Articles tagged with keycloak.
TrustSink turns a rogue Entra external MFA provider into a password trap after an admin compromise. What it needs, why…
Login is one of the biggest sections of a vendor security questionnaire. What the SSO, MFA, access review, audit log…
Connect Cursor to the Skycloak MCP server at mcp.skycloak.io, sign in with browser OAuth, and manage Keycloak clusters, realms, apps…
Use Claude Code or Cursor to review Keycloak realm exports safely: redact secrets, catch PKCE and audience mistakes, and keep…
CVE-2026-95503 lets an adjacent-network attacker spoof the KDC when Keycloak does Kerberos password authentication without SPNEGO. No fixed release yet.
Okta shipped Resource Access Certifications for AI agents on 22 September 2026. What the control does, and how to run…
AI coding agents find bugs and bad configs. They do not replace token issuance, audience checks, step-up, or revocation. Here…
CVE-2026-17526 let a Keycloak impersonation-role holder take over a realm admin. Fixed in 26.7.4 on 16 September 2026, and on…
Keycloak 26.x ships no push authenticator, so MFA fatigue lands differently here. The exposure that matters is authenticator enrollment, and…
Okta widened shadow AI agent discovery at Oktane 2026. Keycloak has no endpoint scanner, but it owns the chokepoint where…
Get tutorials, product updates, and Keycloak tips delivered to your inbox.