SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
Three items, one tier: Keycloak's reset bug, an N-able password leak, a Grok data-theft trick
A single Stormcast episode carries a Keycloak 26.7.2 password-reset fix, a reported N-able password manager leak, and a published LLM safeguard bypass. Most of it sits in the identity and secrets tier.
The Watch · Security desk

What happened
- One of them closes a password reset bug that allowed an unauthenticated user to reset any user's password.
- The verification token mailed to the account holder was not properly validated, so it could be spoofed by an attacker who never saw the email.
- It also linked an adversa.ai post by Ronnie Utevsky on cryptographic context injection, presented as data theft against Grok.
Why it matters
- exposure Operators who never chose Keycloak still own its reset bug, because it arrives inside another vendor's product and rarely appears in their own inventory.
- decision There is no compensating control to buy time with here: stronger passwords and mailbox hygiene do not touch this path, so the upgrade is the only lever in evidence.
- capability Identity inventory becomes a scripted query, and it cuts both ways: whoever holds Graph read scope gets the dormant accounts and the tenant's own risk verdicts in one pull.
- precedent A password manager sold as security tooling landing in the same day's column as an IAM patch pushes vendor-held secret stores toward default rotation scope after any vendor incident.
Every password reset flow is a second authentication path, usually with one factor holding it up. In Keycloak that factor was the emailed token, and with the token not properly validated the path would accept anonymous requests to change any user's password [2]. No other part of the stack was asked to agree.
Then there is distribution. Keycloak is rarely a purchase decision; it is the identity and access management layer sitting under other products and web applications, with Red Hat using it heavily and supporting its development [7]. Upstream exists as 26.7.2, with a number of security fixes in it [1], but an operator running Keycloak inside somebody else's appliance gets those fixes on the vendor's rebuild schedule [10].
Discovery was not systematic either. Johannes Ullrich credited a listener named Daniel for pointing the issue out, and said he would probably have missed it otherwise [8]. Release notes for embedded identity components are read by very few people, and that is the channel this one travelled down.
The other two items in the same episode are, in the material available, links with headlines attached. Ronnie Utevsky's post at adversa.ai describes what he calls cryptographic context injection, presented as a way around safeguards in large language models and framed in both the episode title and the link itself as data theft against Grok [3]. The transcript stops mid-sentence before the method is explained [13], so it is a pointer rather than a finding. The N-able entry is filed as a password manager leak and points at a post whose own URL calls it SolarWinds part two [4].
The Microsoft Graph diaries alongside them are hygiene work: two PowerShell scripts from Rob, one listing users with stale accounts and the licenses assigned to them, the other collecting Entra risk detections with the reason each was raised, including unusual browser user agents and origin by geography or ASN [5]. Stale accounts belong to the same tier as the Keycloak bug. A dormant account still has a reset flow wired to a mailbox nobody reads, and it still holds whatever roles it was handed.
Four topics in one episode, three of them about the machinery that holds credentials [12]. Token validation is the entire Keycloak fix, which is the least interesting class of finding and the one that reaches furthest.
What to watch
- Whether Keycloak assigns a CVE and severity to the reset flaw, and how quickly vendors embedding Keycloak rebuild on 26.7.2.
- Detail from N-able on the scope of the password manager exposure and whether stored customer credentials need rotation.
- Whether the cryptographic context injection method reproduces against assistants other than Grok, and any response from xAI.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence52
- Adoption
- Insufficient
- Hype gap+14
- Incentives34
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Keycloak released version 26.7.2, fixing a number of security vulnerabilities.
ReportedSupportedSource: SANS Internet Storm Center Stormcast, 21 August 20262 sources— create a free account to open themView cited source - [2]
One of the vulnerabilities fixed in Keycloak 26.7.2 is a password reset issue in which an unauthenticated user is able to reset any user's password.
ReportedSupportedSource: Johannes Ullrich, SANS ISC Stormcast2 sources— create a free account to open themView cited source - [3]
The episode links a blog post at adversa.ai by Ronnie Utevsky describing what he calls cryptographic context injection, a way to bypass safeguards in large language models; the episode title and the linked URL present it as Grok data theft.
ReportedSupportedSource: Ronnie Utevsky via adversa.ai, as summarised in the Stormcast2 sources— create a free account to open themView cited source - [4]
The N-able password manager item in the episode is a link to a post at amibeingpwned.com whose URL refers to solar-winds-part-2-avoided; the episode title describes it as an N-able password leak.
- [5]
Two ISC diaries by Rob present PowerShell scripts using Microsoft Graph: one collects users with stale accounts and lists licenses assigned to users, the other collects users flagged by Entra risk detections plus the reason, such as an unusual browser based on user agent, geographic origin, or ASN.
- [6]
Keycloak's password reset sends an email with a verification token that the user clicks to reset the password; the token was not properly validated, so an attacker can spoof it and reset the password without ever seeing the email.
- [7]
Keycloak is an identity and access management system, heavily used by Red Hat, which also supports its development, and it underpins identity and access management for many other products and web applications.
- [8]
Ullrich thanked a listener named Daniel for alerting him to the Keycloak issue and said he would probably have missed it otherwise.
- [9]
The 21 August 2026 SANS ISC Stormcast, hosted by Johannes Ullrich, covered Microsoft Graph and PowerShell, a Keycloak vulnerability, cryptographic context injection, and an N-able password leak.
- [10]
Because Keycloak ships inside other products, some operators receive 26.7.2's fixes only when a downstream vendor rebuilds its product, not when upstream tags the release.
- [11]
An attacker exploiting the Keycloak reset flaw needs no existing credential and no access to the victim's mailbox, so password strength and mailbox control do not constrain the path.
- [12]
Three of the episode's four topics concern identity or secrets systems: Entra data via Microsoft Graph, the Keycloak IAM flaw, and the N-able password manager leak.
- [13]
The supplied transcript ends mid-sentence while introducing the cryptographic context injection technique, so no mechanism detail for the Grok attack is present in the material.
Sources
1 independent publisher whose own reporting we read for this story.
- SANS Stormcast Friday, August 21st, 2026: Microsoft Graph and Powershell; Keycloak Vuln; Cryptographic Context Injection; N-Able Password Leak
isc.sans.edu
1 article · August 26, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.