authentication
236 articles with this tag
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
INFO
HIGH
INFO
MEDIUM
MEDIUM
HIGH
CRITICAL
HIGH
CRITICAL
INFO
MEDIUM
MEDIUM
MEDIUM
MEDIUM
INFO
HIGH
INFO
HIGH
HIGH
MEDIUM
HIGH
MEDIUM
CRITICAL
INFO
HIGH
HIGH
HIGH
HIGH
MEDIUM
CRITICAL
INFO
MEDIUM
LOW
MEDIUM
MEDIUM
MEDIUM
MEDIUM
HIGH
MEDIUM
INFO
INFO
MEDIUM
CRITICAL
HIGH
CRITICAL
HIGH
CRITICAL
INFO
INFO
INFO
HIGH
CRITICAL
CRITICAL
CRITICAL
INFO
INFO
INFO
MEDIUM
MEDIUM
INFO
INFO
LOW
INFO
MEDIUM
MEDIUM
INFO
MEDIUM
INFO
INFO
CRITICAL
MEDIUM
INFO
INFO
INFO
MEDIUM
CRITICAL
CRITICAL
CRITICAL
HIGH
MEDIUM
INFO
CRITICAL
INFO
INFO
HIGH
INFO
CRITICAL
HIGH
INFO
CRITICAL
CRITICAL
HIGH
INFO
CRITICAL
CRITICAL
More JFrog Artifactory bugs under attack, and all 3 have patches
Critical NetScaler Vulnerability Exploited in Attacks
Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
[NEU] [hoch] Microsoft Apps: Mehrere Schwachstellen ermöglichen Privilegieneskalation
CVE-2026-84003 Microsoft Authentication Library (MSAL) for Node.js Spoofing Vulnerability
CVE-2026-73004 Windows Autopilot Tampering Vulnerability
Improper Authentication of FortiPAM Server
Ping YOUniverse: The next stage of human authentication
39 New Methods That Compromise Passkey Authentication
USN-8718-1: SSSD vulnerability
Exploit Published for Fresh Cleo Harmony Vulnerability
Exploited JFrog Artifactory bug puts software supply chain on alert
JFrog Artifactory flaw exploited days after patch release
Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
Microsoft nudges enterprise security closer to its passwordless future. But ‘123456’ will survive.
RHSA-2026:61226: Moderate: pam security update
RHSA-2026:61227: Moderate: pam security update
RHSA-2026:61225: Moderate: pam security update
RHSA-2026:61223: Moderate: pam security update
AI Agent Authentication in 2026: Web Bot Auth, ARD & OAuth
WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android
WhatsApp adds stronger two-step verification, multiple passkeys
NCSC-2026-0322 [1.00] [M/H] Kwetsbaarheden verholpen in Splunk Enterprise door Splunk
Password spraying attacks surge 155x, exploiting legacy authentication flaws
Device Code Phishing Up 1500%
VU#874418: RDK-B WebUI contains multiple vulnerabilities
Hacking SAML with Claude Code
2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway
Updates to your AWS Sign-In experience
NCSC-2026-0300 [1.00] [M/H] Kwetsbaarheden verholpen in Fortinet FortiWeb
NCSC-2026-0299 [1.00] [M/H] Kwetsbaarheid verholpen in Fortinet FortiManager
Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
DSA-6434-1 lemonldap-ng - security update
SharePoint Vulnerability Exploited Shortly After PoC Release
The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In
CVE-2026-19139 Race in CredentialProvider
Microsoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users
NCSC-2026-0280 [1.00] [M/H] Kwetsbaarheid verholpen in macOS Screen Sharing door Apple
I made a full JWT hacking tutorial + testing suite
Enterprise passkey security under threat from malware
Google’s synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacks
Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986)
Docker OIDC connections for GitHub Actions available for Docker Orgs
USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports
Attackers are using Microsoft’s legitimate login system to camouflage phishing attacks
NCSC-2026-0269 [1.00] [M/H] Kwetsbaarheden verholpen in VMware producten
Flaw From 2002 Exposes Data Centers to Server Takeover
Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)
MikroTik RouterOS and Cloud Hosted Router
CheckPoint authentication bypass bug exploited, added to CISA list
How to Build Application Detection and Response
Federation Outage Prevention: What breaks, how to test it and how to recover
Google’s newest sign-in method asks you to look at the camera
VU#492466: Logto Identity Platform has authentication and authorization failures in core protocol handling
CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
Finding actors that probe a CVE's exploit path before public disclosure in 30M honeypot records.
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
OneSpan launches unified platform for financial institution authentication
AI agents are still logging in as humans
Claude can now sign into websites with 1Password without exposing your credentials
n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer
Microsoft is forcing an enterprise transition to passkeys
Authenticate legitimate AI agent traffic with AWS WAF Bot Control
Google adds FIDO2 keys and phone passkeys to Windows login via GCPW
Microsoft Entra ID authentication overhaul to start in September 2026
Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID
CVE-2026-58251 NATS Server: Queue Subscribe Authz Bypass
CVE-2026-58253 NATS Server: Route API Auth Bypass
Only 28% of financial workforce MFA is phishing-resistant
Aduna launches network-based authentication to replace SMS OTPs
Permiso launches risk score engine for unified identity security
Hong Kong SFC mandates stronger login security for crypto platforms
Critical Gitea flaw allows authentication bypass via single HTTP header
CVE-2026-60001 sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
CVE-2026-9079 stale proxy password leak
CVE-2026-8927 env-set cross-proxy Digest auth state leak
Securing the inbox: Where identity, brand and security meet
NCSC-2026-0220 [1.00] [M/H] Kwetsbaarheden verholpen in Rancher door Rancher Labs
Exploitation of Recent Oracle E-Business Suite Vulnerability Begins
Critical SimpleHelp Vulnerability Exploited for Malware Delivery
Splunk Enterprise Authentication Bypass Vulnerability
[UPDATE] [mittel] FreeRADIUS: Mehrere Schwachstellen
CVE-2026-3099 Libsoup: libsoup: authentication bypass via digest authentication replay attack
Website shames companies for not offering passkeys
Why patch directives only go so far
Entrust uses biometrics to verify users during high-risk transactions
Mastodon 4.6 adds profile Collections and two-factor controls
Rockwell Automation FactoryTalk Historian Site Edition
Webinar Today: How Modern Breaches Bypass MFA and Evade Detection
Cisco adds another SD-WAN box to max-severity bug advisory
NCSC-2026-0207 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Fusion Middleware producten
[Security Blog] Understanding OAuth Risks: From Device Code Phishing to Token Abuse
SimpleHelp vulnerability allows unauthenticated attackers to create privileged accounts
Critical Copilot vulnerability allowed hackers to seal 2FA code from users
China-linked spies backdoored authentication stack to stay hidden for years
Red Sift, GMO GlobalSign partnership simplifies email authentication and BIMI adoption
Palo Alto Networks PAN-OS GlobalProtect Authentication Bypass
10-year-old phpBB vulnerability allows admin account takeover