access-control
87 articles with this tag
HIGH
HIGH
INFO
HIGH
CRITICAL
MEDIUM
CRITICAL
INFO
MEDIUM
HIGH
MEDIUM
HIGH
INFO
INFO
INFO
CRITICAL
MEDIUM
INFO
CRITICAL
HIGH
HIGH
HIGH
INFO
CRITICAL
INFO
MEDIUM
HIGH
HIGH
MEDIUM
CRITICAL
HIGH
MEDIUM
CRITICAL
HIGH
HIGH
CRITICAL
MEDIUM
MEDIUM
HIGH
LOW
MEDIUM
INFO
INFO
INFO
LOW
INFO
LOW
HIGH
MEDIUM
MEDIUM
MEDIUM
INFO
INFO
INFO
LOW
INFO
INFO
MEDIUM
INFO
CRITICAL
HIGH
CRITICAL
CRITICAL
CRITICAL
CRITICAL
HIGH
CRITICAL
MEDIUM
LOW
HIGH
MEDIUM
MEDIUM
INFO
INFO
MEDIUM
INFO
INFO
INFO
INFO
LOW
HIGH
HIGH
INFO
INFO
HIGH
HIGH
CRITICAL
'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure
NCSC-2026-0265 [1.00] [M/H] Kwetsbaarheden verholpen in SolarWinds Serv-U
Why Role-Based Access Breaks at Hospital Scale — and What Replaces It
Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data
[UPDATE] [hoch] IBM Security Verify Access: Mehrere Schwachstellen
Cisco Identity Services Engine Path Traversal Vulnerability
[NEU] [hoch] IBM Security Verify Access: Mehrere Schwachstellen
Your company already adopted AI and nobody is governing access
[webapps] KNX visualisering - Broken Access Control
NCSC-2026-0218 [1.00] [M/H] Kwetsbaarheid verholpen in Cisco Catalyst Center
[NEU] [UNGEPATCHT] [mittel] Keycloak: Mehrere Schwachstellen
NCSC-2026-0213 [1.00] [M/H] Kwetsbaarheden verholpen in MISP platform
Robinhood Cuts Access Approval Time to Support High-Velocity Development
Restrict AWS Management Console access to expected networks with sign-in resource-based policies and RCPs
Broken access control demo
Orphaned AI Agents: How to Find Hidden Access Risks Inside Your Network
Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability
WitnessAI Agentic Control secures AI agents, tools, and MCP server access
CISA Adds One Known Exploited Vulnerability to Catalog
NCSC-2026-0197 [1.00] [M/H] Kwetsbaarheid verholpen in Fortinet FortiPortal
CVE-2026-41092 Microsoft Kinect Elevation of Privilege Vulnerability
Schneider Electric EcoStruxure Panel Server
Silverfort integrates identity controls with Microsoft Copilot Studio agents
Acer working to patch max severity zero-days in Wave 7 routers
Why IAM Matters: Benefits, Challenges, and Common Pitfalls
[NEU] [niedrig] GitLab: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
[NEU] [hoch] Hirschmann HiSecOS: Schwachstelle ermöglicht Privilegieneskalation
Gitea Vulnerability Exposed 30,000 Deployments to Attacks
XM Cyber expands platform to enforce least-privilege access
Cisco Patches Critical Vulnerability in Secure Workload
Vulnérabilité dans Cisco Secure Workload (21 mai 2026)
[NEU] [mittel] Keycloak: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Fortinet fixes two critical RCE flaws in FortiAuthenticator and FortiSandbox
NCSC-2026-0155 [1.00] [M/H] Kwetsbaarheid verholpen in Fortinet FortiSandbox
NCSC-2026-0156 [1.00] [M/H] Kwetsbaarheid verholpen in Fortinet FortiAuthenticator
Fortinet warns of critical RCE flaws in FortiSandbox and FortiAuthenticator
Amazon Quick authorization bypass let users reach blocked AI chat agents
Veikleiki í Innu: „Lítum málið mjög alvarlegum augum“
[NEU] [mittel] JetBrains TeamCity On-Premises: Schwachstelle ermöglicht Privilegieneskalation
[NEU] [niedrig] Sonatype Nexus Repository Manager: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
CVE-2026-6667 PgBouncer missing authorization check in KILL_CLIENT admin command
ICYMI: April 2026 @AWS Security
Why most zero-trust architectures fail at the traffic layer
OpenAI locks GPT-5.5-Cyber behind velvet rope despite slamming Anthropic for doing exactly that
Cequence Agent Personas bring granular control and governance to enterprise AI agents
Access control with IAM Identity Center session tags
[NEU] [UNGEPATCHT] [niedrig] Keycloak: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
[NEU] [mittel] IBM WebSphere Application Server: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
[NEU] [mittel] Gitea: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
NCSC-2026-0126 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle E-Business Suite
[webapps] WordPress Plugin 5.2.0 - Broken Access Control
Top Cyber Hygiene Tips for Better Digital Security
Non-human identities now center of enterprise risk
Agentic AI changes the shape of trust
Browser Guard gets even better with Access Control
Securing non-human identities: automated revocation, OAuth, and scoped permissions
Managed OAuth for Access: make internal apps agent-ready in one click
[NEU] [mittel] IBM Security Verify Access: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Secureframe expands Comply with User Access Reviews for automated governance
Attackers exploited this critical FortiClient EMS bug as a 0-day
CISA Adds One Known Exploited Vulnerability to Catalog
CVE-2026-35616: Fortinet FortiClientEMS improper access control vulnerability exploited in the wild
Fortinet Rushes Emergency Fixes for Exploited Zero-Day
New FortiClient EMS flaw exploited in attacks, emergency patch released
API authentication and authorization bypass
Cisco IMC auth bypass vulnerability allows attackers to alter user passwords (CVE-2026-20093)
[NEU] [hoch] IBM Security Verify Access: Mehrere Schwachstellen
NCSC-2026-0103 [1.00] [M/H] Kwetsbaarheden verholpen in GitLab
Anthropic cuts action approval loop, lets Claude Code make the call
NCSC-2026-0099 [1.00] [M/H] Kwetsbaarheid verholpen in Oracle Identity Manager en Oracle Web Services Manager
7 Ways to Prevent Privilege Escalation via Password Resets
shell command limitation bypass by SSH local config overriding
Why access decisions are becoming the weakest link in identity security
New infosec products of the week: March 6, 2026
Cisco Secure Firewall Adaptive Security Appliance Software Multiple Context Mode SCP Unauthorized File Access Vulnerability
Intent-Based Access Control (IBAC) – FGA for AI Agent Permissions
Samsung brings Digital Home Key to Samsung Wallet, extending secure access to the home
3 Ways AI Agents Break Security And How to Avoid Mistakes
Cybersecurity in cross-border logistics operations
Passwork 7.4 enhances enterprise security with centralized User vault restrictions
Tens of thousands of OpenClaw systems exposed by misconfigurations and known exploits - SiliconANGLE
CVE-2025-14778: Keycloak Privilege Escalation Vulnerability
MintMCP’s governance platform helps organizations deploy, monitor, and secure AI agents
The security implementation gap: Why Microsoft is supporting Operation Winter SHIELD
Why non-human identities are your biggest security blind spot in 2026
The top 5 sources of secret sprawl, and how attackers exploit them
CVE-2025-59097: The exos 9300 application can be used to configure Access Managers (e.g. 92xx, 9230 and 9290). The c...