Tag: authentication
-
Keeper Security Named Exemplary in 2026 ISG Buyers Guide for IAM
Keeper Security has been named an Exemplary provider in the 2026 ISG Buyers Guide for Identity and Access Management (IAM) platforms, ISG’s highest classification. ISG Research evaluated 31 software providers across authentication, authorization, identity lifecycle management and access governance…. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/keeper-security-named-exemplary-in-2026-isg-buyers-guide-for-iam/
-
Microsoft Exchange Vulnerability CVE-2026-62911: What Administrators Should Do and How Zscaler Can Help
Microsoft’s August 2026 Patch Tuesday included a fix for CVE-2026-62911, a high-severity authentication bypass vulnerability affecting Exchange Server 2016, 2019, and Subscription Edition. The severity has a CVSS score of 8.0 from Microsoft. As of September 1, threat intelligence group Shadowserver has… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/microsoft-exchange-vulnerability-cve-2026-62911-what-administrators-should-do-and-how-zscaler-can-help/
-
Keeper Security Named Exemplary in 2026 ISG Buyers Guide for IAM
Keeper Security has been named an Exemplary provider in the 2026 ISG Buyers Guide for Identity and Access Management (IAM) platforms, ISG’s highest classification. ISG Research evaluated 31 software providers across authentication, authorization, identity lifecycle management and access governance…. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/keeper-security-named-exemplary-in-2026-isg-buyers-guide-for-iam/
-
G7 Says Migrating to PQC Early Is Cheaper Than Later
Group Urges Countries to Treat PQC as a Standard Evolution of Cryptography. The G7 Cybersecurity Working Group urged governments and organizations to begin phased post-quantum cryptography migrations now, warning that early planning can reduce costs while limiting future exposure to quantum-enabled decryption and authentication attacks. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/g7-says-migrating-to-pqc-early-cheaper-than-later-a-32738
-
Enterprise SSO in a Java EE App: OIDC Without a Vendor SDK
Adding enterprise SSO to a Java EE application has a better answer than it used to, and most guides have not caught up. Jakarta EE Security ships an OpenID Connect authentication mechanism as part of the platform: annotate a class… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/enterprise-sso-in-a-java-ee-app-oidc-without-a-vendor-sdk/
-
Critical Cisco Nexus 9000 Flaw Lets Remote Attackers Execute Code as Root Without Authentication
Cisco has released security updates addressing a critical vulnerability in Nexus 9000 Series switches that could allow unauthenticated remote attackers to execute arbitrary code with root privileges. This vulnerability, tracked as CVE-2026-20212, has a CVSS score of 9.8 and affects Nexus 9000 platforms that are equipped with Cisco Silicon One ASICs. Cisco Nexus 9000 Flaw…
-
Startup Launch Checklist: Authentication and Security Essentials
Photo by Zulfugar Karimov on Unsplash A startup company can ship quickly and raise the much-needed funds, but if they have a weak login flow, it may just as well have taken a loss. Founders tend to underestimate how important… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/startup-launch-checklist-authentication-and-security-essentials/
-
New ‘Knight Office’ Phishing Kit Steals Microsoft 365 Logins Without Touching a Password
A newly identified phishing-as-a-service kit is being used to hijack Microsoft 365 accounts by stealing victims’ active login sessions rather than their passwords, according to new research from cybersecurity firm Huntress, a technique that allows attackers to walk straight past multi-factor authentication (MFA) without ever needing to guess, crack, or bypass it. The kit, dubbed “Knight…
-
Hackers exploit critical JFrog Artifactory flaw to forge admin tokens
A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-exploit-critical-jfrog-artifactory-flaw-to-forge-admin-tokens/
-
Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)
Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans from the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/02/microsoft-exchange-cve-2026-62911-critical-authentication-bypass-flaw/
-
Claude AI Develops Working RCE Exploit Against WAGO PLC With Researcher Assistance
Researchers have demonstrated that Anthropic’s Claude AI can assist in porting a remote code execution exploit between vulnerable models of WAGO programmable logic controllers (PLCs). However, this process requires significant human guidance, lengthy analysis sessions, and more than $500 in API usage. The experiment focused on CVE-2021-31886, a pre-authentication buffer overflow flaw in the Nucleus…
-
Attackers Pounce on Critical Artifactory Bug Following Disclosure
CVE-2026-82329 is an authentication bypass flaw in JFrog’s repository manager that enables bad actors to gain admin-level access on affected systems. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/attackers-pounce-critical-artifactory-flaw-disclosure
-
Attackers Pounce on Critical Artifactory Bug Following Disclosure
CVE-2026-82329 is an authentication bypass flaw in JFrog’s repository manager that enables bad actors to gain admin-level access on affected systems. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/attackers-pounce-critical-artifactory-flaw-disclosure
-
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks.The vulnerabilities, discovered internally by SonicWall’s William Perry and Adam Babis, are listed below – CVE-2026-83548 (CVSS score: 10.0) – A pre-authentication SSRF vulnerability in the Appliance First seen…
-
Is Silent Network Authentication a Restricted Authenticator Under SP 800-63-4?
No. Silent network authentication is not a restricted authenticator under NIST SP 800-63B-4, and the reason is not that it passed a test. SP 800-63B-4 names exactly one restricted authenticator, “the use of the PSTN for out-of-band authentication,” and… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/is-silent-network-authentication-a-restricted-authenticator-under-sp-800-63-4/
-
Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
Forescout Research – Vedere Labs said it used Anthropic’s Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware.The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server’s handling of the USER command First seen…
-
Anthropic: Attackers Using Infostealers to Hijack Claude Sessions
Anthropic is warning Claude users that attackers are using infostealer malware to compromise their login sessions and stealing usage to run their nefarious activities. It’s the latest demonstration of the shift by bad actors from credentials to session tokens and authentication cookies. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/anthropic-attackers-using-infostealers-to-hijack-claude-sessions/
-
Attackers Pounce on Critical Artifactory Flaw Following Disclosure
CVE-2026-82329 is an authentication bypass flaw in JFrog’s repository manager that enables bad actors to gain admin-level access on affected systems. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/attackers-pounce-critical-artifactory-flaw-disclosure
-
China-Linked Hackers Turn Cisco Routers Into Covert Network Gateways
China-linked Fire Ant hackers compromised Cisco IOS XR routers, management hosts, and authentication systems to create covert paths into other networks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-fire-ant-hackers-cisco-ios-xr-routers/
-
Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr.The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access in Artifactory.”JFrog Artifactory contains an authentication weakness that, under default First seen on thehackernews.com Jump…
-
Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/
-
Critical JFrog Artifactory Authentication Bypass Exploited in the Wild
Security researchers have issued warnings that attackers are actively exploiting a critical authentication bypass vulnerability in JFrog Artifactory, tracked as CVE-2026-82329. This vulnerability allows the generation of administrator-level access tokens. According to a post from the security research firm watchTowr dated September 1, its threat intelligence team has already observed exploitation activities targeting this flaw.…
-
Massive Microsoft 365 outage causes auth issues, service failures
Microsoft is investigating a widespread service issue causing authentication issues, email delays and failures, and various other issues for Exchange Online customers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-exchange-online-outage-causes-email-failures-auth-issues/
-
U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog
Tags: authentication, cisa, cve, cybersecurity, exploit, flaw, healthcare, infrastructure, kev, office, remote-code-execution, software, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)addedthe following vulnerabilities to itsKnown Exploited Vulnerabilities (KEV) catalog: PaperCut, the print management software running in schools, hospitals, and offices worldwide, recently confirmed that a pre-authentication remote code execution flaw, tracked as CVE-2026-81578,…
-
Fire Ant Hackers Compromise Cisco Routers and TACACS Servers to Target Critical Infrastructure
China-nexus threat actor Fire Ant has expanded its espionage operations from VMware hypervisors to the trusted infrastructure layer, compromising Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts. Security firm Sygnia, which investigated the activity, said Fire Ant has remained active since it was first reported in 2025. The actor’s latest operations show…
-
PoC Released for Microsoft Exchange CVE-2026-62911 Pre-Auth RCE Attack Chain
Tags: advisory, attack, authentication, cve, cyber, microsoft, rce, remote-code-execution, vulnerabilityA public proof-of-concept (PoC) repository has garnered attention for a pre-authentication remote code execution chain targeting Microsoft Exchange Server. This repository highlights CVE-2026-62911, an Exchange authentication-bypass vulnerability disclosed following Pwn2Own Berlin 2026. Defenders should treat the published code as unverified until it is independently validated in an isolated laboratory environment. Both the official advisory and…
-
Hackers Launch Password Spraying Attacks Against AWS Root Accounts at 150+ Organizations
Research has discovered a password-spraying campaign targeting AWS root user accounts across more than 150 organizations. This highlights ongoing efforts by attackers to compromise the most privileged identities in cloud environments. The campaign ran from July 24 to August 23, 2026, and involved multiple failed authentication attempts against AWS root accounts. Most affected organizations recorded…
-
What Stood Out to Me at This Year’s DEF CON
Ferdinand Mudjialim, Penetration Tester September 1, 2026 “In many cases, they returned to familiar problems around trust, access, authentication, and what happens when a system is exposed in unexpected ways.” Key Takeaways Restricted systems are only as locked down as… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/what-stood-out-to-me-at-this-years-def-con/
-
Microsoft Exchange Online outage causes email failures, auth issues
Microsoft is investigating a widespread service issue causing authentication issues and email delays and failures for Exchange Online customers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-exchange-online-outage-causes-email-failures-auth-issues/
-
Agents Without Guardrails: Why Agentic AI Governance Must Focus on Behavior, Not Just Identity
Enterprises have spent decades building security around a familiar question:”¯Who are you? Identity and access management (IAM), authentication, service accounts, OAuth tokens, and role-based access controls all start there. Establish identity, assign permissions, and control access. Agentic AI changes the equation. AI agents do not simply access systems. They reason, select tools, call APIs, retrieve……

