SANS Stormcast Friday, August 21st, 2026: Microsoft Graph and Powershell; Keycloak Vuln; Cryptographic Context Injection; N-Able Password Leak
Aug 21, 2026 · 7m
Summary
This episode covers two PowerShell scripts for Microsoft Graph to track stale accounts and Entra risk detections. It highlights a critical Keycloak vulnerability allowing unauthenticated password resets via token spoofing. The host discusses cryptographic context injection to bypass LLM safeguards and a Passportal flaw enabling cross-origin password theft. Listeners are urged to update Keycloak and review security practices.
Topics discussed
Introduction and SANS ICS Security Sponsor
PowerShell Automation for Microsoft Graph and Entra
Keycloak Password Reset Vulnerability Fix
Cryptographic Context Injection in LLMs
Enable Passportal Cross-Origin Messaging Flaw
Class Promotion and Closing Remarks
Listen ad-free on Castria