🔑 One Request Steals Any Account — And Your Phone Is Being Tracked 📞
Two stories from today's security news deserve your attention: a critical flaw that lets anyone reset your password without your permission, and new evidence that commercial surveillance firms are quietly tracking phones across the globe through the phone network itself.
The "Forgot Password" Link That Hands Over Your Account
Keycloak is the login system sitting behind a huge number of company apps and internal tools — the thing that shows you a single sign-on page at work. Researchers found a critical flaw (CVE-2026-18963, scored 9.1 out of 10) that lets an attacker with no account, no password, and no access at all send one crafted request to the password-reset endpoint and simply change your password. The email verification step that's supposed to prove it's really you gets skipped entirely.
In plain terms: if your organization runs Keycloak and hasn't patched, someone on the internet could take over any account, including admin accounts, without stealing a single credential first. Administrators should update Keycloak immediately and turn off "Forgot password" in every realm until the patch is applied. If you're not sure whether your company uses Keycloak, that question is worth asking today.
Your Phone Number Is a Tracking Beacon — No Hacking Required
Citizen Lab published research showing two commercial surveillance vendors abusing SS7 and Diameter, the decades-old plumbing that lets phone networks hand your calls and texts between carriers around the world. In one case, a high-profile executive's phone was located repeatedly over just four hours using 11 different operator identities across nine countries, with the attackers switching protocols to slip past carrier firewalls. Another campaign sent a malicious text containing hidden SIM card commands that quietly turned the target's phone into a location beacon.
The unsettling part is that none of this requires malware on your device or a bad link you clicked. It's an abuse of the network your phone connects to, which means the usual advice — don't click suspicious things, keep your apps updated — doesn't help. For executives, journalists, and anyone whose location is valuable to someone else, this is a reminder that a phone number alone can be a liability, and that carrier-level protections matter as much as device-level ones.
Stay ahead of threats with GOCO Security at gocosecurity.com.
.jpg)
Comments
Post a Comment