Password reset bypass in Keycloak opens every account to takeover

Red Hat patches a critical Keycloak flaw that lets unauthenticated attackers seize any account, including admins.

The Latest

Breaking News and Alerts

Spectre attack on Cloudflare Workers leaks JWT across tenants

Researchers leaked a JWT from a co-located Cloudflare Worker via Spectre at 12 bits per second.

Spotlight

Cybersecurity Profiles and Stories

Apollo confirms cloud intrusion as BlackFile spree widens

The private equity giant says attackers hit its cloud platforms in July, exposing names and Social Security numbers.

CISA orders TrueConf patches after Ukraine-linked server attacks

Two exploited TrueConf Server flaws land on CISA's KEV list as Head Mare is caught delivering a poisoned installer.

Calendar add-ons on npm hide Linux backdoor in plain sight

Trend Micro finds 14 trojanized packages that drop the RedC2 4.0 implant the moment they are imported.

First malware rides legitimate car head unit updates

Kaspersky finds a downloader pushed through built-in firmware updaters of Android dashboards, tied to the MoYu Group.

Features

Research and Thought Leadership