaire to determine your organization's current security posture and identify areas of potential or actual weaknesses.

Learn more