Tag

keycloak

Articles tagged with keycloak.

security-best-practices

TrustSink: Rogue External MFA and Phishing-Resistant Login

TrustSink turns a rogue Entra external MFA provider into a password trap after an admin compromise. What it needs, why…

Guilliano Molaire Guilliano Molaire 10 min read
best-practices

What Vendor Security Questionnaires Ask About Login

Login is one of the biggest sections of a vendor security questionnaire. What the SSO, MFA, access review, audit log…

Guilliano Molaire Guilliano Molaire 9 min read
Tutorials

Add Skycloak to Cursor with MCP: Operate Managed Keycloak from Your IDE

Connect Cursor to the Skycloak MCP server at mcp.skycloak.io, sign in with browser OAuth, and manage Keycloak clusters, realms, apps…

Guilliano Molaire Guilliano Molaire 4 min read
security

Harden Keycloak with Claude Code and Cursor: An AI-Assisted Security Review Playbook

Use Claude Code or Cursor to review Keycloak realm exports safely: redact secrets, catch PKCE and audience mistakes, and keep…

Guilliano Molaire Guilliano Molaire 4 min read
security

CVE-2026-95503: Keycloak Kerberos Does Not Verify the KDC

CVE-2026-95503 lets an adjacent-network attacker spoof the KDC when Keycloak does Kerberos password authentication without SPNEGO. No fixed release yet.

Guilliano Molaire Guilliano Molaire 10 min read
comparisons

Resource Access Certifications for AI Agents vs Keycloak

Okta shipped Resource Access Certifications for AI agents on 22 September 2026. What the control does, and how to run…

Guilliano Molaire Guilliano Molaire 11 min read
security

Secure Your App with AI: What AI AppSec Can and Cannot Replace in IAM

AI coding agents find bugs and bad configs. They do not replace token issuance, audience checks, step-up, or revocation. Here…

Guilliano Molaire Guilliano Molaire 4 min read
security

CVE-2026-17526: Keycloak Impersonation Escalates to Realm Admin

CVE-2026-17526 let a Keycloak impersonation-role holder take over a realm admin. Fixed in 26.7.4 on 16 September 2026, and on…

Guilliano Molaire Guilliano Molaire 8 min read
security

MFA Fatigue and Keycloak: The Real Risk Is Enrollment Abuse

Keycloak 26.x ships no push authenticator, so MFA fatigue lands differently here. The exposure that matters is authenticator enrollment, and…

Guilliano Molaire Guilliano Molaire 8 min read
security

Shadow AI Agents: Okta’s Endpoint Scan vs Keycloak Inventory

Okta widened shadow AI agent discovery at Oktane 2026. Keycloak has no endpoint scanner, but it owns the chokepoint where…

Guilliano Molaire Guilliano Molaire 9 min read

Stay ahead on identity & security

Get tutorials, product updates, and Keycloak tips delivered to your inbox.

© 2026 Skycloak. All Rights Reserved. Design by Yasser Soliman