Tag: authentication
-
Critical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command Execution
A critical flaw (CVSS 9.4) in NASA/JPL’s AIT-GUI let anyone send unauthenticated commands to spacecraft instruments. Cycode researchers found that AIT-GUI, the browser-based operator console in NASA/JPL open-source AMMOS Instrument Toolkit, shipped with no authentication, no session checks, and no CSRF protection on any of its state-changing endpoints. >>AIT-GUI, the web front end of NASA/JPL’s…
-
Machine Identity for the AI Era: Building Doppel API V2 With OAuth 2.0
How we introduced organization-bound machine authentication while preserving the API contract customers already know. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/machine-identity-for-the-ai-era-building-doppel-api-v2-with-oauth-2-0/
-
That Legitimate OAuth Login Might Be a Russian Hack
Attackers Use Real Google and Microsoft Authentication Before Redirecting Victims. Google says three Russia-linked espionage clusters are abusing legitimate Google and Microsoft authentication flows to steal tokens and account access from defense, government, academic and think tank targets, exposing a visibility gap around personal accounts. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/that-legitimate-oauth-login-might-be-russian-hack-a-32634
-
Microsoft Patches Entra ID RCE Vulnerability Exploited in Attacks
Microsoft patched an Entra ID RCE vulnerability exploited in attacks that required no authentication or user interaction. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/microsoft-patches-entra-id-rce-vulnerability-exploited-in-attacks/
-
Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics
Tags: access, authentication, conference, cyber, defense, espionage, google, group, intelligence, phishing, russia, tactics, threat, toolGoogle tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff. Google’s Threat Intelligence Group tracked three separate suspected Russia-linked cyber espionage clusters. All three focus on the same thing: abusing authentication features that are supposed to protect accounts to access them instead. Threat actors target researchers,…
-
Critical N-Able PassPortal Extension Flaw Gives Attackers Full Password Vault Access
Tags: access, authentication, control, cve, cvss, cyber, cybersecurity, flaw, malicious, password, vulnerabilityCybersecurity researchers have revealed a critical vulnerability in N-able’s PassPortal browser extension that could have allowed a malicious website or embedded iframe to obtain authentication materials and take control of a user’s password vault. This vulnerability, tracked as CVE-2026-15580, affects PassPortal version 3.49.5 and has a CVSS v4.0 base score of 9.4. It was patched…
-
Russia-Linked Hackers Exploit Legitimate Login Flows to Bypass 2FA and Steal Account Access
Tags: 2fa, access, authentication, credentials, cyber, defense, espionage, exploit, government, hacker, login, password, russiaThree suspected Russian cyber espionage clusters abusing legitimate authentication mechanisms to hijack accounts belonging to academics, diplomats, defense personnel, government staff, and think-tank researchers across Europe and the United States. Rather than relying solely on credential-harvesting pages, the operators manipulate users into completing genuine app-password, OAuth, device-code, and device-linking workflows that can hand attackers authenticated…
-
Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)
Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw tracked as CVE-2026-19490, and is urging … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/21/citrix-netscaler-gateway-cve-2026-19490/
-
Bis zu 12.000 Systeme gefährdet: Zimbra-Server werden attackiert
Eine gefährliche Sicherheitslücke lässt Angreifer ohne Authentifizierung Schadcode auf Zimbra-Server schleusen. Angriffe laufen bereits. First seen on golem.de Jump to article: www.golem.de/news/bis-zu-12-000-systeme-gefaehrdet-zimbra-server-werden-attackiert-2608-212151.html
-
Password spraying attacks surge 155x, exploiting legacy authentication flaws
First seen on scworld.com Jump to article: www.scworld.com/brief/password-spraying-attacks-surge-155x-exploiting-legacy-authentication-flaws
-
Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S.These clusters include UNC6293, UNC7005, and UNC5976.”These clusters engage in persistent, adaptive First seen on…
-
Horizon3.ai alternatives in 2026: Escape vs NodeZero and 4 more tools
Escape is the best Horizon3.ai alternative for continuous AI pentesting across APIs, web apps, and complex authentication, including regression testing, developer-ready remediation, and platform pricing suited for rapidly scaling orgs. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/horizon3-ai-alternatives-in-2026-escape-vs-nodezero-and-4-more-tools/
-
Horizon3.ai alternatives in 2026: Escape vs NodeZero and 4 more tools
Escape is the best Horizon3.ai alternative for continuous AI pentesting across APIs, web apps, and complex authentication, including regression testing, developer-ready remediation, and platform pricing suited for rapidly scaling orgs. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/horizon3-ai-alternatives-in-2026-escape-vs-nodezero-and-4-more-tools/
-
Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability.According to the cloud computing and virtualization technology company, the issues affect customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as well as SecurAccess First seen on thehackernews.com Jump to…

