oss-security·2d agoCVE-2026-92288: Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party#lemonldap#oauth2#token-introspectionCVE-2026-92288 3 sources
CERT/CC Vulnerability Notes·3d agoVU#273940: Enterprise Access Management EAM does not rotate RSA keys#imprivata#eam#cve-2026-82356CVE-2026-82356 2 min
Malwarebytes Labs·4d ago highResearchers used Claude to hack OpenAI#ai-hacking#discourse#libheif 3 sources 4 min
Cyber Security News·5d agoTop 10 Best Single Sign-On (SSO) Solutions in 2026#identity#microsoft-entra#okta 9 min
Security Affairs·7d agoAI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum#account-takeover#ai-driven-exploitation#discourse 5 min
The Hacker News·7d agoClaude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws#account-takeover#anthropic#claude-opus-5 6 min
Hacker News · security·9d ago highA heap overflow and SSO misconfiguration to compromise OpenAI internal repos#account-takeover#bug-bounty#discourse in the wild 9 min1
Infosecurity Magazine·10d agoCISA and NIST Issue Guidance to Protect Cloud Identity Tokens#cisa#guidance#identity 2 min1
The Hacker News·10d agoN0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security#any-run#device-code-phishing#n0va in the wild 6 min5
GBHackers·11d agoNIST Issues New Guidance to Protect SSO and API Tokens From Theft and Forgery#cloud-security#identity-security#nist 2 sources 3 min
Ubuntu Security Notices·11d agoUSN-8768-1: Shibboleth vulnerability#odbc#shibboleth#sql-injectionAdvisory
Cyber Security News·17d agoNew N0va Phishkit Targets North America and EU: A Growing Identity Risk for SOCs#anyrun#device-code-phishing#mfa in the wild 6 min1
CERT/CC Vulnerability Notes·23d ago highVU#889462: Casdoor authentication server is vulnerable to authorization bypass#authorization-bypass#casdoor#cert-ccCVE-2026-15630 3 min
Security Affairs·Aug 25, 2026 criticalTwo CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable#actively-exploited#algorithm-confusion#authentication-bypass in the wild 5 min
Help Net Security·Aug 25, 2026ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack#mfa#okta#reliaquest in the wild 3 min1
Patchstack·Aug 21, 2026 highOne slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress admin#authentication-bypass#digitalocean#miniorange