⤷ Title: When the CDN Was Secure but the Origin Wasn’t: Bypassing SSO Through Direct-to-Origin Access
════════════════════════
𐀪 Author: redhunter01
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 19:41:26 GMT
════════════════════════
⌗ Tags: #bug_bounty #ethical_hacking #cybersecurity #cloud_security #authentication_bypass
════════════════════════
𐀪 Author: redhunter01
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 19:41:26 GMT
════════════════════════
⌗ Tags: #bug_bounty #ethical_hacking #cybersecurity #cloud_security #authentication_bypass
Medium
When the CDN Was Secure but the Origin Wasn’t: Bypassing SSO Through Direct-to-Origin Access
How a protected dev site became publicly accessible because authentication existed only at the CDN edge.
⤷ Title: PortSwigger Lab: Password reset broken logic
════════════════════════
𐀪 Author: sa0k0
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 21:38:43 GMT
════════════════════════
⌗ Tags: #authentication #bug_bounty #web_security #portswigger
════════════════════════
𐀪 Author: sa0k0
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 21:38:43 GMT
════════════════════════
⌗ Tags: #authentication #bug_bounty #web_security #portswigger
Medium
PortSwigger Lab: Password reset broken logic
Lab Information
⤷ Title: CVE-2026-65400: macOS Screen Sharing Flaw Exploited to Deploy Monero Miners
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 03:25:16 +0000
════════════════════════
⌗ Tags: #Vulnerability #Apple Security #authentication bypass #Cryptojacking #CVE_2026_65400 #macos #Monero Miner #Screen Sharing
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 03:25:16 +0000
════════════════════════
⌗ Tags: #Vulnerability #Apple Security #authentication bypass #Cryptojacking #CVE_2026_65400 #macos #Monero Miner #Screen Sharing
Information Security News
CVE-2026-65400: macOS Screen Sharing Flaw Exploited to Deploy Monero Miners
Attackers have begun exploiting a critical vulnerability in macOS’s built-in Screen Sharing feature to gain access to Mac computers without any valid credentials whatsoever. In several confi…
⤷ Title: Session Management: Idle Timeouts and Step-Up Auth (Android)
════════════════════════
𐀪 Author: Khizar Khan
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 12:46:10 GMT
════════════════════════
⌗ Tags: #application_security #cybersecurity #android_development #mobile_security #authentication
════════════════════════
𐀪 Author: Khizar Khan
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 12:46:10 GMT
════════════════════════
⌗ Tags: #application_security #cybersecurity #android_development #mobile_security #authentication
Medium
Session Management: Idle Timeouts and Step-Up Auth (Android)
Part 9 of our Android security series. Part 8 covered Credential Manager — getting the user signed in. This post covers what happens for…
⤷ Title: CVE-2026-19490 (CVSS 9.3): NetScaler Authentication Bypass Flaw Patched
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 15:21:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Citrix #CVE_2026_19489 #CVE_2026_19490 #NetScaler #NetScaler ADC #NetScaler Gateway
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 15:21:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Citrix #CVE_2026_19489 #CVE_2026_19490 #NetScaler #NetScaler ADC #NetScaler Gateway
Daily CyberSecurity
CVE-2026-19490 (CVSS 9.3): NetScaler Authentication Bypass Flaw Patched
TL;DR Citrix patched a critical NetScaler authentication bypass tracked as CVE-2026-19490. It scores 9.3 on CVSS v4. A second flaw, CVE-2026-19489, can cause denial of service. Why it matters NetS…
⤷ Title: IBM Db2 Mirror for i Hit by CVE-2026-17186 RCE Flaw (CVSS 9.9)
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 13:15:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Command Injection #CVE_2026_17182 #CVE_2026_17184 #CVE_2026_17186 #Db2 Mirror for i #IBM #IBM i #Path Traversal #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 13:15:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Command Injection #CVE_2026_17182 #CVE_2026_17184 #CVE_2026_17186 #Db2 Mirror for i #IBM #IBM i #Path Traversal #Remote Code Execution
Daily CyberSecurity
IBM Db2 Mirror for i Hit by CVE-2026-17186 RCE Flaw (CVSS 9.9)
IBM patched 18 flaws in Db2 Mirror for i this week. The worst bug lets a remote attacker run system commands without logging in. IBM Db2 Mirror RCE risk reaches a CVSS score of 9.9. Also, several …
⤷ Title: CVE-2026-20315 & CVE-2026-20317: Cisco Secure Workload Auth Bypass, Privilege Escalation Hit CVSS 10
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 02:05:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Cisco PSIRT #Cisco Secure Workload #CVE_2026_20315 #CVE_2026_20317 #privilege escalation
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 02:05:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Cisco PSIRT #Cisco Secure Workload #CVE_2026_20315 #CVE_2026_20317 #privilege escalation
Daily CyberSecurity
CVE-2026-20315 & CVE-2026-20317: Cisco Secure Workload Auth Bypass, Privilege Escalation Hit CVSS 10
TL;DR Cisco released hardening updates for Secure Workload on August 19, 2026. The Cisco Secure Workload authentication bypass and privilege escalation flaws include two vulnerabilities rated CVSS…
⤷ Title: Beyond Client Secrets: Getting OAuth 2.0 Access Tokens with Keycloak Using Signed JWTs
════════════════════════
𐀪 Author: Aditya Ramaswamy
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 10:13:13 GMT
════════════════════════
⌗ Tags: #oauth2 #authentication #keycloak #api_security #jwt
════════════════════════
𐀪 Author: Aditya Ramaswamy
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 10:13:13 GMT
════════════════════════
⌗ Tags: #oauth2 #authentication #keycloak #api_security #jwt
Medium
Beyond Client Secrets: Getting OAuth 2.0 Access Tokens with Keycloak Using Signed JWTs
1. Introduction
⤷ Title: FreeRDP 3.31.0 Fixes Pre-Auth RCE Chain in Server
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 02 Sep 2026 01:00:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #FreeRDP #GNOME Remote Desktop #KDE krdp #Pre_Auth RCE #Remote Desktop Protocol
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 02 Sep 2026 01:00:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #FreeRDP #GNOME Remote Desktop #KDE krdp #Pre_Auth RCE #Remote Desktop Protocol
Daily CyberSecurity
FreeRDP 3.31.0 Fixes Pre-Auth RCE Chain in Server
TL;DR FreeRDP 3.31.0 patches five server-role flaws reported by Bynario, plus 17 other issues. Researchers chained three of them into pre-authentication remote code execution. This FreeRDP vulnera…
⤷ Title: 22,000 Exchange Servers Exposed to Mailbox-Hijack Flaw
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 03 Sep 2026 08:02:10 +0000
════════════════════════
⌗ Tags: #Malware #authentication bypass #CVE_2026_62911 #Microsoft Exchange #Patch Management #Shadowserver
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 03 Sep 2026 08:02:10 +0000
════════════════════════
⌗ Tags: #Malware #authentication bypass #CVE_2026_62911 #Microsoft Exchange #Patch Management #Shadowserver
Information Security News
22,000 Exchange Servers Exposed to Mailbox-Hijack Flaw
Corporate email can fall into an attacker’s hands after the compromise of a single low-privilege account. Nearly 22,000 internet-facing Microsoft Exchange servers have not received the fix f…