Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: password-reset (2 articles)Clear

ShinyHunters claims theft of Florida driver records through a password-reset flaw

The extortion group ShinyHunters claims it breached Florida's DAVID system, an internal driver and vehicle database used by law enforcement and state officials, and stole more than 200,000 records. According to the group, a password-reset flaw let it take over several internal accounts, including those of motor-vehicle employees and, notably, an FBI agent, which it then used to pull driver files, photos, and signatures by cycling through record IDs. It posted a sample it says is a public figure's license as proof and set a leak deadline. Florida's agency has not confirmed the breach, and the claim is unverified, but the group is reportedly probing other states' motor-vehicle systems the same way.

Check
Organizations with self-service password-reset flows should test them for account-takeover flaws, and agencies operating sensitive lookup systems should monitor for accounts enumerating records by ID and for logins from unexpected sources.
Affected
Government and law-enforcement lookup systems reachable with staff accounts; a password-reset weakness let attackers hijack employee and agent logins and mass-download driver records, exposing highly sensitive identity and vehicle data for extortion.
Fix
Harden password-reset and authentication flows, require phishing-resistant authentication for privileged lookup systems, alert on bulk record access and ID enumeration, limit how much any single account can pull, and verify breach claims.

Critical Keycloak flaw lets attackers take over any account via password reset

A critical flaw in Keycloak, the widely used open-source identity and access management server, lets an unauthenticated attacker take over any account through its password-reset flow. Tracked as CVE-2026-18963, the bug is improper state validation in the reset-credentials flow: a crafted request to the reset endpoint pushes the authentication session straight to the password-update step, so the action token Keycloak normally emails is never required, and the attacker sets new credentials for a chosen user. It needs no user interaction and works against any account, including administrators. Red Hat fixed it in Keycloak 26.7.2 and related releases; there is no confirmed exploitation yet.

Check
Upgrade Keycloak to a fixed release such as 26.7.2, and if you ran a vulnerable version, revoke active and offline sessions and rotate client secrets, since tokens may already have been issued.
Affected
Organizations running Keycloak with the forgotten-password feature enabled on a vulnerable version (CVE-2026-18963); an unauthenticated attacker can reset and take over any user or admin account without the email verification step.
Fix
Patch promptly, then treat exposure as possible account compromise: revoke sessions, rotate accessible client secrets, review identity links and admin permissions, and remember downstream services may hold tokens issued before patching.