Tag: authentication
-
Google adds FIDO2 keys and phone passkeys to Windows login via GCPW
Google has started rolling out FIDO2-compliant physical security key support as a second factor for authentication in Google Credential Provider for Windows (GCPW) to all … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/14/security-key-windows-login-google-workspace/
-
Microsoft Entra ID authentication overhaul to start in September 2026
Microsoft will begin rolling out passkeys as the default authentication experience for Microsoft Entra ID in the public cloud on September 1, 2026. Organizations with SMS or … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/14/microsoft-entra-passkey-authentication/
-
Critical WordPress OAuth SSO Plugin Flaw Allows Unauthenticated Attackers to Gain Admin Access
A critical authentication bypass vulnerability has been disclosed in the widely used miniOrange OAuth Single Sign-On (SSO) WordPress plugin, carrying a near-maximum CVSS score of 9.8. This flaw, tracked as CVE-2026-57807, affects all plugin versions up to and including version 38.5.8. As of now, it remains unpatched, with no official fix available from the vendor.…
-
Exposed Server Unmasks Evilginx Operators Stealing Microsoft 365 Sessions and OAuth Tokens
A misconfigured server in Budapest exposed a live phishing operation built to bypass Microsoft 365 multi-factor authentication and retain access to compromised accounts. The server, hosted at 185.163.204[.]7185.163.204[.]7185.163.204[.]7, was running python3 -m http.server 8080 with directory listing enabled, making its operational files publicly accessible. Researchers found phishing configurations, Telegram session artifacts, credential logs, RMM installers,…
-
Exposed Server Unmasks Evilginx Operators Stealing Microsoft 365 Sessions and OAuth Tokens
A misconfigured server in Budapest exposed a live phishing operation built to bypass Microsoft 365 multi-factor authentication and retain access to compromised accounts. The server, hosted at 185.163.204[.]7185.163.204[.]7185.163.204[.]7, was running python3 -m http.server 8080 with directory listing enabled, making its operational files publicly accessible. Researchers found phishing configurations, Telegram session artifacts, credential logs, RMM installers,…
-
Hidden Backdoor Found in Tenda Router Firmware
Unauthenticated Flaw Allows Full Router, Network Takeover. A hidden backdoor, disclosed by CERT/CC and found in multiple firmware versions made by Chinese manufacturer Tenda, bypasses authentication and could grant attackers administrative access. Researchers are reporting exploitation and an Nmap script is making vulnerable devices easier to identify. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hidden-backdoor-found-in-tenda-router-firmware-a-32181
-
Hidden Backdoor Found in Tenda Router Firmware
Unauthenticated Flaw Allows Full Router, Network Takeover. A hidden backdoor, disclosed by CERT/CC and found in multiple firmware versions made by Chinese manufacturer Tenda, bypasses authentication and could grant attackers administrative access. Researchers are reporting exploitation and an Nmap script is making vulnerable devices easier to identify. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hidden-backdoor-found-in-tenda-router-firmware-a-32181
-
Passwortlos wird MFA noch sicherer
Multifaktor-Authentifizierung (MFA) hat sich sowohl in Unternehmen als auch bei Privatanwendern als weitverbreitetes und etabliertes Standardverfahren zur Identitätsprüfung beim Login etabliert. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/passwortlos-wird-mfa-noch-sicherer
-
Neue Sicherheitslösung unterstützt FIDO2 und PKI für gesicherten logischen Zugriff
Die Infineon Technologies AG bringt SECORA ID Key S USB auf den Markt, eine auf Java Card basierende Lösung mit USB- und NFC-Konnektivität für gesicherte Authentifizierung und digitale Signaturen. Als erste für FIDO Level 3+ zertifizierte und CTAP 2.1-konforme Lösung ermöglicht der Authentifikator eine phishing-resistente, passwortlose Authentifizierung sowie Schutz vor aus der Ferne durchgeführten Softwareangriffen……
-
Hidden Backdoor in Tenda Router Firmware
Unauthenticated Flaw Allows Full Router, Network Takeover. A hidden backdoor, disclosed by CERT/CC and found in multiple firmware versions made by Chinese manufacturer Tenda, bypasses authentication and could grant attackers administrative access. Researchers are reporting exploitation and an Nmap script is making vulnerable devices easier to identify. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hidden-backdoor-in-tenda-router-firmware-a-32181
-
Critical Gitea Docker Bug Under Active Exploitation Exposes Repositories and Secrets
Attackers are exploiting a critical Gitea flaw (CVE-2026-20896) that bypasses authentication with a single HTTP header, exposing repositories and sensitive data. Sysdig researchers warn that attackers are actively exploiting a critical authentication bypass flaw, tracked as CVE-2026-20896 (CVSS score of 9.8), which affects Gitea official Docker images before version 1.26.3. >>CVE-2026-20896 exploited 13 days after…
-
Hidden backdoor in Tenda router firmware grants admin access
A hidden authentication backdoor has been found in multiple Tenda router firmware versions, potentially allowing an attacker to gain administrative access to the device’s web management panel. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hidden-backdoor-in-tenda-router-firmware-grants-admin-access/
-
BeyondTrust Patches Authentication Bypass Vulnerabilities
BeyondTrust has patched four RS and PRA vulnerabilities, including two critical authentication bypass flaws. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/beyondtrust-patches-authentication-bypass-vulnerabilities/
-
Authentication Bypass – Kritische SimpleHelp RMM-Schwachstelle wird aktiv ausgenutzt
Tags: authenticationFirst seen on security-insider.de Jump to article: www.security-insider.de/simplehelp-schwachstelle-oidc-auth-bypass-cve-2026-48558-a-b785971ada922f189ff5f132eaefaba6/
-
Hidden Tenda Router Backdoor Grants Admin Access, No Patch Available
CERT/CC warns an unpatched backdoor in several Tenda routers lets attackers bypass login and gain full admin access with a hidden password. CERT/CC published an alert documenting an undocumented authentication backdoor in multiple Tenda firmware versions, tracked as CVE-2026-11405. The flaw gives anyone who knows the right password full administrative access to the device’s web…
-
CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
Several versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented authentication backdoor that enables administrative access to the devices’ web management interfaces, the CERT Coordination Center (CERT/CC) warned Monday.”An attacker can exploit this vulnerability, tracked as CVE-2026-11405, to bypass the password verification process First seen on thehackernews.com…
-
BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA
BeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that, if successfully exploited, could allow unauthenticated attackers to take control of susceptible devices.The vulnerabilities are listed below – CVE-2026-40138 (CVSS score: 9.2) – A pre-authentication vulnerability exists in the First seen on thehackernews.com Jump…
-
Hackers Use Trusted Microsoft Domain and One-Time Codes to Hijack Corporate Accounts
A rising phishing technique is exploiting a legitimate Microsoft authentication flow to hijack corporate accounts without stealing passwords. Attackers are weaponizing the OAuth 2.0 Device Authorization Grant commonly used to sign in input-constrained devices via a one-time user code to trick victims into approving access on Microsoft’s own domain. Because the final authentication occurs on…
-
FIFA World Cup Phishing Scam Uses Fake Reward Pages to Steal Credit Card Data
A sophisticated email phishing campaign exploiting the global excitement around the 2026 FIFA World Cup is deceiving fans with counterfeit reward pages designed to harvest credit card information rather than deliver promised prizes. Security researchers have identified a multi-stage attack chain that begins with an authentication-passing email, progresses through geo-cloaked redirectors, and culminates in a…
-
SSH Attackers Use Single Exec Commands to Bypass Interactive Honeypot Analysis
SSH attackers are increasingly abusing single non-interactive exec commands over SSH to bypass traditional honeypot analysis, effectively turning post-authentication activity into short, automated probes rather than interactive shell sessions that deception systems were designed to study. Recent measurements on eleven LLM-backed SSH honeypots show that 99.23% of authenticated sessions consist of a single non-interactive exec…
-
Government and Healthcare Are the Weakest Links in Global Email Security
Government and healthcare sectors have weak email security. Many domains lack SPF, DMARC, DKIM, and MTA-STS, leaving them open to phishing attacks. Comparitech analyzed live DNS records for 5,849 domains across 13 sectors and scored each one out of 8 points based on four standard email authentication protocols: SPF, DMARC, DKIM, and MTA-STS. The results…
-
Why a Windows Hello PIN Beats a Password for Enterprise Security
As phishing campaigns, AI-driven identity attacks, and Windows migration planning raise authentication stakes, IT teams should recheck how Windows Hello PIN security works. The post Why a Windows Hello PIN Beats a Password for Enterprise Security appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-windows-hello-pin-security/
-
Signicat und TrustTech kooperieren für wiederverwendbare digitale Identitäten nach eIDAS 2.0
Tags: authenticationDie Partnerschaft wird Unternehmen dabei helfen, von wiederholten Identitätsprüfungen zu reibungslosen Onboarding-, Authentifizierungs- und elektronischen Signaturprozessen überzugehen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/signicat-und-trusttech-kooperieren-fuer-wiederverwendbare-digitale-identitaeten-nach-eidas-2-0/a45652/
-
Phishing Tactics Target Session Tokens and Deliver Malware
Barracuda found phishing attacks increasingly abuse Microsoft authentication, session tokens, and fileless malware. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/phishing-tactics-target-session-tokens-and-deliver-malware/
-
Azure Password-Spraying Attack Bypasses MFA Defenses
Threat Actor Uses Deprecated OAuth 2.0 Authentication Flow. Attackers behind a password-spraying campaign targeting Microsoft Office 365 accounts have amassed dozens of victims by abusing a deprecated feature in OAuth 2.0 to generate access tokens, in some cases sidestepping multifactor authentication controls, warn researchers. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/azure-password-spraying-attack-bypasses-mfa-defenses-a-32128
-
Attackers Seize Exposed AI Endpoints to Power Offensive Ops
Threat actors don’t need any special authentication to reach a target endpoint, they just need to know where it is. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/attackers-hijack-exposed-ai-endpoints-power-offensive-ops
-
Apache Tomcat Vulnerabilities Let Attackers Bypass Authentication and Security Constraints
The Apache Software Foundation has disclosed two security vulnerabilities in Apache Tomcat that can lead to authentication bypass and improper enforcement of security constraints. These vulnerabilities impact various deployments across enterprise environments. They are tracked as CVE-2026-55957 (Important severity) and CVE-2026-55956 (Moderate severity) and affect multiple supported versions of Tomcat. If left unpatched, these issues…
-
Attackers Hijack Exposed AI Endpoints to Power Offensive Ops
Attackers don’t need any special authentication to reach a target endpoint, they just need to know where it is. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/attackers-hijack-exposed-ai-endpoints-power-offensive-ops

