Cyber Security News·1d ago high16-Year-Old Researcher Finds Microsoft Auth Vulnerability that Exposes 17.3 Trillion Stored Records#microsoft#titan#jwt 4 min1
oss-security·2d agoCVE-2026-92288: Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party#lemonldap#oauth2#token-introspectionCVE-2026-92288 3 sources
arXiv cs.CR·2d agoTemplate Ageing and Longitudinal Verification in Fixed-Text Keystroke Dynamics: A Subject-Disjoint Study Across Eight Weeks#keystroke-dynamics#biometrics#template-ageingResearch
oss-security·3d agoCVE-2026-86248: Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled#apache#tomcat#cve-2026-86248CVE-2026-34500 15 sources
oss-security·3d ago highCVE-2026-31377: Apache Doris: Improper Authentication Allows Unauthorized Access to FE Meta Service#apache-doris#cve-2026-31377#authenticationCVE-2026-31377 2 sources
The Hacker News·4d ago highAI Agents Are Rewriting the Rules of Lateral Movement#ai-agent#authentication#cve in the wild 7 min
Cyber Security News·5d agoMicrosoft Entra ID to Block SMS First-Factor Sign-Ins Worldwide in February 2027#microsoft#entra-id#sms 3 sources 4 min
oss-security·5d agoCVE-2026-82355: Apache Airflow: Session cookie silently overrides explicit Authorization bearer header, enabling session fixation#apache-airflow#cve-2026-82355#session-fixationCVE-2026-82355 3 sources
Lobsters · security·8d agosudo and OpenDoas timestamp files (2020)#authentication#doas#linuxResearch 2 min
arXiv cs.AI / cs.LG / cs.CL·8d agoLearning Cardiac Features: ECG Biometrics Across Time and~Exercise#ecg#biometrics#siamese-networkAI research
CISA Advisories·9d agoSchneider Electric PowerChute Serial Shutdown#authentication#brute-force#cisaCVE-2026-13348 3 sources 7 min
arXiv cs.AI / cs.LG / cs.CL·9d agoA Scalable Trust Discovery Architecture for the Internet of Agents#agent-identity#authentication#discoveryAI research
CISA Advisories·11d agoProtecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers#authentication#cisa#cloud-securityAdvisory
Cyber Security News·12d agoUK Government Begins Moving 23 Million Users Away From Passwords#authentication#fido2#gov-uk 3 min
The Register · Security·12d agoUK.gov begins killing off passwords for 23 million users#authentication#govuk-one-login#ncsc 2 min
CSO Online·15d ago highConnectWise patches critical ScreenConnect authentication failure after five days#authentication#connectwise#patch
Lobsters · security·16d agoA rant about phishing: It's not the user's fault (and not DNS either)#authentication#dns#domainsPhishing & fraud 3 min
ZDI Published Advisories·17d ago highZDI-26-657: ASUS Control Center Express Agent Missing Authentication Remote Code Execution Vulnerability#asus#authentication#control-center-expressCVE-2026-19397