vulnerability Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account A critical vulnerability (CVE-2026-18963) in Keycloak allows unauthenticated attackers to force a password reset and take over any user account, including administrative accounts. Red Hat and Keycloak have released patches to address the issue, and a temporary mitigation involves disabling the ‘Forgot password’ functio… The Hacker News · 6d ago Critical CVE-2026-18963CVE-2026-15571password-resetauthenticationkeycloak
threat-intel DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts A Microsoft 365 device code phishing campaign, leveraging collaboration-themed lures, has been observed targeting M365 accounts. The campaign, utilizing a reusable tooling layer called DEBULL, bypasses multi-factor authe… The Hacker News · Jul 7, 2026 High HRTRdevice-codephishingmicrosoft
threat-intel The Four Elevations of Effective Fraud Prevention This article discusses a multi-layered approach to fraud prevention, emphasizing the importance of monitoring across all customer touchpoints – from individual transactions to platform-wide activity. It advocates for col… BleepingComputer · Jun 25, 2026 High fraudaccount-takeoverauthentication