
Spring Security
21
MENTIONS
5
EPISODES
4
PODCASTS
Search complete. 21 mentions across 5 episodes found for "Spring Security".
Sep 10, 2026
Netflix’s Paul Bakker
J
0:24Josh LongHOST
I'm doing a two-part talk.
J
0:26Josh LongHOST
It's two talks stitched together, one right after the other, with the legendary, inimitable, amazing, and also influential Rob Winch, lead of Spring Security.
J
0:35Josh LongHOST
And it's going to be a spring security palooza.
J
0:36Josh LongHOST
It's going to be amazing.
J
0:37Josh LongHOST
So I'm hoping, up against all hope, that it's going to be recorded.
S5E21 - Pro Spring Boot 4 with Felipe Gutierrez
F
41:24Felipe GutierrezGUEST
Thanks to the security, now I can do like a two-factor authentication, right? So easy that it's a feature that...
F
41:35Felipe GutierrezGUEST
I think it was already also due right from previous versions of the Spring Security.
F
41:40Felipe GutierrezGUEST
We needed to have that.
F
41:42Felipe GutierrezGUEST
There was some implementations, of course, but now using this is so simple.
Joe Grandja on Spring Authorization Server, OAuth, and so much more
J
3:11Josh LongHOST
I built a, a CLI with Spring Shell and device code flow and, uh, the Spring Auth Server.
J
3:16Josh LongHOST
I built a web service and a React app, and I secured all that, uh, with the, uh, with the u- you know, Spring Security OAuth support and of course the Spring Auth Server.
J
3:26Josh LongHOST
So really just about every use case, every place I can imagine.
J
3:28Josh LongHOST
Messaging, gRPC, Kafka, integration, um, you know, um, web apps, uh, you know, everything.
J
3:49Josh LongHOST
The Spring Auth Server is a incredibly capable OAuth IDP.
J
3:54Josh LongHOST
And so imagine my delirium, my joy at, uh, the discovery that I could get today's guest, my friend Joe Grandia.
J
4:02Josh LongHOST
He is the lead of the Spring Auth Server, which is itself part of the Spring Security project.
J
4:08Josh LongHOST
So it's, um, you know, it...
Alabama Attorney General Subpoenas OpenAI as 15 States Investigate Rogue AI Hack of Hugging Face, CISA Orders Urgent Patching of Actively Exploited Zimbra Flaw, Critical Keycloak Password Reset Vulnerability
J
7:15James AzarHOST
26.4.15-1. and red hat bk 26.6 operator bundle 26.6.6-1 upgrade immediately if you can't patch today there's a real stop gap here in the admin council so go to realm settings login and disable forgot password across all your realms until you can patch this one up key cloak sits in front of everything else in your environment so an identity provider is exactly the system you don't want to discover was vulnerable after the fact so treat it as such all right The third up is a less single bug and more of a stack of them.
J
7:53James AzarHOST
Spring's latest security update is patching 91 vulnerabilities across Spring Security, Spring AI, Cloud Config, DataRest, Integration, Reactor, Core Reactor, Netty, AAMQP, and Patch.
J
8:09James AzarHOST
Patch would it be? Sorry, not a P.
J
8:13James AzarHOST
uh all right one is rated critical over a dozen more are high severity and together these components sit inside more than 200 000 pieces of downstream software so if your organization runs java there's a good chance spring is already in your stack whether your team put it there directly or not the critical cve of the bunch is 2026.59 or 270 it hits springs security embedded unbound id ldap server and could let an attacker authenticate and even modify entries in that in-memory directory also worth flagging even though it's not in the top rated cve And this specific batch is CVE-2026-59-285, which is a critical remote code execution flaw in Spring for GraphQL and CVE-2026-59-318, a medium severity prompt injection privilege escalation in Spring's AI tool calling functionality, a preview of the bug class we're going to see a lot more of as AI tooling gets wired into application frameworks.
J
9:16James AzarHOST
Spring has a real exploitation track record Spring for Shell wasn't that long ago, and CISA's catalog already lists several spring CVEs from prior year.
J
9:27James AzarHOST
Worth noting, by the way, this vendor patched over 200 spring vulnerabilities in 2026 alone, compared to just 16 in 2025, largely from AI-assisted vulnerability hunting, on their end so expect the space to continue inventory where spring lives in your stack and prioritize patching today especially anywhere spring security or spring for graphql is exposed there as well Alright, we'll get to our fourth story, which is a breach at a security vendor, and security vendors are not exempt from it.
J
10:05James AzarHOST
They're always a target, but it's worth walking through this one because the defense actually worked.
J
10:11James AzarHOST
ReliaQuest, if you were at Hacker Summer Camp, you may have seen that name everywhere.
Cyber Security News for August 21 2026 - Daily DefSec Brief
J
1:20Jerry BellHOST
5.
J
1:20Jerry BellHOST
Spring Security's embedded unbound ID LDAP server has a critical flaw that can hand a remote attacker admin access to an exposed in-memory directory.
J
1:30Jerry BellHOST
Check the advisory for the fixed version, and since that in-memory LDAP is meant for testing, make sure it isn't reachable in production.
J
1:37Jerry BellHOST
6.