
SANS Stormcast Tuesday, April 7th, 2026: Redirects in Phishing; Internet Bug Bounty Suspended; Bluehammer; Keycloak MFA Bypass
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
00:00
Keycloak MFA bypass (CVE‑2026‑3429)
Johannes summarizes the Keycloak REST API flaw allowing removal of a second factor to bypass MFA; patch recommended.
Play episode from 05:35
Transcript


