Tag: authentication
-
PCI DSS 4.0 Audits: Continuum GRC Cybersecurity Assessments 2026
PCI DSS 4.0 compliance audits demand a fundamental shift from periodic checkbox exercises to continuous, risk-based cybersecurity assessments. Organizations preparing for 2026 assessments must address new requirements around targeted risk analyses, multi-factor authentication expansion, and automated security monitoring that directly impact how cardholder data environments are protected and validated. Key Takeaways: PCI DSS 4.0 introduces”¦…
-
ATM Flaws Reveal Key Weaknesses in the Software Supply Chain
A security researcher discovered nine vulnerabilities impacting ATM encryption and authentication software. But the problems extend far beyond your local cash machine. First seen on wired.com Jump to article: www.wired.com/story/atm-flaws-reveal-key-weaknesses-in-the-software-supply-chain/
-
Security Keys werden quantenresistent – Post-Quanten-Kryptographie definiert Authentifizierung neu
First seen on security-insider.de Jump to article: www.security-insider.de/security-keys-post-quanten-kryptographie-passkeys-a-4fd92519e10c1c65ebae30fed95a33a4/
-
Common Authentication Vulnerabilities Developers Overlook (and How to Prevent Them)
Is your app truly secure? Uncover the most common authentication flaws developers miss and learn actionable strategies to protect your users today. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/common-authentication-vulnerabilities-developers-overlook-and-how-to-prevent-them/
-
Critical Microsoft UFO MCP Flaw Lets Attackers Remotely Control Android Devices Without Authentication
Tags: access, android, authentication, control, cve, cvss, cyber, flaw, microsoft, mobile, open-source, vulnerabilityA critical vulnerability in Microsoft’s open-source UFO Desktop AgentOS could allow remote attackers to access and control Android devices connected via the platform’s Mobile Model Context Protocol (MCP) servers without requiring authentication. This vulnerability is tracked as CVE-2026-73296 and GHSA-24fq-m9rr-g3mm, carrying a CVSS v3.1 score of 9.4. It affects UFO versions up to and including…
-
Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening.”This vulnerability gives an unauthenticated attacker remote control over PaperCut’s trusted configuration, which could be used to execute arbitrary Java code inside the application’s…
-
U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog
Tags: authentication, cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, linux, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)addedthe following vulnerabilities to itsKnown Exploited Vulnerabilities (KEV) catalog: CVE-2023-49105 (CVSS score of 9.8) is an improper-authentication flaw in ownCloud Server’s WebDAV functionality. An unauthenticated attacker who…
-
Critical WordPress Plugin Flaw Allows Unauthenticated Administrator Account Takeover
A critical authentication bypass vulnerability has been identified in the WPMU DEV Dashboard WordPress plugin, which could allow unauthenticated attackers to gain administrator-level access to vulnerable sites configured with Hub Single Sign-On (SSO). This vulnerability, tracked as CVE-2026-76581, has a CVSS score of 9.8 and affects WPMU DEV Dashboard versions 5.0.1 and earlier. The plugin…
-
Why We Switched From WorkOS to SSOJet for Enterprise SSO (and Saved $5,000 a Year)
GrackerAI switched enterprise SSO from WorkOS to SSOJet, cut the annual bill by roughly $5,000, and gained the custom authentication flexibility an AI platform needs. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/why-we-switched-from-workos-to-ssojet-for-enterprise-sso-and-saved-5000-a-year/
-
CVE-2026-65400: macOS Screen Sharing Authentication Bypass Under Active Exploitation
First seen on resecurity.com Jump to article: www.resecurity.com/blog/article/cve-2026-65400-macos-screen-sharing-authentication-bypass-under-active-exploitation
-
CVE-2026-65400: macOS Screen Sharing Authentication Bypass Under Active Exploitation
First seen on resecurity.com Jump to article: www.resecurity.com/blog/article/cve-2026-65400-macos-screen-sharing-authentication-bypass-under-active-exploitation
-
SonarQube Hunter Agent is now GA: Catch broken access control and business logic flaws
SonarQube Hunter Agent uses AI to detect broken access control, business logic flaws, and authentication vulnerabilities traditional SAST can miss. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/sonarqube-hunter-agent-is-now-ga-catch-broken-access-control-and-business-logic-flaws/
-
Critical Veeam ONE Flaw Lets Unauthenticated Attackers Coerce SMB Authentication From Service Accounts
Veeam has released security updates for a critical vulnerability in Veeam ONE that could allow an unauthenticated network attacker to coerce SMB authentication from the account running an affected service. Tracked as CVE-2026-65641, the vulnerability received a CVSS v4.0 severity score of 9.3. Veeam disclosed the issue through Knowledge Base article 4905, published on August…
-
Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts
Tags: access, authentication, credentials, cyber, espionage, exploit, flaw, infrastructure, phishing, russia, softwareRussian-linked cyber espionage operators are expanding account-compromise operations by combining OAuth abuse, device-code phishing, credential-harvesting infrastructure, and suspected Evilginx reverse-proxy setups. GTIG assesses with moderate confidence that UNC6293 is an initial-access subcluster of ICE RELIC, formerly tracked as APT29, Cozy Bear, and Midnight Blizzard. Rather than exploiting a software flaw, the operators abuse legitimate authentication…
-
AnonyMousKIT PhaaS Automates Apple ID, Device Passcode, and Live 2FA Harvesting Across Five Channels
AnonyMousKIT, an AI-enabled Phishing-as-a-Service (PhaaS) platform built to turn stolen Apple devices into monetizable assets. The service automates the collection of an owner’s device passcode, Apple ID credentials and live two-factor authentication (2FA) codes information that can enable criminals to remove Activation Lock and resell a stolen device. Rather than relying on a single phishing…
-
Ubiquiti Fixes 22 UniFi Flaws Enabling Command Injection, Authentication Bypass and Privilege Escalation
Ubiquiti has released security updates to address 22 vulnerabilities across its UniFi ecosystem. These updates include multiple critical flaws that could allow unauthenticated command injection, authentication bypass, and privilege escalation on exposed devices. Documented in Security Advisory Bulletin 067 and published on August 26, 2026, these vulnerabilities affect several components, including UniFi OS, UniFi Protect,…
-
Apache Tomcat Flaws Let Attackers Bypass Authentication and Security Controls, Trigger DoS Attacks
Apache has released version 11.0.25 of Apache Tomcat to address ten security vulnerabilities, including multiple flaws that could lead to authentication bypasses, access-control evasion, and denial-of-service (DoS) conditions. The most serious issues affect Tomcat’s processing of security constraints, authentication mechanisms, HTTP/2 implementation, and behavior of the RewriteValve. All ten vulnerabilities impact releases of Apache Tomcat…
-
Kritische Schwachstellen zur Ausweitung von Active-Directory-Rechten
‘ResetNightmare” und ‘KerberLoss” nutzen Schwächen von Identitätssystemen in der Interpretation von Benutzer- und Dienstnamen aus, wodurch Angreifer möglicherweise Dienste stören, die Authentifizierung untergraben oder sich als privilegierte Benutzer ausgeben können. Der Experte für identitätsbasierte Cyber-Resilienz und Krisenbewältigung, Semperis, gab bekannt, dass Shai Laron, Sicherheitsforscher bei Semperis, zwei kritische Sicherheitslücken in Active-Directory (AD) entdeckt hat, die…
-
Snowflake ends service-account passwords. Now comes the hard part
Snowflake is ending password authentication for legacy service accounts, forcing organizations to migrate them to passwordless methods. Token Security explains why the harder challenge is identifying what uses each account, who owns it, and how much access it still needs. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/snowflake-ends-service-account-passwords-now-comes-the-hard-part/
-
Your Coding Assistant Is Shipping Security Vulnerabilities
Tags: access, ai, api, application-security, authentication, compliance, credentials, email, endpoint, framework, github, governance, LLM, programming, risk, service, tool, vulnerabilityYour Coding Assistant Is Shipping Security Vulnerabilities. Here’s How to Fix That. AI coding assistants have gotten remarkably good at writing functional code. Syntax correctness rates are approaching 100%. Developers are more productive than ever. And yet the security picture tells a very different story. Veracode recently evaluated over 150 large language models across vendors…
-
The Complete Account Security Checklist for Modern Web Applications
Use this account security checklist to protect modern web applications with stronger authentication, secure sessions, access controls, and secure recovery. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-complete-account-security-checklist-for-modern-web-applications/
-
WhatsApp Passkeys Now Protect Over 1 Billion Users Against Account Takeover Attacks
WhatsApp has announced that over one billion people now use passkeys to secure their accounts, enhancing phishing-resistant authentication across one of the world’s largest messaging platforms. This update, revealed on August 25, introduces support for multiple passkeys, stronger two-step verification credentials, and additional context for calls from unknown numbers. These changes target common account takeover…
-
Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable
Two CVSS 9.8 miniOrange SAML WordPress plugin auth bypasses were exploited while paid editions never appeared in any vulnerability database. Manual patch required. Two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On WordPress plugin, both rated CVSS 9.8, are under active exploitation. Both CVE-2026-61979 and CVE-2026-15981 allow an unauthenticated attacker to…
-
Researchers warn about chained SharePoint sequence
An authentication bypass flaw is already under exploitation, the latest in a series of recent SharePoint attacks.; First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/researchers-warn-about-chained-sharepoint-sequence/828726/
-
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators.The vulnerabilities, as disclosed by Patchstack, are listed below – CVE-2026-61979 (CVSS score: 8.1) – An unauthenticated privilege escalation…
-
German Cyber Agency Warns Fingerprints Can Be Spoofed
BSI Says AI, High-Resolution Photos and 3D Printing Increase Biometric Risks. Germany’s cybersecurity agency is warning against relying solely on fingerprint authentication, saying criminals can use high-resolution photos, AI and 3D printing to create synthetic fingerprints capable of spoofing some biometric systems. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/german-cyber-agency-warns-fingerprints-be-spoofed-a-32643
-
Hackers target WordPress sites in miniOrange auth bypass attacks
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks/
-
Cudy WR3000 Router Flaws Can Be Chained to Gain Root Access
Public exploit tools for 2 Cudy WR3000 flaws can forge JWTs, bypass MQTT authentication, and remotely execute operating-system commands as root on the router. First seen on hackread.com Jump to article: hackread.com/cudy-wr3000-router-flaws-chained-root-access/
-
Doubloon Dredger Abuses Notion to Harvest Authentication Tokens
Doubloon Dredger abused Notion and malicious PDFs to harvest Microsoft authentication tokens First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/doubloon-dredger-notion/
-
Kühlketten in Gefahr
Die Sicherheitsforscher von Team82, der Forschungsabteilung des Spezialisten für die Sicherheit von cyberphysischen Systemen (CPS) Claroty, haben Schwachstellen in weitverbreiteten Steuerungssystemen für Kühlanlagen entdeckt. In der Danfos- AK-SM 800A-Plattform identifizierten die Experten Sicherheitslücken, durch die sich die Authentifizierung umgehen und Remote-Code ausführen lässt. Bei der Copeland-XWEB-Pro-Plattform konnte Team82 insgesamt 23 Sicherheitslücken aufdecken, durch die Sicherheitsmechanismen…

