Every story tagged Authentication, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
406 stories · open in the command center
On MISP instances configured to require TOTP enrolment (Security.otp_required), the enforcement of the mandatory two-factor authentication setup applied only to standard browser requests. An authenticated user who had not yet enrolled in TOTP could bypass the forced setup by issuing any non-browser request type, including AJAX/XHR calls, REST API requests, .json format URLs, restSearch queries, or automation actions. Because these machine-readable request shapes cannot follow the redirect that the browser path uses to send the user to the TOTP enrolment page, the guard simply skipped the check and the user retained full access to the instance without completing the required second-factor setup. The initial fix (commit 8deb0619e) added a guard specifically for AJAX requests. A follow-up fix (commit 6b527ba6e) broadened the guard to cover every non-browser request shape, while preserving the exemption for identities authenticated via API key (logged_by_authkey flag). Impact: an auth...
Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "local blackouts on the whole continent" in Europe. An email address for the user_account property is required; however, a user can view the email address associated with their parent organization.
A command injection vulnerability exists in the h-ui (version v0.0.25 and below) administrative API due to improper validation of the listen configuration field. When an authenticated administrator submits a value containing shell metacharacters, the application constructs nftables/iptables rule strings using fmt.Sprintf and executes them via bash -c as root. Because the listen field lacks port or format validation, arbitrary OS commands can be injected and executed with root privileges.
LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess mode HTTP server that allows remote unauthenticated attackers to access management endpoints listening on all interfaces by default. Attackers can read environment credentials via GET /env and configuration via GET /config, clear caches, delete cache objects, and modify tenant quotas to evict other tenants' cached data.
Gophish through 0.12.1 contains an insecure direct object reference vulnerability that allows authenticated users to take over other users' groups, templates, landing pages and sending profiles. Attackers can supply another user's sequential id in POST requests to /api/groups/, /api/templates/, /api/pages/ or /api/smtp/ to overwrite and reassign objects, locking out owners and exposing victims' recipient lists.
: Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit. Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match with no credential check. This issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0 through 2.20.17. Users are recommended to upgrade to versions 2.23.6, 2.22.5, or 2.20.18 which fix the issue.
A fast-moving browser-in-browser phishing campaign is impersonating trusted AI and advertising brands to steal advertising credentials, MFA codes, payment methods, and even linked client accounts, creating direct financial loss and operational risk for marketing and digital teams. For CIOs and technology leaders, the key implication is that attackers can rapidly rebrand a reusable phishing platform, so IT organizations need stronger identity controls, continuous domain/reputation monitoring, and detections that work across Google, Meta, TikTok, and Okta workflows—not just brand-specific defenses.
Google appears to be working on a low-light Face Unlock improvement for Pixel devices, which could make biometric authentication more reliable and reduce friction for employees using phones as business endpoints. For IT leaders, the strategic value is improved mobile security and user experience, but the feature is still unconfirmed and may depend on future Android builds or hardware assumptions, so it should be treated as a roadmap watch item rather than a planning certainty.
Incorrect authorization in Selection in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Incorrect authorization in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Authentication bypass vulnerabilities exist in the web management interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to gain unauthorized access to the affected system.
Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated administrative privilege whose scope is not fully enforced during authorization checks. Elasticsearch contains an incorrect authorization weakness in a configurable, non-default privilege that lets an administrator delegate limited role-management capability to another user, scoped to specific indices. The authorization check that enforces this scoping does not correctly account for a role-definition setting that can expand the matched index set. A user holding this delegated privilege with a broadly-scoped index pattern can exploit this inconsistency by updating their own assigned role to gain access to indices that should remain restricted, including internal security data. This can enable further escalation up to full administrative control of the cluster.
Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, causes the identity provider (IdP) to deliver authentication material to an attacker-controlled URL instead of to CloudVision.
Attackers hijacked multiple country-code top-level domains to issue counterfeit TLS certificates for Google and other major services, demonstrating that DNS and certificate-validation weaknesses can be exploited to impersonate trusted digital properties at scale. For CIOs and technology leaders, this highlights that browser-side protections are not enough: IT must treat certificate governance, DNS integrity, and continuous monitoring as core controls for protecting customer trust, transaction security, and brand reputation. The incident also underscores the operational risk of slow certificate revocation and the need for layered defenses across web, identity, and infrastructure teams.
OpenSSH 10.6 delivers important security fixes that reduce exposure to SSH-related data leakage, path traversal, and credential handling issues, while also tightening input validation for usernames and deprecating fragile legacy options. For CIOs and technology leaders, the release underscores that core infrastructure tools are evolving faster in response to both AI-assisted vulnerability discovery and real-world attack risk, which means IT teams should expect shorter remediation cycles and more frequent patch deployments. Organizations that rely on SSH for administration, automation, or file transfer should assess compatibility impacts now, especially around compression behavior and older platforms, to avoid operational disruptions.
AI agents are moving from novelty to transaction-layer tools, but widespread website blocking and anti-bot defenses are now a major adoption barrier. For CIOs and technology leaders, this creates a strategic inflection point: organizations need to decide whether to support agentic commerce with new identity, security, and API standards or risk frustrating customers and missing a new digital channel. IT teams should expect pressure to distinguish legitimate user-authorized agents from malicious automation, while also rethinking fraud controls, access policies, and partner integrations.
ASOS received a rogue in-app notification claiming its Snowflake environment had been compromised and threatening to leak data, but the claim has not been verified. Even without confirmed theft, the incident shows how a single security rumor can quickly trigger brand damage, customer anxiety, and a material market reaction, underscoring the business risk of cloud data platforms and the need for rapid, credible incident handling. For IT organizations, it reinforces the importance of strong identity controls, monitoring, and clear communication paths across security, data, and customer-facing teams.
ASOS appears to have suffered a highly visible extortion incident in which customers received app push notifications allegedly sent by hackers, turning a potential data breach into a direct customer-facing trust event. For CIOs and technology leaders, the key implication is that compromise may extend beyond a cloud data platform like Snowflake into notification infrastructure and credentials, underscoring the need to harden identity controls, segment critical systems, and validate that customer communications cannot be spoofed or abused. This kind of event can quickly damage brand confidence, increase regulatory exposure, and force IT teams to coordinate incident response across application, cloud, security, and customer operations.
The article highlights a growing identity security gap: many enterprise apps still operate outside SSO protections, creating blind spots for access control, compliance, and user offboarding. For CIOs and IT leaders, the strategic implication is that identity management must extend beyond traditional SSO coverage to enforce policy across the full app estate, reducing risk without adding excessive friction for employees.
mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4, the packages read a wallet address from the client-supplied credential.source, checked whether that public address met configured on-chain conditions, and returned a successful free-access receipt without invoking the wrapped payment verifier or proving that the caller controlled the wallet. An unauthenticated attacker could name any qualifying wallet and obtain content that should require payment, and cached grants could be reused for the configured cache lifetime. The corrected packages prevent free-access authorization unless payer control has been established. These issues are fixed in @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4.
Plane is an open-source project management tool. Prior to 1.4.0, GET /api/workspaces/{slug}/entity-search/?query_type=user_mention returns workspace-member display names, UUIDs, and avatar URLs to any authenticated user who knows the workspace slug, even when the caller is not a workspace member. The endpoint also exposes ProjectMember rows under the same condition. SearchEndpoint in apps/api/plane/app/views/search/base.py inherits BaseAPIView with only permission_classes = [IsAuthenticated] and performs no workspace-membership check. This issue is fixed in 1.4.0.
Plane is an open-source project management tool. Prior to 1.4.0, a user whose account has been deactivated by setting is_active=False can still log in with existing credentials. Successful authentication silently changes is_active back to True, reactivating the account without notifying the administrator. This issue is fixed in 1.4.0.
Plane is an open-source project management tool. Prior to 1.4.0, Plane validates GITEA_HOST only for its URL scheme and does not reject hosts that resolve to private or internal IP addresses. The four outbound requests in the Gitea OAuth flow are derived from this unvalidated host and do not call validate_url(). In addition, avatar_url is taken from the Gitea user's profile, where users can configure external avatar URLs. After an administrator enables Gitea OAuth for a legitimate instance, a Gitea user can set an internal URL as the profile avatar and log in through Gitea, causing Plane to fetch the internal target without validation. This issue is fixed in 1.4.0.
Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses a six-digit numeric OTP with approximately 20 bits of entropy. The verifier has no per-code failed-attempt counter, and an incorrect code does not increment a counter, invalidate the Redis entry, or lock the email address. The verifier extends django.views.View rather than DRF's APIView, so the configured AnonRateThrottle limit does not apply. The middleware stack also contains no Django-level rate limiter such as django-ratelimit, django-axes, or an IP-throttling middleware. This vulnerability is fixed in 1.4.0.
Bromcom’s breach shows how legacy authentication components left running for internal dependencies can become a customer data exposure even when core systems remain uncompromised. For CIOs and technology leaders, the business risk is not just the leaked email and registration metadata, but the trust, compliance, and operational damage that can follow from poor service retirement discipline and incomplete dependency mapping.
The article highlights a practical move away from a cloud-tied authenticator toward an open source, offline alternative, underscoring a broader enterprise lesson: security and access dependencies on third-party cloud services can create avoidable operational risk. For CIOs and technology leaders, the business implication is clear—identity and authentication tools should be evaluated not just for convenience, but for resilience, portability, and control over critical access workflows.
This article highlights a gray market in China where resellers use harvested identities, prepaid/USDT-funded cards, and proxy networks to buy and resell Claude access, bypassing platform controls and geographic restrictions. For CIOs and technology leaders, the key implication is that AI services are becoming an identity-, payment-, and network-security problem as much as a software procurement issue, increasing exposure to fraud, policy violations, and supply-chain risk. IT organizations should assume that unauthorized AI access and account sharing can evade standard controls, so governance must extend to vendor verification, usage monitoring, and enforcement of regional and payment restrictions.
The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypass two-factor authentication, including on administrator accounts.
In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing subkey whose Subkey Binding signature carried no embedded Primary Key Binding (cross-certification) signature, in the case where that binding omits a Key Flags subpacket. RFC 9580 sec. 5.2.1.8 and sec. 10.1.3 require the embedded Primary Key Binding signature on any subkey that can issue signatures; it is the subkey's own statement that it belongs to the primary key it is bound under. OpenPGPCertificate resolved the subkey's key flags two different ways. isSigningKey() goes through getKeyFlags() and getApplyingSubpacket(), which falls back to the primary key's direct-key or primary User ID self-signature when the binding signature omits the subpacket, so the subkey inherited the primary's SIGN_DATA and counted as signing-capable; verifyEmbeddedPrimaryKeyBinding(), which enforces the requirement, reads the binding signature's own hashed subpackets, found no SIGN_DATA there, a...