<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Account-Takeover on CuraSec</title><link>https://curasec.metacog.co.kr/tags/account-takeover/</link><description>Recent content in Account-Takeover on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 25 Aug 2026 11:39:54 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/account-takeover/index.xml" rel="self" type="application/rss+xml"/><item><title>Critical Keycloak Password Reset Flaw Enables Unauthenticated Account Takeover</title><link>https://curasec.metacog.co.kr/insights/2026-08-25-critical-keycloak-password-reset-flaw-could-let-unauthentica/</link><pubDate>Tue, 25 Aug 2026 11:39:54 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-25-critical-keycloak-password-reset-flaw-could-let-unauthentica/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Keycloak is a common IAM component in Kubernetes and cloud stacks; a public PoC for unauthenticated account takeover makes exploitation practical regardless of the low EPSS. Patch Keycloak to the fixed release immediately and audit authentication logs for anomalous password-reset activity since disclosure.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No active exploitation or IOCs yet, but a public PoC raises the likelihood of opportunistic abuse soon. Build or tune a detection for high-volume or cross-account password-reset requests against Keycloak endpoints so you are ready to alert when attempts begin.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> An unauthenticated takeover flaw in an IAM server is high-blast-radius if exploited — it could affect all accounts in the realm. Confirm your engineering team has scheduled the Keycloak patch and verify whether any customer-facing SSO flows depend on it.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-18963 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub&lt;/li>
&lt;/ul></description></item><item><title>Insurance phishing evolves to real-time AiTM account hijacking</title><link>https://curasec.metacog.co.kr/insights/2026-07-25-ctm360-research-reveals-how-insurance-phishing-has-evolved-i/</link><pubDate>Sat, 25 Jul 2026 12:08:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-25-ctm360-research-reveals-how-insurance-phishing-has-evolved-i/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> AiTM (adversary-in-the-middle) phishing bypasses MFA by proxying sessions in real time; build or tune detections for impossible-travel, session token anomalies, and auth from new ASNs immediately after login events.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Real-time session hijacking erodes MFA as a control — useful context for risk register and security awareness program updates, but no immediate action required given no corroborating signals or named breach.&lt;/li>
&lt;/ul></description></item><item><title>Zoom patches critical unauthenticated account-takeover flaw in Windows client</title><link>https://curasec.metacog.co.kr/insights/2026-07-16-zoom-warns-of-critical-account-takeover-vulnerability/</link><pubDate>Thu, 16 Jul 2026 12:18:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-16-zoom-warns-of-critical-account-takeover-vulnerability/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Zoom&amp;rsquo;s Windows desktop client and SDK carry a critical unauthenticated account-takeover flaw — high severity but no KEV listing or public PoC moves this to Plan rather than Act. Update Zoom Windows clients and any SDK integrations to the patched version as soon as your next patch window allows.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, active exploitation evidence, or mapped TTPs accompany this advisory, so there is no immediate detection or hunt work. File awareness of the attack vector (unauthenticated ATO on Zoom Windows) so detection rules can be prioritized if exploitation begins appearing in the wild.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Zoom is standard enterprise communication infrastructure, and a critical unauthenticated account-takeover flaw warrants confirming that endpoint and IT teams are deploying the patched client org-wide. Without reported exploitation this does not require leadership escalation yet, but track it for the next risk review.&lt;/li>
&lt;/ul></description></item><item><title>Zoom Patches Critical Windows Flaw (CVSS 9.8) Enabling Account Takeover</title><link>https://curasec.metacog.co.kr/insights/2026-07-16-zoom-patches-critical-windows-flaw-that-could-enable-account/</link><pubDate>Thu, 16 Jul 2026 12:18:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-16-zoom-patches-critical-windows-flaw-that-could-enable-account/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> A public PoC on GitHub for a CVSS 9.8 improper-input-validation flaw in Zoom Desktop Client, VDI Client, and Meeting SDK for Windows raises exploitation risk significantly even without KEV listing; update all three Zoom Windows products to the patched versions immediately.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> With a public PoC in circulation for a critical Zoom account-takeover vulnerability, exploitation attempts against unpatched Windows endpoints are plausible now; hunt for anomalous Zoom process behavior and unexpected authentication events since the patch cycle may lag exposure.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Zoom is near-universal in enterprise environments, and a CVSS 9.8 flaw with a public PoC in the Windows client warrants confirming with engineering that patching is tracked and on a days-not-weeks timeline before this surfaces in customer security questionnaires.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-53412 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub&lt;/li>
&lt;/ul></description></item></channel></rss>