
Identity & accessEXPLAINER · 3 MIN READ
Two curl bugs in Apple’s updates: redirects, proxies and credential mix-ups
The curl advisories describe a bearer token following the wrong destination and a proxy connection reused with the wrong identity. Each is a credential-state failure rather than memory corruption.
Sep 9, 2026 ↗

Identity & accessEXPLAINER · 3 MIN READ
macOS Accounts CVE-2026-43749: how path handling can lead to root
Apple fixed a directory-path parsing issue in the Accounts component. The advisory reports potential root privileges for an app, while leaving the precise path-handling failure unpublished.
Sep 9, 2026 ↗

Identity & accessEXPLAINER · 3 MIN READ
SharePoint CVE-2026-69465: when a signed-in user has too much access
Microsoft’s missing-authorization fix needs more than a package install. Review the affected SharePoint edition, Workflow Manager prerequisite and upgrade status across the farm.
Sep 9, 2026 ↗

Identity & accessEXPLAINER · 5 MIN READ
Apple’s Screen Sharing fix: CVE-2026-65400 and unauthenticated access
Apple repaired an authentication-state flaw in macOS Screen Sharing. Check the affected release branch, who can reach the service and whether older access needs investigation.
Sep 9, 2026 ↗

Identity & accessEXPLAINER · 5 MIN READ
Authenticator codes or passkeys: what changes when you sign in?
Both can improve on a password alone, but they protect against different attacks. Understand TOTP secrets, WebAuthn origin checks, recovery and the sessions left open after login.
Sep 8, 2026 ↗

Identity & accessGUIDE · 5 MIN READ
Who can actually control your business accounts?
Account ownership goes beyond the person who signs in. Check who can change permissions, keep an integration running, revoke sessions and recover access when someone leaves.
Sep 8, 2026 ↗