Skip to content
tag — identity

grep -rl "identity" ./articles

#identity

14 articles

The anonymous client passes the ownership check by being nobody

2026-09-09Security

Two flaws in FreeIPA and 389 Directory Server are unremarkable on their own. Together they let an unauthenticated client write a token entry with blank ownership, satisfy the check for whether it owns that entry, and attach a Kerberos identity with administrative group membership. Nobody has published how to tell whether it already happened to you.

They phoned a security company, used real employees' names, and got in

2026-08-25Security

ShinyHunters registered a fake ReliaQuest SSO page and rang staff one by one, each time impersonating a named colleague from the security team. One person typed their password and approved the push. ReliaQuest says the attackers got view-only access to an Okta dashboard and nothing else — and the interesting part is which controls held.