Read more about the article Keycloak CVE-2026-18963: Account Takeover via Password Reset
Keycloak CVE-2026-18963 reset-credentials takeover – broken handshake diagram

Keycloak CVE-2026-18963: Account Takeover via Password Reset

  • Post author:
  • Post category:Security

Keycloak's reset-credentials flow skips its own email action token: an unauthenticated attacker can set a new password on any account, including admins. CVSS 9.1, fixed in 26.7.2 - patch guide, detection hunting, and the temporary mitigation inside.

Continue ReadingKeycloak CVE-2026-18963: Account Takeover via Password Reset
Read more about the article GitLab Exploited in Days & the 86-Minute Rust Backdoor
Weekly threat intelligence August 2026 W3 – disclosure-to-exploit delta clock

GitLab Exploited in Days & the 86-Minute Rust Backdoor

  • Post author:
  • Post category:Security

GitLab CVE-2026-19478 went from disclosure to in-the-wild exploitation in days; a compromised maintainer account backdoored three Rust crates with 245M downloads for 86 minutes; Citrix shipped a CVSS 9.3 NetScaler auth bypass. The week's threats, IoCs, and your Monday patch list.

Continue ReadingGitLab Exploited in Days & the 86-Minute Rust Backdoor
Read more about the article XXE Injection: A Detection and Prevention Guide
XXE Injection: A Detection and Prevention Guide

XXE Injection: A Detection and Prevention Guide

XXE Injection remains one of the most dangerous web vulnerabilities, allowing attackers to read server files, execute SSRF, and even achieve remote code execution. Master in-band, out-of-band, and blind XXE techniques with practical payload examples.

Continue ReadingXXE Injection: A Detection and Prevention Guide
Read more about the article CORS Misconfigurations in Modern Web Apps: How to Find and Fix Them
CORS Misconfigurations in Modern Web Apps: How to Find and Fix Them

CORS Misconfigurations in Modern Web Apps: How to Find and Fix Them

CORS misconfigurations rank among the most critical web security vulnerabilities in modern applications. Learn how to identify, exploit, and remediate cross-origin resource sharing flaws including origin reflection, null origin trust, and subdomain bypass techniques.

Continue ReadingCORS Misconfigurations in Modern Web Apps: How to Find and Fix Them