CVE-2026-15571: Predictable Account-Linking Hash in Keycloak
A predictable account-linking hash in Keycloak could enable account takeover via a malicious OpenID Connect client. Fixed in version 26.7.2.
A predictable account-linking hash in Keycloak could enable account takeover via a malicious OpenID Connect client. Fixed in version 26.7.2.
Red Hat and the Keycloak project have released patches for a critical vulnerability, CVE-2026-18963, that could let unauthenticated attackers take over any…
Cybersecurity researchers at CTM360 have exposed a large-scale, global recruitment-themed phishing campaign that leverages Browser-in-the-Browser (BitB) windows to steal Google and Facebook…
The RecruitTrap campaign also targets Facebook credentials through fake authentication popups, enabling account takeover and potential access to advertising platforms.
N-able has issued Hotfix 2 for its N-central Remote Monitoring and Management (RMM) product, responding to ongoing exploitation of a recently disclosed…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity vulnerability affecting N-able N-central to its Known Exploited Vulnerabilities (KEV)…
Eight security flaws in NodeBB were disclosed on July 24, 2026, along with exploit code. Discovered by Aikido Security's AI pentest agents…
A separate NodeBB federation vulnerability, CVE-2026-58593, filed on July 1, 2026, allows an outside server to post and send messages in the…
A critical vulnerability in n8n's Enterprise token exchange feature, tracked as CVE-2026-59208, allows attackers to log in as any user by exploiting…
Zoom has released security updates for a critical security flaw impacting Zoom Workplace for Windows that could facilitate account takeover. The vulnerability,…