Keycloak flaw lets unauthorized password resets
CVE-2026-18963 allows full account takeover via reset flow; patches out.
8 results for “account takeover”
CVE-2026-18963 allows full account takeover via reset flow; patches out.
Device-bound session credentials could curb account takeovers, but rollout is limited for now.
As AI accelerates account takeover attacks, experts argue credentials alone can no longer secure access.
New research details how threat actors are ditching delayed credential harvesting for live, session-based account hijacking.
A critical vulnerability in Budibase allows attackers to hijack existing user accounts by exploiting improper email validation in the OIDC login process.
A critical 9.8 severity vulnerability in Zoom's Windows desktop client exposes millions of users to potential account hijacking.
A Telegram-based phishing service is lowering barriers to entry for M365 attacks by automating complex bypass and exfiltration workflows.
A new subscription-based phishing service leverages device code theft and AI to bypass traditional security defenses.