Tag

Authentication

All articles tagged with #authentication

Auth glitches halt Microsoft 365 services, hitting Exchange Online and linked apps
technology1 month ago

Auth glitches halt Microsoft 365 services, hitting Exchange Online and linked apps

Microsoft is investigating a widespread outage causing authentication failures, connectivity issues, and email delays in Exchange Online, with broader impact on OneDrive for Business, SharePoint Online, Teams, Purview, and Defender XDR. The incident, tracked as MO1465074 (formerly EX1464935), affects tens of thousands of users per Downdetector. Microsoft says a common authentication/protocol failure pattern is under investigation and notes a core authentication configuration issue is being addressed with manual server resets as the scope and remediation continue.

Microsoft Outlook Down as Exchange Online Authentication Glitch Hits Thousands
technology1 month ago

Microsoft Outlook Down as Exchange Online Authentication Glitch Hits Thousands

Thousands of Microsoft Outlook users faced an outage tied to an authentication component issue in Exchange Online. Microsoft says a remediation strategy is being tested on part of the infrastructure before broader deployment, with the incident EX1464935 opened. Down Detector shows thousands of reports, including 37% unable to receive messages, 23% having trouble using the app, and 20% unable to access the website.

Keycloak Password-Reset Flaw Enables Unauthenticated Account Takeover
security1 month ago

Keycloak Password-Reset Flaw Enables Unauthenticated Account Takeover

Red Hat and Keycloak patched a critical vulnerability (CVE-2026-18963) in the reset-credentials flow that allowed an unauthenticated attacker to bypass email verification and reset any user’s password, potentially taking over accounts including admins. Upstream Keycloak is fixed in 26.7.2; Red Hat builds require 26.4.15/26.6.6 updates. As a temporary mitigation, disable the forgot-password feature across all realms; no public exploit evidence has been found yet.

Chrome adds hardware-backed session keys to curb account takeovers
technology1 month ago

Chrome adds hardware-backed session keys to curb account takeovers

Google Chrome is adding device-bound session credentials (DBSCs) that store a private key in hardware (TPM on Windows, Secure Enclave on macOS/iOS) to sign authentication challenges, making stolen session cookies useless for account takeover. Currently limited to a test rollout on Windows and macOS, the feature aims to reduce reliance on shared secrets and work alongside passkeys and 2FA; other Chromium-based browsers may adopt it as the standard progresses via the W3C.

Microsoft shifts to passwordless sign-ins, phasing out SMS codes
technology4 months ago

Microsoft shifts to passwordless sign-ins, phasing out SMS codes

Microsoft will retire SMS-based authentication for personal accounts and push passwordless sign-ins using passkeys, with verified secondary emails for account recovery. The new flow offers on-device passkeys that can be stored in password managers, smartphones, or Windows Hello biometrics, aiming to curb phishing and SIM-swapping. While sign-in could be faster and more secure, users accustomed to SMS verification may face friction during the transition.

cPanel Patch Fixes Critical Authentication Flaw Across Supported Versions
security5 months ago

cPanel Patch Fixes Critical Authentication Flaw Across Supported Versions

cPanel released security updates to fix a critical authentication vulnerability across all supported versions, listing patched builds (11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, 11.136.0.5); Namecheap temporarily blocked cPanel/WHM ports 2083 and 2087 as a precaution, with patches rolling out and some servers already updated as of April 29, 2026.

China Cabinet Cash: 10 Vintage Plates That Can Become Big Bucks
shopping6 months ago

China Cabinet Cash: 10 Vintage Plates That Can Become Big Bucks

A FinanceBuzz piece highlights 10 vintage plates that can fetch significant sums on resale markets, including Kutani, Tiffany & Co. bone china, Kangxi-era Chinese porcelain, Meissen, Flora Danica, Sèvres, Minton, Moorcroft, Spode, and Lenox. Values range from roughly $120 for a Lenox Fountain plate to hundreds or thousands for rarer makers and older pieces; authenticity marks and back-stamps are key to determining value, and not all vintage pieces retain value.

Google Strengthens Android Theft Protections With Stronger Auth and Remote Lock
technology8 months ago

Google Strengthens Android Theft Protections With Stronger Auth and Remote Lock

Google rolled out stronger Android theft protections, including a configurable Failed Authentication Lock, expanded Identity Check to require biometric verification for actions outside trusted locations and to cover all Android Biometric Prompt apps, improvements to prevent accidental lockouts, longer lockout times after failed attempts, and a Remote Lock with an optional ownership verification step. In Brazil, new devices will have Theft Detection Lock and Remote Lock enabled by default. Recovery tools now work on Android 10+ and safeguards on Android 16+, with Android in-call scam protection extended to major banks and Cash App/JPMorgan Chase in the US.

SMS sign-in links expose data for millions, study warns
technology8 months ago

SMS sign-in links expose data for millions, study warns

A new study finds that many services authenticate users via SMS-delivered links or codes, with weak, easily guessable tokens that can be brute-forced or enumerated to access other users’ accounts and view sensitive data. Researchers analyzed 332,000 unique SMS URLs from 33 million texts across 177 services, uncovering 701 endpoints that exposed data and 125 allowing mass enumeration. Only a minority of providers contacted by the researchers have fixed the flaws, underscoring the need for stronger authentication, time-limited links, and multi-factor checks or safer alternatives like email-based magic links.

The Shift Toward Passwordless Security: Embracing Passkeys and Facial Recognition
technology9 months ago

The Shift Toward Passwordless Security: Embracing Passkeys and Facial Recognition

Passkeys are a secure and user-friendly alternative to passwords that are underutilized due to low awareness, misconceptions, and implementation challenges. Companies are encouraged to promote phased adoption and educate users on their benefits to improve security and user experience, especially as traditional methods become more vulnerable to AI-driven attacks.

Plex Security Breach Prompts Urgent Password Changes
technology1 year ago

Plex Security Breach Prompts Urgent Password Changes

Plex has warned users to reset their passwords following a data breach that exposed email addresses, usernames, and securely hashed passwords. The company has addressed the breach and recommends users change passwords, log out of all devices, and enable two-factor authentication for added security. No payment card information was compromised in the incident.