Advisory: WordPress vulnerability

We’re aware of a security vulnerability (CVE-2026-87902) affecting WordPress websites. If exploited, this vulnerability could allow an attacker to gain control of an affected WordPress site. The vulnerability affects all WordPress versions before 7.1.2. What you need...

Read more

Advisory: WordPress vulnerabilities

We’re aware of two security vulnerabilities (CVE-2026-63030 and CVE-2026-60137) affecting WordPress websites. If exploited together, these vulnerabilities could allow an unauthenticated attacker to perform SQL injection and potentially gain remote code execution (RCE)...

Read more

Palo Alto GlobalProtect VPN vulnerability

We’re aware of a critical vulnerability in Palo Alto’s GlobalProtect VPN application used under our Remote Access solution. If exploited, a remote attacker could connect to school networks as a VPN user - you can find more information in Palo Alto’s advisory.  It’s...

Read more

Advisory: Lumma Stealer malware

We're aware that Lumma Stealer malware has affected some New Zealanders’ online accounts, as reported by the NCSC. We are monitoring the situation and will contact you directly if we see anything suspicious. Find out more and their recommendations via the NCSC alert -...

Read more