Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2614+ Articles
162+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
22 articles

#authentication

All CosmicBytez Labs articles tagged #authentication, across news, security advisories, how-to guides, and projects.

  • NewsAug 25, 2026

    WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins

    Meta announces WhatsApp support for multiple passkeys per account on iOS and Android, ending password reliance with phishing-resistant biometric auth.

  • NewsAug 24, 2026

    Critical Keycloak Flaw Lets Attackers Reset Any Account Password Without Authentication

    CVE-2026-18963 (CVSS 9.1) in Keycloak allows unauthenticated attackers to bypass email verification and take over any account. Patch to 26.7.2 immediately.

  • NewsAug 19, 2026

    Password Spraying Attacks Surge 155x as Hackers Exploit MFA Gaps

    Huntress reports a 155x surge in password spraying in H1 2026, with one campaign logging 81 million login attempts in two weeks via MFA and legacy auth gaps.

  • SecurityAug 17, 2026

    SiYuan API Token Brute-Force via Missing Rate Limiting — CVE-2026-73056

    SiYuan's CheckAuth() middleware has no rate limiting, allowing unauthenticated attackers to brute-force API tokens and gain full admin access (CVSS 9.8).

  • SecurityAug 16, 2026

    SiYuan API Authentication Has No Rate Limiting (CVE-2026-73046)

    SiYuan before v3.7.4 has no brute-force protection on its /api/* auth middleware, exposing the workspace to credential stuffing. CVSS 9.8.

  • SecurityAug 15, 2026

    CVE-2026-72822: Grav API Plugin 2FA Scope Bypass Allows Admin Account Takeover

    Grav API plugin before 1.0.13 fails to enforce API key scope caps on the disable2fa endpoint, enabling privilege escalation.

  • SecurityAug 15, 2026

    CVE-2026-73683: Laravel Socialite Facebook OIDC Authentication Bypass

    Laravel Socialite's Facebook provider is vulnerable to OIDC id_token replay attacks due to missing nonce validation in getUserByOIDCToken().

  • SecurityAug 12, 2026

    CVE-2026-18961: WordPress VentraConnect Plugin Authentication Bypass

    High-severity auth bypass in the VentraConnect Social Login plugin allows unauthenticated attackers to take over any WordPress account.

  • NewsAug 10, 2026

    Critical Flaws Discovered in Belgian eID Software Used by 2 Million People

    Security researchers uncovered critical vulnerabilities in Belgium's eID middleware software, affecting eight of the country's ten largest banks and over 60 government agencies — putting more than two million citizens at risk.

  • HOWTOAug 10, 2026

    OpenSSH Hardening with Certificate-Based Authentication

    Replace static SSH keys with a short-lived certificate authority. Harden sshd_config, eliminate lateral-movement risk, and enforce zero-trust access across your Linux fleet.

  • SecurityAug 7, 2026

    CVE-2026-14364: TrueBooker WordPress Plugin Account Takeover via Password Reset Bypass

    A critical unauthenticated account takeover vulnerability in the TrueBooker Appointment Booking plugin for WordPress allows attackers to reset any user's password, including administrators, without verification. CVSS 9.8.

  • SecurityJul 27, 2026

    CVE-2026-13332: Masteriyo LMS Allows Unauthenticated Force-Logout of Any User

    A critical unauthenticated AJAX vulnerability in the Masteriyo LMS WordPress plugin allows attackers to terminate any user's session — including administrators — without any credentials.

  • SecurityJun 25, 2026

    CVE-2026-45688: Rocket.Chat CAS Login MongoDB Operator Injection (CVSS 9.1)

    Critical unauthenticated account takeover vulnerability in Rocket.Chat's CAS login handler passes unsanitized client input directly into a MongoDB findOne...

  • SecurityJun 25, 2026

    CVE-2026-45689: Rocket.Chat OAuth Token Hijack via MongoDB Operator Injection (CVSS 9.1)

    Critical pre-authentication vulnerability in Rocket.Chat allows any unauthenticated network attacker to obtain a valid OAuth access token for an arbitrary...

  • NewsJun 13, 2026

    Chinese Hackers Hijack Auth Flow, Spy on Isolated Network for a Decade

    Chinese state-sponsored hackers seized complete control of a target organization's authentication infrastructure and maintained undetected access for ten...

  • SecurityMay 9, 2026

    CVE-2026-41588: RELATE Courseware Timing Attack in Authentication (CVSS 9.0)

    A timing attack vulnerability in RELATE's check_sign_in_key() function could allow attackers to infer valid sign-in keys through response time differences...

  • NewsApr 29, 2026

    cPanel & WHM Emergency Update Fixes Critical Auth Bypass Bug

    cPanel and WebHost Manager have released an emergency patch for a critical authentication bypass vulnerability that allows attackers to gain control panel...

  • SecurityApr 22, 2026

    CVE-2026-22753: Spring Security Filter Chain Bypass via PathPattern Matcher

    A high-severity flaw in Spring Security allows security filter chains to silently fail to match requests when PathPatternRequestMatcher.Builder is used to...

  • SecurityApr 10, 2026

    CVE-2025-57735: Apache Airflow JWT Token Not Invalidated on Logout

    A critical CVSS 9.1 vulnerability in Apache Airflow fails to invalidate JWT tokens upon user logout, allowing intercepted tokens to be reused for...

  • SecurityMar 31, 2026

    CVE-2026-32714: Critical SQL Injection in SciTokens

    A critical SQL injection vulnerability in the SciTokens Python library allows attackers to manipulate authentication token validation via unsanitized...

  • SecurityMar 28, 2026

    CVE-2026-33875: Gematik Authenticator Authentication Flow

    A critical vulnerability in Gematik Authenticator prior to version 4.16.0 allows attackers to hijack authentication sessions via malicious deep links,...

  • ProjectMar 26, 2026

    Keycloak SSO: Self-Hosted Identity Provider for Your Homelab

    Deploy Keycloak with Docker Compose and PostgreSQL to build a centralised single sign-on platform for your homelab services, with OIDC integration for...