#authentication


Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

Jul 22, 2026 // 15:40

A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 […]

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Jul 21, 2026 // 17:10

Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on […]

Microsoft Entra ID gets passkeys default authentication starting September

Jul 14, 2026 // 15:56

Microsoft has announced that passkeys will become the default authentication method for the Entra ID enterprise identity service starting September 2026. Passkeys will be enabled […]

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

Jun 13, 2026 // 16:25

Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even […]

Critical UniFi OS bug lets hackers gain root without authentication

Jun 8, 2026 // 19:57

Attackers can chain three already fixed vulnerabilities in the Ubiquiti UniFi OS server to execute remote code with root privileges and without authentication. The security […]

OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack

Jun 1, 2026 // 12:33

Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that’s targeting developers using OpenAI Codex through a legitimate-looking remote web UI. The […]

PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

May 30, 2026 // 18:59

Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. […]

Gitea Vulnerability Exposes Private Container Images without Authentication

May 27, 2026 // 13:08

Cybersecurity researchers have disclosed a security flaw in Gitea, an open-source, self-hosted platform for version control, that allows unauthenticated remote attackers to pull private container […]

Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass

May 4, 2026 // 20:28

Progress Software has released updates to address two security flaws in MOVEit Automation, including a critical bug that could result in an authentication bypass. MOVEit […]

Critical cPanel Authentication Vulnerability Identified — Update Your Server Immediately

May 1, 2026 // 00:41

cPanel has released security updates to address a security issue impacting various authentication paths that could allow an attacker to obtain access to the control […]