Urgent.News

What's breaking now, across thousands of outlets.

Tech

40,059 Keycloak Servers: Where the Identity Provider Is the Asset

40,059 Keycloak Servers: Where the Identity Provider Is the Asset An identity provider is the component that decides who a user is for every application connected to it. When that component is reachable from an untrusted network, the exposure is not about data leakage alone. It is about the trust anchor for authentication across an estate. What the server presents Keycloak provides…

Keycloak, an identity provider, manages authentication and single sign-on across various connected applications. When this critical component is accessible via an untrusted network, the risk extends beyond data exposure to encompass the trust anchor for authentication within an entire IT ecosystem. Keycloak offers authentication, single sign-on, and identity brokering, with administrative controls centralized in its console.

An exposed Keycloak server presents three primary risks: an unsecured administrative console, an administrative console with default or weak credentials, and a realm configuration that allows self-registration or broad default roles for new users. These factors collectively grant unauthorized access to client secrets and the ability to create accounts within connected applications.

Operational best practices involve securing the administrative console, employing unique per-environment credentials, reviewing realm settings against intended behavior, ensuring proper client configuration, and monitoring the provider's visibility in external attack surface monitoring tools. Despite the extensive footprint of 40,059 affected services, this figure represents a significant yet manageable risk that can be mitigated through focused configuration reviews and operational checks.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Week2 Challenge(Touch_grass)

What I Built Touch Grass is a desktop wellness and focus companion designed to help people step away from their screens and spend more time in the real world.

Defining SLOs and SLIs for Microservices

How to translate business outcomes into measurable SLIs Choosing SLIs that survive production reality Practical SLO targets, error budgets, and burn-rate policies SLO-driven monitoring, alerts, and…

More from Saturday 10 October →