Faav, 16, impersonated an administrator on Microsoft's internal Titan service with an unsigned token, reaching an estimated 17.3 trillion rows. Microsoft disabled the API four days after his report and paid a $5,000 bounty.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+30
- Incentives55
- Confidence55
Researchers read a token out of a co-located Worker in Cloudflare's production fleet, 360 times faster than the 2021 demo that justified language-level isolation.
Reality
- Evidence58
- Adoption45
- Hype gap+15
- Incentives55
- Confidence62
CVE-2026-5430 lets a token signed with an algorithm WSO2 does not support pass authentication as an administrator. watchTowr says tokens with administrator privileges baked in reached its honeypots on September 13.
Reality
- Evidence68
- Adoption20
- Hype gap+25
- Incentives45
- Confidence65
WSO2 published the fix in May. watchTowr saw forged tokens arrive at its honeypot in September. Its own replay against a correctly targeted deployment came back with the credentials the gateway holds.
Publishers:dev.to · security.docs.wso2.com Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence62
Row-level security in a no-backend Neon app refused 27 of 27 tenant attacks, yet a removed member read on for 928 seconds. A membership check in the policies closed that gap at a cost of about 5 ms on function calls.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence55
A dev.to build reproduces the runaway spend Mandiant reported in September by pointing three agents at the same Convex route and changing only where the server looks for the running total. Each call costs $2.50.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+18
- Incentives55
- Confidence48
FlashPoint pulled 555 AI-service tokens out of a single 44,791-token stealer dump, 24 of them still valid, and five dollars is the Telegram bulk price because a copied session leaves the victim's own login working.
Reality
- Evidence22
- Adoption30
- Hype gap+45
- Incentives55
- Confidence28
A dev.to design post puts a per-task scope check under every tool invocation and caps the agent's cloud credentials at fifteen minutes. The restrictions work by taking capability away from the model.
Reality
- Evidence32
- Adoption
- Insufficient
- Hype gap+30
- Incentives20
- Confidence45
Auth0's documentation gives middle-tier services and MCP servers an RFC 8693 route to call downstream APIs as the user. The token carries the delegation chain, and the exchange has its own rate ceiling.
Publishers:auth0.com
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap−12
- Incentives70
- Confidence58
Written as separate entries, a country check and a model allowlist become alternatives, so a caller from a restricted jurisdiction gets through by naming an approved model, and the policy still reports Accepted and Attached.
Reality
- Evidence62
- Adoption20
- Hype gap+12
- Incentives38
- Confidence64
A JWT signature only proves integrity when the verifier and the application already agree on algorithm, key and validity window, and in the vulnerable pattern all three are settled by input the attacker sent.
Reality
- Evidence52
- Adoption
- Insufficient
- Hype gap+12
- Incentives18
- Confidence56
The whole auth layer of this job-alert tool is about fifty lines. Three credentials with lifetimes of 15 minutes, 30 days and a year come out of one HS256 secret, separated by a custom claim that one function compares.
Reality
- Evidence52
- Adoption10
- Hype gap−8
- Incentives45
- Confidence45
An engineer writing on dev.to traces the tenant-and-user token that scopes every query in multi-tenant SaaS, and what breaks when the caller is a process choosing its own API calls on a user's behalf.
Reality
- Evidence44
- Adoption
- Insufficient
- Hype gap+15
- Incentives22
- Confidence46
A WordPress plugin author implemented Web Push against VAPID and ES256 in a few hundred lines of PHP with OpenSSL. The crypto took an afternoon; the week went to a missing 0x04 byte, a wrong JWT audience and DER-encoded signatures.
Reality
- Evidence62
- Adoption12
- Hype gap−8
- Incentives30
- Confidence58
AWS's multi-Region replication copies a Cognito pool's configuration, hashed credentials and IdP settings into one other Region with eventual consistency. Only the primary accepts writes, so failover planning becomes a per-path decision.
Reality
- Evidence66
- Adoption
- Insufficient
- Hype gap+22
- Incentives85
- Confidence64
A checklist written by someone who sells generated multi-tenant backends dates the tenant model and the source of tenant identity to day one, and the database isolation argument to the first paying customer. The author then runs the test on their own product.
Reality
- Evidence42
- Adoption
- Insufficient
- Hype gap−10
- Incentives70
- Confidence52
The policy lives in a JSON file a reviewer can read without reading the code, and the gate resolves overlapping matches by severity, so a JWT found inside a log line is denied instead of merely warned on.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+30
- Incentives78
- Confidence45
AgentCore Identity now hosts the redirect leg and keeps the tokens, and what you configure in exchange is an OIDC application in your corporate IdP, a service role, and AWS's callback URL inside your GitHub and Slack apps.
Reality
- Evidence62
- Adoption12
- Hype gap+8
- Incentives88
- Confidence55
Okta's read of one Telegram stealer dump shows commodity malware now hoovering up AI session tokens and API keys, and a replayed token walks past MFA because the second factor was spent when the token was minted.
Reality
- Evidence61
- Adoption56
- Hype gap+16
- Incentives71
- Confidence57
Consolidating every database credential onto one server leaves one process deciding who is asking on each request, which is why LibreDB Studio's authors re-verify the caller inside every route rather than trusting a matcher that exempts any path with a dot.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap−15
- Incentives55
- Confidence55
Earlier coverage
- CSA's Agentic Trust Framework maps agent autonomy to an auth stack you already run
Product · September 6, 2026 · 1 publisher
- One boolean in VerifyAudience decides whether a JWT with no audience claim gets through
Build · September 4, 2026 · 1 publisher
- TeamCity's new OIDC plugin turns your build server into the credential issuer
Build · September 1, 2026 · 1 publisher
- Google Cloud IAP fences staging for free until the client stops being a browser
Build · September 1, 2026 · 1 publisher
- A JWT model that mints tokens will also accept an unsigned claims dict
Build · August 30, 2026 · 1 publisher
- Reversibility decides which of six services may guess and which must refuse
Build · August 28, 2026 · 1 publisher
- One authorization flaw survives both plan and default mode across six agent-built apps
Science · August 28, 2026 · 1 publisher
- Jenkins static AWS keys work from anywhere; the OIDC replacement fails in four known ways
Build · August 27, 2026 · 1 publisher
- The five-minute grep: what `synchronize: true` tells a reviewer before your tests do
Build · August 23, 2026 · 1 publisher
- Basic Auth becomes a gateway problem: AgentCore's Lambda interceptor keeps the password away from the model
Build · August 18, 2026 · 1 publisher
- The agent asks, the gateway decides: why read-only is not a security boundary
Build · August 17, 2026 · 1 publisher
- trelix's most useful release detail is an exit code, not the audit log
Build · August 15, 2026 · 1 publisher
- Cloudflare makes internal Workers private by default, conceding developer discipline never held
Build · August 14, 2026 · 1 publisher