ZDI-26-129: Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability

ZDI-26-129: Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability

• CVE ID | CVE-2026-2491 | CVSS SCORE | 6 • 3, AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L | AFFECTED VENDORS | Socomec | AFFECTED PRODUCTS | DIRIS A-40 | VULNERABILITY DETAILS | This vuln

Threat Intelligence · February 25, 2026 (updated February 25, 2026) · 1 min · 198 words
CrowdStrike Named Customers' Choice 2026 Gartner Peer Insights Voice User Authentication

CrowdStrike Named Customers' Choice 2026 Gartner Peer Insights Voice User Authentication

• CrowdStrike awarded Customers’ Choice for user authentication in 2026. • Recognition reflects high customer satisfaction and product reliability. • Falcon platform offers multi‑f

Cybersecurity · February 23, 2026 (updated February 24, 2026) · 3 min · 529 words
ZDI-26-111: MLflow Use of Default Password Authentication Bypass Vulnerability

ZDI-26-111: MLflow Use of Default Password Authentication Bypass Vulnerability

• Advisory Details MLflow Use of Default Password Authentication Bypass Vulnerability ZDI-26-111ZDI-CAN-28256 This vulnerability allows remote attackers to bypass authentication on

Threat Intelligence · February 19, 2026 (updated February 25, 2026) · 2 min · 214 words
No Display? No Problem: Cross-Device Passkey Authentication for XR Devices

No Display? No Problem: Cross-Device Passkey Authentication for XR Devices

• We’re sharing a novel approach to enabling cross-device passkey authentication for devices with inaccessible displays (like XR devices). • Our approach bypasses the use of QR cod

Engineering Blogs · February 4, 2026 (updated February 25, 2026) · 2 min · 279 words
No Display? No Problem: Cross-Device Passkey Authentication for XR Devices

No Display? No Problem: Cross-Device Passkey Authentication for XR Devices

• We’re sharing a novel approach to enabling cross-device passkey authentication for devices with inaccessible displays (like XR devices). • Our approach bypasses the use of QR cod

Is that allowed? Authentication and authorization in Model Context Protocol

Is that allowed? Authentication and authorization in Model Context Protocol

• MCP enables AI agents to access services via standardized remote APIs, similar to REST. • Authentication and authorization happen at the transport layer, ensuring secure client-s

Developer Ecosystem · January 21, 2026 (updated February 24, 2026) · 1 min · 186 words

W3C Invites Implementations of Web Authentication: An API for accessing Public Key Credentials Level 3

• The Web Authentication Working Group has published Web Authentication: An API for accessing Public Key Credentials Level 3 as a W3C Candidate Recommendation Snapshot. • This spec

W3C Invites Implementations of Web Authentication: An API for accessing Public Key Credentials Level 3

• The Web Authentication Working Group has published Web Authentication: An API for accessing Public Key Credentials Level 3 as a W3C Candidate Recommendation Snapshot. • This spec

Open Protocols for Agent Interoperability Part 2: Authentication on MCP

Open Protocols for Agent Interoperability Part 2: Authentication on MCP

• AWS Open Source Blog Open Protocols for Agent Interoperability Part 2: Authentication on MCP In Part 1 of our blog series on Open Protocols for Agent Interoperability we covered