News

CVE-2025-14847 MongoDB

ISO is aware of a high severity vulnerability that affects MongoDB Server and is being actively exploited. The MongoDB vulnerability allows attackers to gain access to information in the program's memory without the need to authenticate.

CVE-2026-23550 Wordpress Modular DS flaw

ISO is aware of a critical vulnerability that affects the Modular DS WordPress plugin[1]. This vulnerability, CVE-2026-23550, allows unauthenticated users to gain Administrator privileges due to a flaw in the “direct request” mode of the plugin.

Critical Vulnerabilities in React and Next.js

A critical vulnerability has been identified in the React Server Components (RSC) "Flight" protocol, a core feature of the modern React 19 ecosystem. This flaw, tracked as CVE-2025-55182 (React) and impacting the popular framework Next.js, allows an attacker to achieve unauthenticated Remote Code...

Fraudulent New Salary Details Phish

This phony email is allegedly from a campus department regarding new salary details or a financial bonus.

Bogus bCal Meetings - Spam / Malware

A default setting in bCal may allow anyone from the internet to add you to a Google Calendar invite. This is being used to create fake spam meetings or include potentially malicious links or attachments. Any links included are as dangerous as the ones that would have been included in a phishing...