The Hacker News
NEWS · ALERTS · RESEARCH
Identity & access
Industry reporting, official advisories and security research, collected in one place. Headlines link to the original publisher.
30 sourced updates · Publication dates or labeled coverage weeks shown · Read full coverage at the source
The Hacker News
Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens ↗
Industry newsThe Hacker News
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens ↗
Industry newsThe Hacker News
BambooToken Malware Uses MQTT to Control Windows and Linux Systems ↗
Industry newsCISA Cybersecurity Advisories
Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers ↗
Agency · CISACISA News
CISA and NIST Release Guidelines to Protect Federal Cloud Identity Systems from Token Theft, Forgery, and Misuse ↗
Agency · CISAThe Hacker News
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers ↗
Industry newsMicrosoft Security Response Center
Chromium CVE-2026-87646: Use after free in Web Authentication ↗
ResearchMicrosoft Security Response Center
Chromium CVE-2026-87626: Incorrect authorization in DeviceBoundSessionCredentials ↗
ResearchMicrosoft Security Response Center
Chromium CVE-2026-87624: UI misrepresentation in Passwords ↗
ResearchMicrosoft Security Response Center
Chromium CVE-2026-87590: Improper input validation in Passwords ↗
ResearchMicrosoft Security Response Center
Chromium CVE-2026-87583: UI misrepresentation in Passwords ↗
ResearchMicrosoft Security Response Center
Chromium CVE-2026-87565: Information leak in Passwords ↗
ResearchMicrosoft Security Response Center
Chromium CVE-2026-87561: Incorrect authorization in Web Authentication ↗
ResearchThe Hacker News
3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials ↗
Industry newsThe Hacker News
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users ↗
Industry newsThe Hacker News
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware ↗
Industry newsMicrosoft Security Research
Detect and disrupt AI-themed attacks with Microsoft Defender ↗
ResearchMicrosoft Security Research
Passkey-themed social engineering leads to identity and cloud compromise ↗
ResearchThe Hacker News
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA ↗
Industry newsThe Hacker News
N-able N-central Pre-Auth RCE Flaw Exploited in the Wild ↗
Industry newsChannelPro
5 ways MSPs can protect identity integrity during cloud transitions ↗
Industry newsThe Hacker News
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours ↗
Industry newsThe Hacker News
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials ↗
Industry newsKrebsOnSecurity
Microsoft Plugs Nearly 400 Security Holes ↗
Industry newsCIS / MS-ISAC
Multiple Vulnerabilities in SolarWinds Web Help Desk Could Allow for Authentication Bypass ↗
Threat sharingCIS / MS-ISAC
A Vulnerability in PAN-OS Could Allow for Authentication Bypass ↗
Threat sharingCIS / MS-ISAC
A Vulnerability in SimpleHelp Could Allow for Authentication Bypass ↗
Threat sharingCIS / MS-ISAC
Multiple Vulnerabilities in Check Point Products Could Allow for Authentication Bypass ↗
Threat sharingCIS / MS-ISAC