SecurityWeek·8d ago highBrevo Supply Chain Attack Injects Malware Into 100,000 Websites#brevo#clickfix#cloudflare in the wild 2 min1
Infosecurity Magazine·10d agoCISA and NIST Issue Guidance to Protect Cloud Identity Tokens#cisa#guidance#identity 2 min1
GBHackers·11d agoNIST Issues New Guidance to Protect SSO and API Tokens From Theft and Forgery#cloud-security#identity-security#nist 2 sources 3 min
Cyber Security News·11d agoCISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse#cisa#dpop#identity-tokens 4 min1
Ubuntu Security Notices·11d agoUSN-8770-1: SimpleSAMLphp vulnerabilities#saml#signature-validation#simplesamlphpCVE-2019-34651
Malwarebytes Labs·15d ago highCrypto customers targeted by scammers after email marketing provider breach#breach#brevo#cryptocurrency in the wild 3 min1
oss-security·18d ago highCVE-2026-56207: Apache Impala: SAML authentication bypass via forged bearer token#apache#authentication-bypass#impalaCVE-2026-56207 3 sources1
oss-security·20d agoCVE-2026-86304: MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor#authentication-bypass#mojox-authentication#net-saml2CVE-2026-86304
Canadian Centre for Cyber Security·22d ago highAL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489#advisory#authentication-bypass#buffer-overflow 3 sources 3 min1
Canadian Centre for Cyber Security·23d ago[Control Systems] Siemens security advisory (AV26-881)#account-hijacking#control-systems#mendix
Security Affairs·Aug 25, 2026 criticalTwo CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable#actively-exploited#algorithm-confusion#authentication-bypass in the wild 5 min
The Hacker News·Aug 25, 2026 highAttackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access#authentication-bypass#digitalocean#miniorange in the wild 2 min
Patchstack·Aug 21, 2026 highOne slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress admin#authentication-bypass#digitalocean#miniorange