All CosmicBytez Labs articles tagged #authentication, across news, security advisories, how-to guides, and projects.
Meta announces WhatsApp support for multiple passkeys per account on iOS and Android, ending password reliance with phishing-resistant biometric auth.
CVE-2026-18963 (CVSS 9.1) in Keycloak allows unauthenticated attackers to bypass email verification and take over any account. Patch to 26.7.2 immediately.
Huntress reports a 155x surge in password spraying in H1 2026, with one campaign logging 81 million login attempts in two weeks via MFA and legacy auth gaps.
SiYuan's CheckAuth() middleware has no rate limiting, allowing unauthenticated attackers to brute-force API tokens and gain full admin access (CVSS 9.8).
SiYuan before v3.7.4 has no brute-force protection on its /api/* auth middleware, exposing the workspace to credential stuffing. CVSS 9.8.
Grav API plugin before 1.0.13 fails to enforce API key scope caps on the disable2fa endpoint, enabling privilege escalation.
Laravel Socialite's Facebook provider is vulnerable to OIDC id_token replay attacks due to missing nonce validation in getUserByOIDCToken().
High-severity auth bypass in the VentraConnect Social Login plugin allows unauthenticated attackers to take over any WordPress account.
Security researchers uncovered critical vulnerabilities in Belgium's eID middleware software, affecting eight of the country's ten largest banks and over 60 government agencies — putting more than two million citizens at risk.
Replace static SSH keys with a short-lived certificate authority. Harden sshd_config, eliminate lateral-movement risk, and enforce zero-trust access across your Linux fleet.
A critical unauthenticated account takeover vulnerability in the TrueBooker Appointment Booking plugin for WordPress allows attackers to reset any user's password, including administrators, without verification. CVSS 9.8.
A critical unauthenticated AJAX vulnerability in the Masteriyo LMS WordPress plugin allows attackers to terminate any user's session — including administrators — without any credentials.
Critical unauthenticated account takeover vulnerability in Rocket.Chat's CAS login handler passes unsanitized client input directly into a MongoDB findOne...
Critical pre-authentication vulnerability in Rocket.Chat allows any unauthenticated network attacker to obtain a valid OAuth access token for an arbitrary...
Chinese state-sponsored hackers seized complete control of a target organization's authentication infrastructure and maintained undetected access for ten...
A timing attack vulnerability in RELATE's check_sign_in_key() function could allow attackers to infer valid sign-in keys through response time differences...
cPanel and WebHost Manager have released an emergency patch for a critical authentication bypass vulnerability that allows attackers to gain control panel...
A high-severity flaw in Spring Security allows security filter chains to silently fail to match requests when PathPatternRequestMatcher.Builder is used to...
A critical CVSS 9.1 vulnerability in Apache Airflow fails to invalidate JWT tokens upon user logout, allowing intercepted tokens to be reused for...
A critical SQL injection vulnerability in the SciTokens Python library allows attackers to manipulate authentication token validation via unsanitized...
A critical vulnerability in Gematik Authenticator prior to version 4.16.0 allows attackers to hijack authentication sessions via malicious deep links,...
Deploy Keycloak with Docker Compose and PostgreSQL to build a centralised single sign-on platform for your homelab services, with OIDC integration for...