OpenStack Keystone delegated tokens could create persistent credentials and escape project scope
OSSA-2026-037 covers CVE-2026-80182 and CVE-2026-80184: delegated tokens could extend access lifetime and cross an intended project boundary.
Active Directory, Entra ID, authentication, PKI and privileged access: attack paths, secure configuration, detection and retesting.
OSSA-2026-037 covers CVE-2026-80182 and CVE-2026-80184: delegated tokens could extend access lifetime and cross an intended project boundary.
DPoPProofJwtDecoderFactory could forget a used jti after cache pressure. We explain replay preconditions, fixed versions and OAuth 2.0 monitoring.
Three LemonLDAP::NG and Net::OAuth flaws show how state, oauth_verifier and pre-auth dispatch semantics can quietly move an SSO trust boundary.
An option-merging error makes @fastify/jwt ignore a route-specific key. We explain the authorization bypass, affected architectures and upgrade to 10.2.2.
GitGuardian found thousands of n8n tokens in public commits. A total of 321 active instances accepted keys that exposed workflows and downstream credentials.
Unit 42 documented three attacks on Google Password Manager in Chrome for Windows. We explain the prerequisites, user-verification flag and defenses.
How to split an environment into tiers, what really belongs to Tier 0, how to enforce the split technically and how to migrate without downtime.
How JWT verification works and where it breaks: alg confusion, kid injection, JWKS handling, iss/aud validation, revocation, testing and detection.
Credentials linked to more than 70,000 FortiGate devices were leaked. FortiBleed is not a new zero-day: learn the confirmed facts and response steps.
Protect passwords, tokens and API keys with workload identity, Vault, KMS, short TTLs, rotation, audit trails and a tested leak-response process.
PAM reduces risks from administrator accounts, secrets and sessions. Learn how to deploy JIT access, session control and meaningful metrics.
A quantum computer will break RSA and ECC, and the "collect now, decrypt later" attack is underway today. We discuss ML-KEM, ML-DSA, hybrid modes and migration plan.
Passkeys remove passwords and are phishing-resistant. We explain how they work, how they differ from MFA and how to start rolling them out.
MFA is the cheapest risk reduction we know — but only when deployed well. The differences between methods, a staged rollout plan and common traps.
Shared passwords in a spreadsheet are a ticking bomb. How a business password manager works, how to choose one and roll it out to teams.
Technical SAML 2.0 testing for XML signatures, wrapping, Audience, Destination, Recipient, replay, RelayState and identity-provider key rotation.
Audit TLS 1.3, mutual TLS and PKI: protocol negotiation, identity validation, certificate paths, revocation, 0-RTT and key rotation.
Stolen personal data lets criminals take out loans or register a company in your name. How identity theft happens and how to protect yourself.
Change your password every 30 days? Invent complex character strings? We explain which password rules are outdated myths and what really protects your accounts.
Assess Entra ID tokens, consent, roles, Conditional Access, PIM, service principals, workload identities, hybrid trust and cloud identity detection.
A technical model for NTLM relay to SMB, LDAP and HTTP, with safe assessment, signing, channel binding, EPA, detection and NTLM migration guidance.
Understand S4U2self, S4U2proxy, KCD and RBCD, then safely assess delegation ACLs, SPNs, tickets, detection and lateral-movement exposure.
Audit AD CS, certificate templates and ESC1–ESC15 paths. Understand PKINIT, strong mapping, safe validation, detection and enterprise PKI hardening.
We turn current threats into role-based training, safe exercises and a clear reporting path. The free Academy remains available for self-directed learning.