Tag

Authentication

All articles tagged with #authentication

Keycloak Password-Reset Flaw Enables Unauthenticated Account Takeover
security1 day ago

Keycloak Password-Reset Flaw Enables Unauthenticated Account Takeover

Red Hat and Keycloak patched a critical vulnerability (CVE-2026-18963) in the reset-credentials flow that allowed an unauthenticated attacker to bypass email verification and reset any user’s password, potentially taking over accounts including admins. Upstream Keycloak is fixed in 26.7.2; Red Hat builds require 26.4.15/26.6.6 updates. As a temporary mitigation, disable the forgot-password feature across all realms; no public exploit evidence has been found yet.

Chrome adds hardware-backed session keys to curb account takeovers
technology13 days ago

Chrome adds hardware-backed session keys to curb account takeovers

Google Chrome is adding device-bound session credentials (DBSCs) that store a private key in hardware (TPM on Windows, Secure Enclave on macOS/iOS) to sign authentication challenges, making stolen session cookies useless for account takeover. Currently limited to a test rollout on Windows and macOS, the feature aims to reduce reliance on shared secrets and work alongside passkeys and 2FA; other Chromium-based browsers may adopt it as the standard progresses via the W3C.

Microsoft shifts to passwordless sign-ins, phasing out SMS codes
technology3 months ago

Microsoft shifts to passwordless sign-ins, phasing out SMS codes

Microsoft will retire SMS-based authentication for personal accounts and push passwordless sign-ins using passkeys, with verified secondary emails for account recovery. The new flow offers on-device passkeys that can be stored in password managers, smartphones, or Windows Hello biometrics, aiming to curb phishing and SIM-swapping. While sign-in could be faster and more secure, users accustomed to SMS verification may face friction during the transition.

cPanel Patch Fixes Critical Authentication Flaw Across Supported Versions
security3 months ago

cPanel Patch Fixes Critical Authentication Flaw Across Supported Versions

cPanel released security updates to fix a critical authentication vulnerability across all supported versions, listing patched builds (11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, 11.136.0.5); Namecheap temporarily blocked cPanel/WHM ports 2083 and 2087 as a precaution, with patches rolling out and some servers already updated as of April 29, 2026.

China Cabinet Cash: 10 Vintage Plates That Can Become Big Bucks
shopping4 months ago

China Cabinet Cash: 10 Vintage Plates That Can Become Big Bucks

A FinanceBuzz piece highlights 10 vintage plates that can fetch significant sums on resale markets, including Kutani, Tiffany & Co. bone china, Kangxi-era Chinese porcelain, Meissen, Flora Danica, Sèvres, Minton, Moorcroft, Spode, and Lenox. Values range from roughly $120 for a Lenox Fountain plate to hundreds or thousands for rarer makers and older pieces; authenticity marks and back-stamps are key to determining value, and not all vintage pieces retain value.

Google Strengthens Android Theft Protections With Stronger Auth and Remote Lock
technology6 months ago

Google Strengthens Android Theft Protections With Stronger Auth and Remote Lock

Google rolled out stronger Android theft protections, including a configurable Failed Authentication Lock, expanded Identity Check to require biometric verification for actions outside trusted locations and to cover all Android Biometric Prompt apps, improvements to prevent accidental lockouts, longer lockout times after failed attempts, and a Remote Lock with an optional ownership verification step. In Brazil, new devices will have Theft Detection Lock and Remote Lock enabled by default. Recovery tools now work on Android 10+ and safeguards on Android 16+, with Android in-call scam protection extended to major banks and Cash App/JPMorgan Chase in the US.

SMS sign-in links expose data for millions, study warns
technology7 months ago

SMS sign-in links expose data for millions, study warns

A new study finds that many services authenticate users via SMS-delivered links or codes, with weak, easily guessable tokens that can be brute-forced or enumerated to access other users’ accounts and view sensitive data. Researchers analyzed 332,000 unique SMS URLs from 33 million texts across 177 services, uncovering 701 endpoints that exposed data and 125 allowing mass enumeration. Only a minority of providers contacted by the researchers have fixed the flaws, underscoring the need for stronger authentication, time-limited links, and multi-factor checks or safer alternatives like email-based magic links.

The Shift Toward Passwordless Security: Embracing Passkeys and Facial Recognition
technology7 months ago

The Shift Toward Passwordless Security: Embracing Passkeys and Facial Recognition

Passkeys are a secure and user-friendly alternative to passwords that are underutilized due to low awareness, misconceptions, and implementation challenges. Companies are encouraged to promote phased adoption and educate users on their benefits to improve security and user experience, especially as traditional methods become more vulnerable to AI-driven attacks.

Plex Security Breach Prompts Urgent Password Changes
technology11 months ago

Plex Security Breach Prompts Urgent Password Changes

Plex has warned users to reset their passwords following a data breach that exposed email addresses, usernames, and securely hashed passwords. The company has addressed the breach and recommends users change passwords, log out of all devices, and enable two-factor authentication for added security. No payment card information was compromised in the incident.

Buyer Scores £30,000 Salvador Dalí Painting for Just £150 at House Sale
art1 year ago

Buyer Scores £30,000 Salvador Dalí Painting for Just £150 at House Sale

A modestly priced painting bought for £150 at a house clearance sale in Cambridge has been authenticated as a genuine Salvador Dalí artwork, valued at £20,000 to £30,000. The piece, Vecchio Sultano, is part of Dalí's unfinished Middle Eastern folktale illustrations, which were largely unpublished and stored in a London garage. The discovery highlights the potential value hidden in overlooked art pieces and the importance of expert authentication.