Keycloak flaw lets unauthorized password resets
CVE-2026-18963 allows full account takeover via reset flow; patches out.
7 results for “identity security”
CVE-2026-18963 allows full account takeover via reset flow; patches out.
As AI accelerates account takeover attacks, experts argue credentials alone can no longer secure access.
Okta plans to acquire Permiso Security to bolster its identity threat detection capabilities within multi-cloud environments.
Threat actors are weaponizing OAuth client ID spoofing to validate stolen credentials while remaining invisible to standard telemetry.
Microsoft details how threat actors bypassed traditional defenses to compromise Salesforce environments via OAuth and guest access.
A new subscription-based phishing service leverages device code theft and AI to bypass traditional security defenses.
A flurry of 37 cybersecurity acquisitions in June 2026 underscores how major tech firms are rapidly integrating AI and identity governance.