Cyber Security News·3d ago highAWS Lambda Flaw Lets Attackers Bypass IAM Permissions and Access Cloud Services#aws#cloud-security#iam 3 min
BleepingComputer·3d ago highHow One Kubernetes YAML Can Hand Over a GCP Organization#confused-deputy#gcp#iam 8 min1
GBHackers·3d agoAembit Launches Support for Okta Cross App Access, Extending Enterprise Identity Controls to AI Agents#aembit#okta#iam 3 sources 3 min
GBHackers·5d ago criticalAWS Detects and Quarantines Exposed IAM Credentials in Public GitHub Repositories#aws#cloud-security#credential-protection 3 sources in the wild 4 min1
Help Net Security·5d agoPasswork NIS2 efficiency guide: Save your team hours before the 2026 audit#passwork#nis2#password-manager 6 min1
Cyber Security News·5d agoTop 10 Best Identity & Access Management (IAM) Solutions in 2026#cyberark#iam#microsoft-entra-id 10 min
The Hacker News·7d agoIdentity Visibility in 2026: The Foundation of Identity Security#agentic-ai#cloud-security#credential-abuse 11 min
BleepingComputer·8d agoSecure enterprise sharing with access reviews for Microsoft 365#access-governance#access-reviews#iam 2 sources 4 min2
Help Net Security·10d agoAWS’s new sign-up gives accounts spend caps, email invites, and agent-set permissions#agent-toolkit#aws#cloud-security 3 min
CSO Online·10d agoAI agent authorization risks remain a gap in new NIST-CISA token security guidance#ai-agents#caep#cisa 5 min
oss-security·12d agoCVE-2026-77181: Apache Syncope: ClientApp update entitlement not effective#access-control#apache#authorizationCVE-2026-77181
oss-security·12d ago highCVE-2026-77147: Apache Syncope: Groovy Sandbox escape for empty CommandArgs#apache-syncope#code-injection#cve-2026-77147CVE-2026-77147
oss-security·12d agoCVE-2026-77051: Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search#apache-syncope#audit#cve-2026-77051CVE-2026-77051
oss-security·12d agoCVE-2026-75030: Apache Syncope: Incomplete authorization checks for Group members deprovisioning#apache-syncope#authorization#cve-2026-75030CVE-2026-750301
oss-security·12d agoCVE-2026-75015: Apache Syncope: Nested secrets leak cleartext into audit records readable#apache#audit-records#credential-leakCVE-2026-750151
oss-security·12d agoCVE-2026-73668: Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values#apache#authorization-bypass#connidCVE-2026-73668
oss-security·12d agoCVE-2026-73579: Apache Syncope: Non-recursive Any search could skip Realms restrictions#apache#authorization-bypass#cve-2026-73579CVE-2026-735791
oss-security·12d agoCVE-2026-73470: Apache Syncope: Delegating users can grant unowned Roles#apache#authorization#cve-2026-73470CVE-2026-73470
oss-security·12d agoCVE-2026-73236: Apache Syncope: Cross-Realm authorization bypass in delegated administration#apache#authorization-bypass#cve-2026-73236CVE-2026-73236 2 sources1
Cyber Security News·12d ago highAWS Systems Manager Agent Vulnerability Allows Attackers to Bypass Port-Forwarding Restrictions#aws#ec2#iam 3 min1
Cyber Security News·15d agoOkta Fixes Auth0 and Access Gateway Flaws Enabling XSS, Auth Bypass, and SQL Injection#access-gateway#auth0#authorization-bypass 3 min1
The Hacker News·19d agoYour Cloud Security Checklist Doesn't Work the Way You Think It Does#aws#azure#cloud-security 4 min
CERT/CC Vulnerability Notes·23d ago highVU#889462: Casdoor authentication server is vulnerable to authorization bypass#authorization-bypass#casdoor#cert-ccCVE-2026-15630 3 min