authentication
196 articles with this tag
CRITICAL
INFO
INFO
INFO
HIGH
CRITICAL
CRITICAL
CRITICAL
INFO
INFO
INFO
MEDIUM
MEDIUM
INFO
INFO
LOW
INFO
MEDIUM
MEDIUM
INFO
MEDIUM
INFO
INFO
CRITICAL
MEDIUM
INFO
INFO
INFO
MEDIUM
CRITICAL
CRITICAL
CRITICAL
HIGH
MEDIUM
INFO
CRITICAL
INFO
INFO
INFO
INFO
HIGH
INFO
CRITICAL
HIGH
INFO
CRITICAL
CRITICAL
HIGH
INFO
CRITICAL
CRITICAL
LOW
MEDIUM
INFO
CRITICAL
INFO
CRITICAL
CRITICAL
MEDIUM
INFO
HIGH
MEDIUM
LOW
HIGH
MEDIUM
MEDIUM
HIGH
CRITICAL
MEDIUM
INFO
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
INFO
HIGH
MEDIUM
INFO
CRITICAL
MEDIUM
CRITICAL
CRITICAL
CRITICAL
MEDIUM
MEDIUM
HIGH
HIGH
MEDIUM
MEDIUM
INFO
INFO
HIGH
CRITICAL
MEDIUM
CRITICAL
CRITICAL
CRITICAL
CRITICAL
HIGH
CheckPoint authentication bypass bug exploited, added to CISA list
How to Build Application Detection and Response
Federation Outage Prevention: What breaks, how to test it and how to recover
Google’s newest sign-in method asks you to look at the camera
VU#492466: Logto Identity Platform has authentication and authorization failures in core protocol handling
CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
Finding actors that probe a CVE's exploit path before public disclosure in 30M honeypot records.
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
OneSpan launches unified platform for financial institution authentication
AI agents are still logging in as humans
Claude can now sign into websites with 1Password without exposing your credentials
n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer
Microsoft is forcing an enterprise transition to passkeys
Authenticate legitimate AI agent traffic with AWS WAF Bot Control
Google adds FIDO2 keys and phone passkeys to Windows login via GCPW
Microsoft Entra ID authentication overhaul to start in September 2026
Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID
CVE-2026-58251 NATS Server: Queue Subscribe Authz Bypass
CVE-2026-58253 NATS Server: Route API Auth Bypass
Only 28% of financial workforce MFA is phishing-resistant
Aduna launches network-based authentication to replace SMS OTPs
Permiso launches risk score engine for unified identity security
Hong Kong SFC mandates stronger login security for crypto platforms
Critical Gitea flaw allows authentication bypass via single HTTP header
CVE-2026-60001 sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
CVE-2026-9079 stale proxy password leak
CVE-2026-8927 env-set cross-proxy Digest auth state leak
Securing the inbox: Where identity, brand and security meet
NCSC-2026-0220 [1.00] [M/H] Kwetsbaarheden verholpen in Rancher door Rancher Labs
Exploitation of Recent Oracle E-Business Suite Vulnerability Begins
Critical SimpleHelp Vulnerability Exploited for Malware Delivery
Splunk Enterprise Authentication Bypass Vulnerability
[UPDATE] [mittel] FreeRADIUS: Mehrere Schwachstellen
CVE-2026-3099 Libsoup: libsoup: authentication bypass via digest authentication replay attack
Website shames companies for not offering passkeys
Why patch directives only go so far
Entrust uses biometrics to verify users during high-risk transactions
CrowdStrike Expands Identity Leadership with OpenID and IDPro
CrowdStrike Expands Identity Leadership with OpenID and IDPro
Mastodon 4.6 adds profile Collections and two-factor controls
Rockwell Automation FactoryTalk Historian Site Edition
Webinar Today: How Modern Breaches Bypass MFA and Evade Detection
Cisco adds another SD-WAN box to max-severity bug advisory
NCSC-2026-0207 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Fusion Middleware producten
[Security Blog] Understanding OAuth Risks: From Device Code Phishing to Token Abuse
SimpleHelp vulnerability allows unauthenticated attackers to create privileged accounts
Critical Copilot vulnerability allowed hackers to seal 2FA code from users
China-linked spies backdoored authentication stack to stay hidden for years
Red Sift, GMO GlobalSign partnership simplifies email authentication and BIMI adoption
Palo Alto Networks PAN-OS GlobalProtect Authentication Bypass
10-year-old phpBB vulnerability allows admin account takeover
CrowdStrike Expands Identity Leadership with OpenID and IDPro
[NEU] [mittel] MIT Kerberos: Schwachstelle ermöglicht nicht spezifizierten Angriff
CrowdStrike Expands Identity Leadership with OpenID and IDPro
SAP Patches Critical NetWeaver, Commerce Vulnerabilities
TOTP-based two-factor authentication for Sculpt OS
Veikleikar í Linux, Flowise, Windows NetLogon, WP Maps Pro, Oracle & Palo Alto Networks
Veikleikar í Android, Cisco, Acer Wave 7, HP Poly VVX og Trio VoIP
[UPDATE] [mittel] Red Hat Single Sign On: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Building secure B2C applications with fine-grained access control using Amazon Cognito and Amazon Verified Permissions
Claude Code has an MCP security problem — and your developers are already using it
Microsoft continues migration from NTLM to Kerberos
Microsoft Edge retires master password feature, adopts passkeys and biometrics
VU#873170: Collibra Agent contains improper authentication and path traversal vulnerabilities
OpenAI requires stronger authentication for users of its most powerful AI models
Microsoft confirms outage affecting MFA, My Sign-Ins platform
OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack
Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
Vulnérabilité dans Apereo CAS (28 mai 2026)
Defense by accumulation
USN-8320-1: Memcached vulnerabilities
USN-8315-1: MediaWiki vulnerabilities
From Cookies to Keys: The Threat of Session Hijacking
ABB AbilityTM Zenon Remote Transport Vulnerability
MFA Prompt Bombing: Why Your Second Factor Isn't Saving You
What Is Single Sign-On? The Practical Guide | Huntress
CVE-2026-34472: Pre-auth credential exposure and auth bypass in ZTE H188A V6 routers
CVE-2026-7168 cross-proxy Digest auth state leak
Earbud sensors can authenticate users by their heartbeat, study finds
[NEU] [hoch] Microsoft Authenticator: Schwachstelle ermöglicht Offenlegung von Informationen
CVE-2026-42010 Gnutls: gnutls: authentication bypass via nul character in username
CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits
Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Siemens SIPROTEC 5
Siemens Opcenter RDnL
[UPDATE] [mittel] PAM: Schwachstelle ermöglicht Privilegieneskalation
Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise
MyAudi app:Security issues in Audi Connected Vehicle experience
CVE-2026-42256 net-imap: Denial of service via high iteration count for `SCRAM-*` authentication
CVE-2026-40379 Microsoft Enterprise Security Token Service (ESTS) Spoofing Vulnerability
World Passkey Day: Advancing passwordless authentication
Critical Buffer Overflow in Palo Alto Networks PAN-OS User-ID Authentication Portal (CVE-2026-0300)
Microsoft's patch for a 0-day exploited by Russian spies fell short. Another Windows flaw is under attack
Proton Pass: Second-Password Bypass Through Emergency Access
Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass
Critical MOVEit Automation auth bypass vulnerability fixed (CVE-2026-4670)
Progress warns of critical MOVEit Automation auth bypass flaw
Critical cPanel vulnerability actively exploited in the wild
ABB Ability OPTIMAX