HackMyIP

Authentication News

132 stories tagged Authentication

← All cybersecurity news

2026-08-14Dark Reading
Cyera's $1B Oasis Security Buy Redefines AI Agent Access Control

Cyera has announced a $1 billion acquisition of Oasis Security, signaling one of the largest deals in the data security space this year and a clear bet that the next frontier of...

AI SecurityCloud SecurityAuthentication
Read More → Use Tool →
2026-08-13SecurityWeek
WordPress 7.0.4 Patches Critical RCE Flaw CVE-2026-65640

WordPress released version 7.0.4 on Wednesday to address a high-severity remote code execution vulnerability tracked as CVE-2026-65640, carrying a CVSS score of 8.8. The flaw allow...

VulnerabilityAuthentication
Read More → Use Tool →
2026-08-13SecurityWeek
Adobe Commerce CVE-2026-71362 Exploited Within Hours of Patch Release

Hackers began exploiting a critical Adobe Commerce vulnerability almost immediately after Adobe published its patch advisory, according to webstore security firm Sansec. Tracked as...

VulnerabilityAuthenticationZero-Day
Read More → Use Tool →
2026-08-13Dark Reading
Critical Flaw in Belgium's eID Extension Exposes Citizens to Remote Code Execution

A series of severe vulnerabilities discovered in the browser extension powering Belgium's national electronic identification (eID) system could allow attackers to execute arbitr...

VulnerabilityAuthentication
Read More → Use Tool →
2026-08-13SecurityWeek
21 Cybersecurity M&A Deals Reshape Industry in July 2026

Twenty-one cybersecurity-related merger and acquisition deals were announced in July 2026, signaling continued consolidation across identity protection, AI-driven detection, and ne...

Cloud SecurityAI SecurityAuthentication
Read More → Use Tool →
2026-08-13The Hacker News
SharePoint CVE-2026-55040 Under Active Attack After Rapid7 PoC Release

Threat actors are actively weaponizing a critical Microsoft SharePoint authentication bypass vulnerability, CVE-2026-55040, following the public release of a proof-of-concept (PoC)...

VulnerabilityAuthenticationThreat Intel
Read More → Use Tool →
2026-08-12The Hacker News
SAP Patches Critical Commerce Cloud Flaw Enabling Remote Code Execution

SAP has rolled out emergency patches for a maximum-severity vulnerability in SAP Commerce Cloud (Data Hub Adapter) that could allow unauthenticated attackers to execute arbitrary c...

VulnerabilityCloud SecurityAuthentication
Read More → Use Tool →
2026-08-12SecurityWeek
SharePoint Auth Bypass CVE-2026-55040 Exploited After Rapid7 PoC Release

Microsoft's July Patch Tuesday addressed CVE-2026-55040, a SharePoint vulnerability rooted in weak authentication that allows remote, unauthenticated attackers to bypass securit...

VulnerabilityAuthenticationThreat Intel
Read More → Use Tool →
2026-08-12The Record
FBI Warns: Hackers Use Social Engineering to Hijack Accounts and Steal Explicit Content

The FBI has issued a new public alert warning that threat actors are increasingly using social engineering and cyber intrusion techniques to compromise social media accounts belong...

PhishingAuthenticationPrivacy
Read More → Use Tool →
2026-08-12The Hacker News
Adobe Fixes Three CVSS 10.0 Flaws in ColdFusion & Campaign Classic

Adobe has rolled out emergency patches addressing multiple critical security vulnerabilities across ColdFusion, Commerce, and Campaign Classic that could allow attackers to execute...

VulnerabilityCloud SecurityAuthentication
Read More → Use Tool →
2026-08-11The Hacker News
Malicious SIM Card Flaw Exposes Cellular IoT Devices to Remote Takeover

A malicious SIM card can run attacker-controlled code directly inside the cellular modems powering electric-vehicle chargers, industrial routers, and automotive telematics units, a...

VulnerabilitySupply ChainAuthentication
Read More → Use Tool →
2026-08-11Dark Reading
Gunra Ransomware Gang Exploits Fortinet Flaws to Bypass MFA

The Gunra ransomware-as-a-service (RaaS) operation has emerged as a significant threat to critical infrastructure organizations, leveraging leaked Conti source code and weaponizing...

RansomwareVulnerabilityAuthentication
Read More → Use Tool →
2026-08-10The Record
Russian APT Breached Polish Heat Plant via Cellular Network & Default Credentials

Poland's CERT Polska has disclosed a previously unknown cyberattack that disrupted a combined heat and power (CHP) plant supplying heat to roughly 50,000 residents during last wint...

APTThreat IntelAuthentication
Read More → Use Tool →
2026-08-10Dark Reading
Critical Metabase SQL Zero-Day Flaw Exposes Admin Access Without CVE

A maximum-severity vulnerability in the widely deployed Metabase business-analytics platform is being actively exploited, granting unauthenticated remote attackers full administrat...

Zero-DayVulnerabilityAuthentication
Read More → Use Tool →
2026-08-10SecurityWeek
Critical Flaws in Belgian eID Software Exposed 2 Million Users

Security researcher James Arnott, founder of cybersecurity firm Bay Area Labs, disclosed severe vulnerabilities in the Connective digital identity system, a browser extension devel...

VulnerabilityBug BountyAuthentication
Read More → Use Tool →
2026-08-08The Hacker News
New CSS Attacks Break Webmail Defenses to Steal Passwords and Tokens

PortSwigger researcher Gareth Heyes presented a new class of CSS-based webmail attacks at Black Hat USA 2026, demonstrating how content inside an email can escape its message bound...

VulnerabilityPhishingAuthentication
Read More → Use Tool →
2026-08-08The Hacker News
N-able N-central Hotfix 2 Released as Attackers Exploit CVE-2026-18577

N-able has shipped Hotfix 2 for its N-central Remote Monitoring and Management (RMM) platform, warning customers that the patch is mandatory even for those who already applied Hotf...

Zero-DayVulnerabilityAuthentication
Read More → Use Tool →
2026-08-07The Hacker News
Critical WordPress Login XSS Flaw (CVE-2026-64638) Enables RCE — Patch Now

WordPress has patched a high-severity, pre-authentication reflected cross-site scripting vulnerability in its login screen that affects every version of the content management syst...

VulnerabilityZero-DayAuthentication
Read More → Use Tool →
2026-08-07The Hacker News
Microsoft 365 AitM Phishing Campaign Hijacks Payroll Accounts

Arctic Wolf Labs has revealed a widespread adversary-in-the-middle (AitM) phishing campaign targeting Microsoft 365 accounts at organizations across healthcare, education, manufact...

PhishingAuthenticationThreat Intel
Read More → Use Tool →
2026-08-06KrebsOnSecurity
Canadian Hacker Pleads Guilty in $2.5M Snowflake Data Breach Extortion

Connor Riley Moucka, of Kitchener, Ontario, has pleaded guilty to computer fraud and conspiracy charges stemming from a massive 2024 extortion campaign that compromised more than 1...

Data BreachCloud SecurityAuthentication
Read More → Use Tool →
2026-08-06Dark Reading
Inside the DNC's Security-First Culture: Lessons from Former CSOs

When Bob Lord joined the Democratic National Committee as its first-ever chief security officer in the aftermath of the 2016 election breach, he inherited an organization still ree...

Incident ResponseAuthenticationPrivacy
Read More → Use Tool →
2026-08-05The Hacker News
Paperclip AI Flaws Expose Servers to RCE via Malicious Agent Imports

Two critical security vulnerabilities in Paperclip, an open-source control plane for managing teams of AI agents, could allow attackers to execute arbitrary host commands on a netw...

AI SecurityVulnerabilityAuthentication
Read More → Use Tool →
2026-08-05The Hacker News
Veeam, Terraform MCP, Django Patch 11 Critical Flaws Including CVSS 10.0

Three major software vendors — Veeam, HashiCorp, and the Django Software Foundation — released patches on August 5, 2026, addressing 11 vulnerabilities across Terraform MCP Server,...

VulnerabilityCloud SecurityAuthentication
Read More → Use Tool →
2026-08-05The Hacker News
Critical Gitea Flaw (CVE-2026-59774) Lets Attackers Read Server Files Without Login

A critical vulnerability in Gitea, the self-hosted Git platform, allows unauthenticated attackers to read any file the service account can access—no login or repository write acces...

VulnerabilityCloud SecurityAuthentication
Read More → Use Tool →
2026-08-04The Hacker News
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has evolved into a more dangerous offering, adding support for device code phishing to its existing arsenal ...

PhishingAuthenticationThreat Intel
Read More → Use Tool →
2026-08-04The Hacker News
Critical cPanel Flaw Lets Hosting Users Hijack Database Root Access

cPanel has shipped an emergency patch for a critical privilege-escalation vulnerability that lets authenticated hosting customers execute arbitrary SQL commands with full database-...

VulnerabilityCloud SecurityAuthentication
Read More → Use Tool →
2026-08-04The Hacker News
CISA Flags N-able N-central Auth Bypass Flaw After Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity vulnerability in N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog fo...

VulnerabilityAuthenticationIncident Response
Read More → Use Tool →
2026-08-04Dark Reading
Device Code Phishing Surges 1,500% as Vishing Attacks Double in 2026

Attackers are rapidly abandoning traditional credential-stealing campaigns in favor of social engineering techniques that sidestep multi-factor authentication and leave minimal for...

PhishingAuthenticationThreat Intel
Read More → Use Tool →
2026-08-03Dark Reading
Attackers Exploit N-able RMM Patch Bypass for Admin Access

Over the weekend, N-able disclosed a critical authentication bypass vulnerability tracked as CVE-2026-18577 affecting its Remote Monitoring and Management (RMM) platform. The flaw ...

VulnerabilityAuthentication
Read More → Use Tool →
2026-08-03The Hacker News
Google Password Manager Passkey Attacks Expose Post-Compromise Risks

Researchers at Palo Alto Networks' Unit 42 have uncovered three attack paths against Chrome's Google Password Manager cloud authenticator that could allow malware running as a stan...

VulnerabilityAuthenticationMalware
Read More → Use Tool →
2026-07-31Dark Reading
USA Fencing Automates Identity Verification to Secure Amateur Athletes

USA Fencing, the national governing body for the sport and the organization responsible for fielding Team USA's Olympic and Paralympic fencing squads, has deployed automated ide...

AuthenticationPrivacyAI Security
Read More → Use Tool →
2026-07-31The Hacker News
Device Code Phishing: Why It's 2026's Fastest-Growing Threat

Device code phishing, the abuse of the OAuth 2.0 device authorization grant to hijack access tokens, has escalated from a niche red-team technique into an industrial-scale threat i...

PhishingAuthenticationThreat Intel
Read More → Use Tool →
2026-07-30The Hacker News
Cisco FMC Zero-Day Actively Exploited via Static Credentials

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a newly disclosed flaw in Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited V...

Zero-DayVulnerabilityAuthentication
Read More → Use Tool →
2026-07-29The Hacker News
Critical Rails Vulnerability CVE-2026-66066 Exposes Server Secrets via Image Uploads

Ruby on Rails has shipped emergency patches for a critical Active Storage vulnerability, tracked as CVE-2026-66066 with a CVSS score of 9.5, that enables unauthenticated attackers ...

VulnerabilityCloud SecurityAuthentication
Read More → Use Tool →
2026-07-29The Hacker News
Critical VMware Flaws Enable Auth Bypass, Code Execution, and VM Escape

Broadcom has shipped urgent security updates to address five vulnerabilities affecting VMware ESX, vCenter Server, Workstation, and Fusion, three of which carry critical severity r...

VulnerabilityCloud SecurityAuthentication
Read More → Use Tool →
2026-07-29The Hacker News
Check Point CVE-2026-16232: PoC Released for SmartConsole Auth Bypass

Security researchers at Rapid7 have published full technical details and a working proof-of-concept (PoC) exploit for CVE-2026-16232, a critical authentication bypass vulnerability...

VulnerabilityZero-DayAuthentication
Read More → Use Tool →
2026-07-28Dark Reading
Dormant Cloud Credentials: Hidden Identity Risks Exposed by NHI Hound

Security researcher Aleksandr Krasnov has spotlighted a growing blind spot in cloud environments: dormant non-human identities (NHIs) that retain trust paths long after they should...

Cloud SecurityAuthenticationVulnerability
Read More → Use Tool →
2026-07-28Dark Reading
Thousands of Exposed Data Center BMCs Vulnerable to Password Cracking

Thousands of internet-exposed Baseboard Management Controllers (BMCs) and similar remote hardware management interfaces are vulnerable to offline password-cracking attacks, and thr...

VulnerabilityAuthenticationThreat Intel
Read More → Use Tool →
2026-07-28The Hacker News
24,650 BMCs Leak IPMI Password Hashes Before Login — CVE-2013-4784 Still Unpatched

Cybersecurity researchers at Israeli firm Lava have identified more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing the Intelligent Platform Manage...

VulnerabilityAuthenticationCloud Security
Read More → Use Tool →
2026-07-28The Hacker News
Critical TeamCity RCE Flaw (CVSS 9.8) Lets Hackers Bypass Authentication

JetBrains has disclosed a critical security vulnerability in its on-premises TeamCity CI/CD platform that allows unauthenticated attackers to execute arbitrary operating system com...

VulnerabilityAuthenticationZero-Day
Read More → Use Tool →
2026-07-27Dark Reading
Confused Deputy Flaws Expose Admin Access in Google Cloud and Azure

A class of vulnerabilities known as 'Confused Deputy' flaws continues to plague major cloud platforms, including Google Cloud and Microsoft Azure, according to researchers tracking...

Cloud SecurityVulnerabilityAuthentication
Read More → Use Tool →
2026-07-25The Hacker News
Insurance Phishing Now Hijacks Accounts in Real Time via Google Ads

A new investigation from CTM360, published via The Hacker News, reveals that insurance-focused phishing operations have evolved beyond traditional credential harvesting into real-t...

PhishingThreat IntelAuthentication
Read More → Use Tool →
2026-07-24The Hacker News
Certighost AD CS Flaw Lets Users Impersonate Domain Controllers (CVE-2026-54121)

Security researchers H0j3n and Aniq Fakhrul have publicly released a working exploit, dubbed Certighost, that allows a low-privileged Active Directory user to obtain a certifica...

VulnerabilityAuthentication
Read More → Use Tool →
2026-07-24Dark Reading
Azure Automation Flaw Enabled Cross-Tenant Identity Takeover

Microsoft has patched a critical configuration flaw in Azure Automation that, combined with a chain of code vulnerabilities, could have allowed attackers to take over identities be...

Cloud SecurityVulnerabilityAuthentication
Read More → Use Tool →
2026-07-24The Record
Wrench Attacks on Crypto Holders Surge 33% in First Half of 2026

Cryptocurrency holders are increasingly being targeted through physical-world coercion rather than purely digital exploits, according to a new report from blockchain security audit...

Threat IntelPrivacyAuthentication
Read More → Use Tool →
2026-07-24The Hacker News
Beyond AI Agent Visibility: Why Security Teams Must Enforce Least Privilege

AI agent security is rapidly maturing through a familiar enterprise cycle: adoption, visibility, and finally, control. But as organizations discover, enforcing least privilege for ...

AI SecurityAI ThreatsAuthentication
Read More → Use Tool →
2026-07-23Ars Technica
Google Selfie Video Login: New Way to Reset Passwords & Verify Age

Google has introduced a password recovery method that lets users regain access to their accounts by recording a short selfie video. The biometric verification system, detailed by A...

AuthenticationPrivacyAI Security
Read More → Use Tool →
2026-07-23The Hacker News
RefluXFS: 9-Year-Old Linux Flaw Grants Root on Default RHEL Systems

Qualys has disclosed a nine-year-old Linux kernel vulnerability, tracked as CVE-2026-64600 and nicknamed RefluXFS, that enables unprivileged local users to overwrite root-owned fil...

VulnerabilityAuthenticationCloud Security
Read More → Use Tool →
2026-07-23The Hacker News
Check Point Patches Critical SmartConsole Auth Bypass Exploited in the Wild

Check Point has shipped emergency security updates to remediate multiple high-severity flaws affecting its Security Management and Multi-Domain Security Management (MDSM) products,...

VulnerabilityAuthenticationIncident Response
Read More → Use Tool →
2026-07-22The Hacker News
Critical Windmill Path Traversal Bug Under Active Attack — 170 Servers Exposed

A high-severity path traversal vulnerability in the open-source Windmill developer platform is being actively exploited in the wild, according to threat intelligence from VulnCheck...

VulnerabilityAuthenticationCloud Security
Read More → Use Tool →
2026-07-22The Hacker News
Kratos Phishing Kit Takedown: 200+ Servers Offline, Developer Arrested

German and US law enforcement have dismantled the core infrastructure of Kratos, a phishing-as-a-service kit investigators describe as one of the most widely used criminal phishing...

PhishingAuthenticationIncident Response
Read More → Use Tool →
2026-07-21The Hacker News
Qilin Ransomware Exploits PAN-OS Authentication Bypass Vulnerability

Threat actors affiliated with the Qilin (also known as Agenda) ransomware-as-a-service (RaaS) operation have been weaponizing a now-patched high-severity flaw in Palo Alto Networks...

RansomwareVulnerabilityAuthentication
Read More → Use Tool →
2026-07-16The Hacker News
Scattered Spider Hackers Jailed 5.5 Years Each for £29M TfL Cyberattack

Owen Flowers, 18, and Thalha Jubair, 20, members of the Scattered Spider cybercrime group, were each sentenced to five and a half years at Woolwich Crown Court on 16 July 2026 for ...

Data BreachRegulationAuthentication
Read More → Use Tool →
2026-07-16The Hacker News
Critical Unpatched Shark Vacuum Flaw Lets Attackers Seize Devices Region-Wide

A serious unpatched vulnerability in SharkNinja robot vacuums allows attackers to extract device certificates from the hardware and use them to issue commands on other Shark vacuum...

VulnerabilityCloud SecurityAuthentication
Read More → Use Tool →
2026-07-15Dark Reading
Identity Attacks Eclipse Exploits as Top Ransomware Root Cause

Identity-based attacks have dethroned vulnerability exploits as the leading root cause of ransomware intrusions, marking a significant shift in attacker tradecraft, according to re...

RansomwareAuthenticationPhishing
Read More → Use Tool →
2026-07-13The Hacker News
Misconfigured Server Exposes Three Evilginx Phishing Operations Targeting M365

A single misconfiguration handed French security firm Lexfo an intelligence windfall. During a routine internet scan in late April 2026, researchers found an attacker-controlled ho...

PhishingThreat IntelAuthentication
Read More → Use Tool →
2026-07-09The Hacker News
npm 12 Disables Install Scripts by Default to Cut Supply Chain Risk

GitHub has officially released npm 12, the latest version of the world's most widely used JavaScript package manager, with a major security-focused overhaul that disables install s...

Supply ChainAuthenticationVulnerability
Read More → Use Tool →
2026-07-09The Hacker News
AI-Powered Attacks Move in Minutes: Zero Trust Defense Strategies

AI-powered attacks have compressed the attacker's timeline from days to minutes. Using models like "Mythos," adversaries generate tailored phishing bait, identify high-value target...

AI SecurityAI ThreatsAuthentication
Read More → Use Tool →
2026-07-07Dark Reading
Fake Big-Brand Job Listings Steal Google Logins from Marketers

A sophisticated phishing campaign is weaponizing the names of well-known consumer brands to lure marketing professionals into surrendering their Google Workspace credentials. Resea...

PhishingThreat IntelAuthentication
Read More → Use Tool →
2026-07-07The Hacker News
DEBULL Tooling Exploits Microsoft Device-Code Flow in M365 Phishing

A new Microsoft 365 device-code phishing campaign observed between late June and early July 2026 is leveraging a reusable attack framework dubbed DEBULL to hijack enterprise accoun...

PhishingAuthenticationThreat Intel
Read More → Use Tool →
2026-07-07The Hacker News
BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support, PRA

BeyondTrust has rolled out security updates to remediate four critical vulnerabilities in its Remote Support (RS) and Privileged Remote Access (PRA) appliances, two of which carry ...

VulnerabilityAuthenticationAI Security
Read More → Use Tool →
2026-07-06The Hacker News
Critical Gitea Docker Flaw CVE-2026-20896 Actively Exploited Within Days

Threat actors began probing a critical security flaw in Gitea Docker images just 13 days after public disclosure, according to cloud security firm Sysdig. Tracked as CVE-2026-20896...

VulnerabilityCloud SecurityAuthentication
Read More → Use Tool →
2026-07-03BleepingComputer
ARToken PhaaS Exposes EvilTokens Microsoft 365 Phishing Toolkit

Cisco Talos researchers have uncovered a phishing-as-a-service (PhaaS) platform named “ARToken” that operates as an affiliate of the EvilTokens ecosystem, exposing a sophisticated ...

PhishingThreat IntelAuthentication
Read More → Use Tool →
2026-07-03The Hacker News
PamStealer macOS Malware Steals Login Passwords via Fake Maccy Sites

A new macOS information stealer dubbed PamStealer has been identified by Jamf Threat Labs, employing a multi-stage infection chain designed to harvest login credentials, browser da...

MalwareAuthenticationThreat Intel
Read More → Use Tool →
2026-07-02The Hacker News
ToddyCat's Umbrij Malware Exploits OAuth Tokens to Hijack Gmail Sessions

Kaspersky researchers have uncovered a sophisticated new malware dubbed Umbrij, attributed to the advanced persistent threat group ToddyCat, which leverages the Google API and OAut...

APTMalwareAuthentication
Read More → Use Tool →
2026-07-02The Hacker News
Why Traditional Identity Lifecycle Management Breaks Down for AI Agents

Enterprise identity lifecycle management was architected around a human employee with an HR record, a reporting manager, and a defined departure date. AI agents possess none of the...

AI SecurityAuthenticationRegulation
Read More → Use Tool →
2026-07-01The Hacker News
Azure CLI Password Spray Compromises 78 Microsoft Accounts in 81M+ Attempts

Cybersecurity researchers at Huntress have uncovered a massive, ongoing automated password spray campaign targeting Microsoft's Azure command-line interface (CLI), generating more ...

Cloud SecurityAuthenticationThreat Intel
Read More → Use Tool →
2026-06-30The Hacker News
SimpleHelp CVE-2026-48558 Exploited to Deploy TaskWeaver, Djinn Stealer

An unknown threat actor is actively exploiting CVE-2026-48558, a maximum-severity (CVSS 10.0) authentication bypass flaw in SimpleHelp's OpenID Connect (OIDC) flow, to deploy two p...

VulnerabilityMalwareAuthentication
Read More → Use Tool →
2026-06-30SecurityWeek
Daktronics Controller Flaws Let Hackers Hijack Highway Signs

Critical and high-severity vulnerabilities in Daktronics controllers could allow remote attackers to tamper with highway signs, electronic scoreboards, and digital billboards world...

VulnerabilityAuthenticationBug Bounty
Read More → Use Tool →
2026-06-29The Hacker News
WhatsApp Rolls Out Usernames to Protect Phone Number Privacy

WhatsApp, the Meta-owned messaging platform used by more than three billion people, officially began global username reservations on Monday. The new optional feature allows users t...

PrivacyAuthentication
Read More → Use Tool →
2026-06-29The Hacker News
Post-Quantum Cryptography: Why Credentials Are the First Target

The public-key cryptography protecting today's credentials and encrypted data faces an expiration date. While no existing machine can crack RSA or elliptic curve cryptography, quan...

EncryptionAuthenticationRegulation
Read More → Use Tool →
2026-06-28BleepingComputer
KDDI Breach Exposes 14.2M Email Logins Across Six Japanese ISPs

Japanese telecommunications giant KDDI Corporation has disclosed a major data breach affecting up to 14.22 million email accounts across six domestic internet service providers. Th...

Data BreachVulnerabilityAuthentication
Read More → Use Tool →
2026-06-27The Hacker News
Russian Hackers Use Fake Signal Support Texts to Steal Messaging Credentials

Ukraine's Security Service (SSU), working alongside the U.S. Federal Bureau of Investigation (FBI), has uncovered a long-running cyber espionage campaign attributed to Russian inte...

PhishingAPTAuthentication
Read More → Use Tool →
2026-06-23KrebsOnSecurity
Scattered Spider Members Plead Guilty in Transport for London Cyberattack

Two key members of the prolific cybercrime group Scattered Spider pleaded guilty on the opening day of their six-week trial at a UK court. Thalha Jubair, 20, of East London, and 18...

RansomwarePhishingAuthentication
Read More → Use Tool →
2026-06-23The Hacker News
FortiBleed: 110M Credentials Stolen from 430K FortiGate Firewalls

A Russian-speaking initial access broker (IAB) has been linked to a massive credential-harvesting campaign called FortiBleed, which has compromised over 430,000 FortiGate firewalls...

Threat IntelVulnerabilityAuthentication
Read More → Use Tool →
2026-06-19BleepingComputer
Icarus Hackers Claim Klue OAuth Breach Exposing Salesforce Data

Market intelligence platform Klue has confirmed a security incident in which attackers exploited a compromised legacy credential to steal OAuth tokens, gaining access to multiple c...

Data BreachSupply ChainAuthentication
Read More → Use Tool →
2026-06-19The Hacker News
CISA Warns: FortiBleed Campaign Hits 86,644 FortiGate Devices Globally

CISA has issued an urgent advisory urging Fortinet customers to secure their FortiGate appliances against an ongoing malicious campaign dubbed FortiBleed, which has already comprom...

Data BreachAuthenticationThreat Intel
Read More → Use Tool →
2026-06-18The Hacker News
Orphaned AI Agents: Hidden Access Risks in Enterprise Networks

When an autonomous AI agent interacts with a company's core intellectual property, most security teams cannot instantly name the person who authorized it. The rush to deploy intern...

AI SecurityAuthenticationCloud Security
Read More → Use Tool →
2026-06-17BleepingComputer
Account Takeover Attacks Surge: How Attackers Bypass MFA in 2026

Organizations now manage thousands of human and non-human identities spread across cloud services, SaaS applications, endpoints, and remote environments. As hybrid work, BYOD polic...

AuthenticationPhishingThreat Intel
Read More → Use Tool →
2026-06-17The Hacker News
Top 10 Attack Surface Exposures of 2026: 60% of Organizations at Risk

A new analysis of 3,000 organizational attack surfaces reveals that unnecessary internet-facing services remain the weakest link in enterprise defense. Intruder's 2026 Attack Surfa...

VulnerabilityThreat IntelAuthentication
Read More → Use Tool →
2026-06-16The Hacker News
Rokarolla Android Trojan Targets 217 Banking and Crypto Apps With 137 Commands

Security researchers at Zimperium's zLabs have uncovered a new Android banking trojan dubbed Rokarolla, named after its command-and-control infrastructure. The malware targets 217 ...

MalwareThreat IntelAuthentication
Read More → Use Tool →
2026-06-16BleepingComputer
UK to Require ID or Face Scan for All New Social Media Accounts

The UK government will require anyone opening a new social media account to verify their age by uploading government-issued ID or passing a facial age scan, under regulations annou...

RegulationPrivacyAuthentication
Read More → Use Tool →
2026-06-15BleepingComputer
Critical SimpleHelp Flaw Lets Hackers Create Rogue Admin Accounts

A critical vulnerability in SimpleHelp remote management software, tracked as CVE-2026-48558, enables unauthenticated attackers to create privileged Technician accounts on servers ...

VulnerabilityAuthenticationIncident Response
Read More → Use Tool →
2026-06-15The Hacker News
Palo Alto Networks PAN-OS GlobalProtect VPN Flaw Actively Exploited

Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, a high-severity authentication bypass vulnerability (CVSS 7.8) affecting the GlobalProtect VPN portal and gat...

VulnerabilityAuthenticationThreat Intel
Read More → Use Tool →
2026-06-13BleepingComputer
Ex-IT Worker Gets 21 Months in Prison for Cyberattacks on Iowa School District

Ezekiel Dean Potter, a 34-year-old former senior IT support specialist for Iowa's Saydel Community School District, has been sentenced to 21 months in federal prison for a sustaine...

AuthenticationIncident ResponseData Breach
Read More → Use Tool →
2026-06-13The Hacker News
Critical Splunk Enterprise Flaw Enables Unauthenticated RCE via PostgreSQL Sidecar

Splunk has rolled out emergency security patches for a critical vulnerability in Splunk Enterprise that allows remote attackers to execute arbitrary code without any authentication...

VulnerabilityAuthenticationZero-Day
Read More → Use Tool →
2026-06-13BleepingComputer
Operation Highland: Velvet Ant APT Spied on Air-Gapped Network for 10 Years

The Chinese state-linked espionage group "Velvet Ant" maintained undetected access to a large organization's critical infrastructure for an extraordinary 10 years, according to res...

APTAuthenticationThreat Intel
Read More → Use Tool →
2026-06-12The Hacker News
China-Linked Velvet Ant APT Backdoored Linux Login Software for a Decade

A China-nexus advanced persistent threat tracked as Velvet Ant by incident response firm Sygnia maintained covert access to a target network for nearly a decade by compromising the...

APTAuthenticationSupply Chain
Read More → Use Tool →
2026-06-12BleepingComputer
Critical phpBB Auth Bypass Flaw Unpatched for 10 Years Exposes Admin Accounts

Security researchers at application security firm Aikido have disclosed a severe authentication bypass vulnerability in phpBB, the widely used open-source forum platform, that h...

AuthenticationVulnerabilityBug Bounty
Read More → Use Tool →
2026-06-12The Record
Coupang Hit With Record $409M Fine After Massive 33.7M User Data Breach

South Korea's Personal Information Protection Commission (PIPC) has imposed a record 624.7 billion won ($409 million) fine on Coupang, the country's largest online retailer, over a...

Data BreachRegulationAuthentication
Read More → Use Tool →
2026-06-10The Hacker News
Ivanti, Fortinet, SAP Patch Critical RCE and Auth Bypass Flaws

Fortinet, Ivanti, and SAP have rolled out urgent security updates addressing multiple critical vulnerabilities that could enable arbitrary code execution, authentication bypass, an...

VulnerabilityAuthenticationCloud Security
Read More → Use Tool →
2026-06-06BleepingComputer
Critical Everest Forms Pro Flaw Actively Exploited to Hijack WordPress Sites

Hackers are actively exploiting a critical unauthenticated remote code execution (RCE) vulnerability in the Everest Forms Pro WordPress plugin to seize full control of vulnerable w...

VulnerabilityAuthenticationThreat Intel
Read More → Use Tool →
2026-06-04The Hacker News
Cisco Unified CM SSRF Flaw (CVE-2026-20230): PoC Public, Full Patch Months Away

Cisco has released a patch for a server-side request forgery (SSRF) vulnerability in Unified Communications Manager (Unified CM) and its Session Management Edition that allows an u...

VulnerabilityThreat IntelAuthentication
Read More → Use Tool →
2026-06-03The Hacker News
Microsoft 365 Android Bug Let Any App Steal User Account Tokens

A single leftover debug flag in production builds of several Microsoft 365 Android applications disabled a critical security check, allowing any app installed on the same device to...

VulnerabilityAuthentication
Read More → Use Tool →
2026-06-03The Hacker News
One-Click GitHub.dev Attack Steals Full OAuth Tokens via VS Code

Cybersecurity researchers have disclosed a critical one-click attack chain that abuses Microsoft Visual Studio Code (VS Code) webviews to steal fully scoped GitHub OAuth tokens. Di...

VulnerabilityAuthenticationSupply Chain
Read More → Use Tool →
2026-06-03The Hacker News
IVIP: Closing the Identity Dark Matter Gap in Enterprise IAM

Enterprise identity and access management is approaching a structural breaking point. As organizations scale, identity data fragments across thousands of applications, decentralize...

AuthenticationAI SecurityCloud Security
Read More → Use Tool →
2026-06-03The Hacker News
Unpatched Windows Search URI Flaw Lets Attackers Steal NTLMv2 Hashes

Cybersecurity researchers at Huntress have disclosed an unpatched vulnerability in the Windows "search:" URI handler that can be weaponized to leak a user's NTLMv2 hash to a remote...

VulnerabilityAuthenticationThreat Intel
Read More → Use Tool →
2026-06-03BleepingComputer
Acer Wave 7 Routers Hit by Two Max-Severity Zero-Day Vulnerabilities

Acer has confirmed it is actively developing patches for two maximum-severity zero-day vulnerabilities impacting its Wave 7 mesh routers. Both flaws were reported by independent se...

Zero-DayVulnerabilityAuthentication
Read More → Use Tool →
2026-06-02BleepingComputer
Hackers Steal Instagram Accounts Using AI-Generated Selfies to Bypass Meta Verification

Attackers have hijacked multiple high-value Instagram accounts by exploiting Meta's AI-powered support assistant, tricking it into transferring ownership using deepfake selfie vide...

AI ThreatsAuthenticationDeepfake
Read More → Use Tool →
2026-06-02The Hacker News
Dashlane Confirms Brute-Force Attack Exposed Encrypted Vaults of Under 20 Users

Password manager Dashlane has disclosed a brute-force security incident in which encrypted password vaults belonging to fewer than 20 personal plan subscribers were downloaded by a...

Data BreachAuthenticationIncident Response
Read More → Use Tool →
2026-06-01BleepingComputer
Red Hat npm Supply Chain Attack Spreads Shai-Hulud 'Miasma' Malware

More than 30 npm packages under the @redhat-cloud-services namespace were compromised in a sophisticated supply‑chain attack that delivered a new variant of the Shai‑Hulud credenti...

Supply ChainMalwareAuthentication
Read More → Use Tool →
2026-05-30The Hacker News
CVE-2026-0257: PAN-OS GlobalProtect Bypass Actively Exploited

Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, a medium-severity authentication bypass vulnerability (CVSS 7.8) affecting PAN-OS and Prisma Access GlobalPro...

VulnerabilityAuthenticationZero-Day
Read More → Use Tool →
2026-05-28The Hacker News
Critical Gogs RCE Vulnerability Allows Code Execution

A critical security vulnerability has been disclosed in Gogs, a popular open-source self-hosted Git service, enabling authenticated users to execute arbitrary code on affected serv...

VulnerabilityZero-DayAuthentication
Read More → Use Tool →
2026-05-26The Hacker News
MFA Prompt Bombing: Push-Based 2FA Exploitation Explained

Multi-factor authentication (MFA) was designed to close a critical gap in identity security by requiring a second factor beyond passwords. However, attackers have developed a techn...

AuthenticationPhishingThreat Intel
Read More → Use Tool →
2026-05-22The Record
FBI Warns of Kali365 Phishing Service Targeting Microsoft 365

The FBI has issued a critical advisory regarding Kali365, a Telegram-based Phishing-as-a-Service (PhaaS) platform that enables cybercriminals to compromise Microsoft 365 accounts b...

PhishingCloud SecurityAuthentication
Read More → Use Tool →
2026-05-21The Hacker News
Identity is the Attack Path: Cloud Security Risks in 2025

A threat actor recently obtained an AWS access key cached on a developer's workstation through standard browser behavior—no misconfiguration or policy violation required. This sing...

Cloud SecurityAuthenticationAI Security
Read More → Use Tool →
2026-05-21Dark Reading
Enterprises Boost AI Agent Identity Security Budgets as Omdia Reveals Shifting Priorities

Organizations are dramatically increasing investments in AI agent identity management as enterprise deployments accelerate, according to new research from Omdia. The study reveals ...

AI SecurityAuthenticationCloud Security
Read More → Use Tool →
2026-05-18The Hacker News
Developer Workstations Now Critical Supply Chain Attack Targets

In a concentrated 48-hour window, threat actors launched coordinated attacks against npm, PyPI, and Docker Hub, marking a significant escalation in software supply chain aggression...

Supply ChainThreat IntelAuthentication
Read More → Use Tool →
2026-05-18The Hacker News
Ivanti, Fortinet, SAP, VMware Patch Critical RCE, SQL Injection, Privilege Escalation

Multiple enterprise software vendors have released critical security patches addressing severe vulnerabilities that could allow remote code execution, authentication bypass, and pr...

VulnerabilityZero-DayAuthentication
Read More → Use Tool →
2026-05-12Ars Technica
Fired Brothers Wipe 96 US Gov Databases in 5-Minute Revenge Attack

Twin brothers Muneeb and Sohaib Akhter, both 34, have been accused of destroying 96 databases holding US government information within minutes of being fired from their Washington,...

Data BreachAuthenticationIncident Response
Read More → Use Tool →
2026-05-08SecurityWeek
PCPJack Worm Cleans TeamPCP, Steals AWS Cloud Credentials

Security researchers have identified a new self‑propagating threat, named PCPJack, that behaves like a worm while simultaneously purging systems infected by the earlier TeamPCP mal...

MalwareCloud SecurityAuthentication
Read More → Use Tool →
2026-05-08The Record
Virginia Man Convicted for Deleting 96 Government Databases

A federal jury in Virginia has convicted 39-year-old Richmond resident James E. Thornton on multiple charges stemming from a 2023 cyber intrusion that resulted in the deletion of 9...

Data BreachIncident ResponseAuthentication
Read More → Use Tool →
2026-05-08The Hacker News
Linux PamDOORa Backdoor Exploits PAM to Steal SSH Credentials

Cybersecurity researchers have disclosed a previously unknown Linux backdoor called PamDOORa that is being actively advertised on the Russian cybercrime forum Rehub for $1,600 by a...

MalwareThreat IntelAuthentication
Read More → Use Tool →
2026-05-06The Hacker News
CloudZ RAT Exploits Windows Phone Link to Steal Credentials and OTPs

Security analysts have uncovered a sophisticated intrusion campaign leveraging the CloudZ remote access trojan (RAT) alongside a previously undocumented plugin called Pheno to targ...

MalwareAPTAuthentication
Read More → Use Tool →
2026-05-06Dark Reading
CloudZ RAT and Pheno Plug-in Target Windows Phone Link for Text Theft

Security researchers have uncovered a sophisticated cyberattack campaign leveraging the Windows Phone Link application to steal text messages and circumvent two-factor authenticati...

MalwareAuthenticationPrivacy
Read More → Use Tool →
2026-05-06BleepingComputer
Google Ads Abused in GoDaddy ManageWP Login Phishing Scam

A sophisticated phishing campaign is leveraging Google’s sponsored search ads to mimic the login page of ManageWP, GoDaddy’s platform for centrally managing large fleets of WordPre...

PhishingAuthenticationThreat Intel
Read More → Use Tool →
2026-05-05Dark Reading
Edge Password Leak in Process Memory Threatens Enterprise

A new proof‑of‑concept (PoC) published by security researcher Alex Chen of CyberX Labs shows that Microsoft Edge stores user passwords in plaintext within the browser’s process mem...

VulnerabilityAuthenticationData Breach
Read More → Use Tool →
2026-05-04The Hacker News
Progress Patches Critical MOVEit Automation Authentication Bypass

Progress Software has released urgent updates for MOVEit Automation (formerly Central) that address two security flaws, the most severe of which is a critical authentication bypass...

VulnerabilityAuthentication
Read More → Use Tool →
2026-05-04Dark Reading
cPanel Authentication Bypass Zero‑Day Exploit Threatens Millions

A critical authentication bypass flaw in cPanel and its associated WebHost Manager (WHM) interface was publicly disclosed on March 5, 2026, sending shockwaves through the web‑hosti...

Zero-DayVulnerabilityAuthentication
Read More → Use Tool →
2026-05-04BleepingComputer
Credit Union Loan Fraud: Stolen Identity Verification Exposed

Fraudsters are not breaking into credit unions with zero‑days or ransomware; they are exploiting the normal loan origination workflow. Flare’s threat‑intelligence team uncovered a ...

AuthenticationThreat IntelPrivacy
Read More → Use Tool →
2026-05-04BleepingComputer
Progress Warns of Critical MOVEit Automation Auth Bypass (CVE-2025-2025)

Progress Software has issued an urgent security advisory for a critical authentication bypass vulnerability in its MOVEit Automation managed file transfer (MFT) platform. Tracked a...

VulnerabilityAuthenticationZero-Day
Read More → Use Tool →
2026-05-02BleepingComputer
ConsentFix v3: Automated OAuth Abuse Targets Azure

Security researchers have flagged a new iteration of the consent‑phishing tool known as ConsentFix, now labeled v3, which dramatically expands the scale and automation of attacks a...

Cloud SecurityAuthenticationThreat Intel
Read More → Use Tool →
2026-04-29The Hacker News
Critical cPanel Authentication Vulnerability: Patch Now

cPanel and its WebHost Manager (WHM) product line contain a critical authentication flaw that could allow a remote attacker to bypass login controls and gain full control of the ho...

VulnerabilityAuthenticationZero-Day
Read More → Use Tool →
2026-04-17Dark Reading
Tycoon 2FA Phishers Switch to Device Code Phishing Attacks

Tycoon, a well‑known phishing collective that has long abused two‑factor authentication (2FA) bypass tricks, has quietly shifted to a new attack vector: OAuth 2.0 device‑code phish...

PhishingAuthenticationThreat Intel
Read More → Use Tool →
2026-04-07KrebsOnSecurity
Russia Exploits Router Flaws to Harvest Microsoft Office Tokens

Security researchers have linked a new wave of cyber‑attacks to Russia’s military intelligence, specifically the APT groups tied to the GRU, which are actively exploiting known vul...

APTVulnerabilityAuthentication
Read More → Use Tool →
2026-03-17Ars Technica
World ID Iris Tokens to Secure AI Agents, Prevent Swarms

Worldcoin’s World ID initiative, built by Tools for Humanity, is deploying a biometric authentication system based on iris scanning to assign a unique human identity to every AI ag...

AI SecurityPrivacyAuthentication
Read More → Use Tool →
2026-03-03Ars Technica
Google Tightens Android Developer Verification: Security vs Open Access

Google has announced significant changes to its Android app distribution model, implementing mandatory developer verification for all apps published on Google Play Store. The new r...

RegulationPrivacyAuthentication
Read More → Use Tool →
2026-01-21Ars Technica
SMS Sign-In Links Expose Millions of Users' Sensitive Data

Even major online services that pride themselves on seamless login experiences are quietly exposing sensitive user data through SMS sign‑in links. Security researchers analyzing th...

VulnerabilityAuthenticationData Breach
Read More → Use Tool →
2025-10-03Ars Technica
Google Confirms Android Developer Verification Tiers: Free and Paid Options

Google has officially announced its Android developer verification program will feature both free and paid tiers, marking a significant shift in how developers are authenticated be...

Supply ChainAuthenticationPrivacy
Read More → Use Tool →
2025-09-02Ars Technica
Google Denies Major Gmail Breach Affecting 2.5 Billion Users

Google has publicly pushed back against viral claims circulating online that all 2.5 billion Gmail accounts have been compromised in a sweeping security incident. The rumors, which...

Data BreachAuthenticationCloud Security
Read More → Use Tool →
2025-07-23Ars Technica
Clorox Sues Vendor After $380M Hack Exposes Password Failures

Clorox has filed a lawsuit against a service desk vendor following a 2023 cybersecurity breach that cost the company approximately $380 million. The legal action centers on allegat...

Data BreachSupply ChainAuthentication
Read More → Use Tool →
2022-08-29Threatpost
0ktapus Phishing Attacks Compromised 130 Firms, Bypassed MFA

A coordinated phishing operation attributed to the threat group 0ktapus has ensnared more than 130 organizations across multiple industries, according to researchers at Threatpost....

PhishingThreat IntelAuthentication
Read More → Use Tool →