Lorna Singh

Identity, IAM & authentication

Lorna covers SSO, passkeys, OAuth flaws, session hijacking, and the slow death of the password. Background in IAM architecture at two FAANGs.

Recent stories

Gamaredon's 2025 Phishing Surge: 35 Campaigns, Fresh Loaders, and Identity Tradecraft
Threat Intelligence
Gamaredon's 2025 Phishing Surge: 35 Campaigns, Fresh Loaders, and Identity Tradecraft
The Russia-aligned group has spent the year refining spear-phishing lures against Ukrainian targets, leaning harder on cloud services and credential theft.
Jun 29
DirtyClone: New Linux Kernel Flaw Hands Unprivileged Users the Root Keys
Vulnerabilities
DirtyClone: New Linux Kernel Flaw Hands Unprivileged Users the Root Keys
A page-cache manipulation bug related to DirtyFrag lets local, unprivileged attackers escalate to root — no credentials required beyond a shell.
Jun 29
GDPR Turns Ten: A Decade of Fines, Frustration, and Unfinished Business
Policy & Regulation
GDPR Turns Ten: A Decade of Fines, Frustration, and Unfinished Business
Six billion euros in penalties later, Europe's data regulation has reshaped corporate behavior — and created a compliance burden that companies say is quietly strangling AI development on the continent.
Jun 26
Law Enforcement and Microsoft Tear Down Command Infrastructure Behind Amadey and StealC
Threat Intelligence
Law Enforcement and Microsoft Tear Down Command Infrastructure Behind Amadey and StealC
Hundreds of C2 servers went dark in a coordinated takedown targeting the shared hosting backbone used by two prolific infostealer families.
Jun 24
AI-SPM Is Now a Real Category. Here's Why Your Organization Probably Needs It.
AI Security
AI-SPM Is Now a Real Category. Here's Why Your Organization Probably Needs It.
More than half of enterprise AI agents run without security oversight or logging. A maturing class of AI security posture management tools exists to fix that — if you know what to look for.
Jun 24
FFmpeg Vulnerability 'PixelSmash' Threatens Media Applications
Vulnerabilities
FFmpeg Vulnerability 'PixelSmash' Threatens Media Applications
A critical flaw in FFmpeg's MagicYUV decoder reveals the fragility of software supply chains.
Jun 24
Two Scattered Spider Members Plead Guilty as London Trial Opens
Identity & Access
Two Scattered Spider Members Plead Guilty as London Trial Opens
Thalha Jubair and Owen Flowers admitted roles in the TfL intrusion and a sprawling SIM-swap and SMS-phishing operation that turned harvested SSO credentials into nine-figure ransom payouts.
Jun 23
White House Sets Hard Clock on Post-Quantum Migration for Federal Systems
Policy & Regulation
White House Sets Hard Clock on Post-Quantum Migration for Federal Systems
An executive order mandates that high-value federal assets shift to post-quantum cryptography by 2030–2031. For identity infrastructure, that deadline is closer than it looks.
Jun 23
From Prevention to Resilience: Cybersecurity’s New Paradigm
Opinion
From Prevention to Resilience: Cybersecurity’s New Paradigm
As breaches become inevitable, organizations must focus on operational resilience, not just perimeter defense.
Jun 23
ShapedPlugin's Update Channel Hijacked, Pro Plugins Shipped with Backdoor
Threat Intelligence
ShapedPlugin's Update Channel Hijacked, Pro Plugins Shipped with Backdoor
Attackers slipped malicious code into licensed Pro releases by compromising the vendor's own build pipeline — a clean supply-chain hit on WordPress installs.
Jun 22
usbliter8 Burns a Permanent Hole in A12 and A13 SecureROM
Vulnerabilities
usbliter8 Burns a Permanent Hole in A12 and A13 SecureROM
Paradigm Shift's tethered exploit reaches code burned into the silicon, putting a years-long tail on iPhone XS through SE2 boot-chain trust.
Jun 19
Briefing: Apple Fixes Beats Bug, GCP Config Connector Flaw Enables Account Takeover, Velvet Ant's Decade in the Shadows
Vulnerabilities
Briefing: Apple Fixes Beats Bug, GCP Config Connector Flaw Enables Account Takeover, Velvet Ant's Decade in the Shadows
A Bluetooth eavesdropping patch, a quietly dangerous GCP misconfiguration vulnerability, and a threat actor that spent ten years undetected — here's what you may have missed.
Jun 19
AutoJack Exploit in Web-Enabled AI Agents: Bypassing Localhost Security
AI Security
AutoJack Exploit in Web-Enabled AI Agents: Bypassing Localhost Security
Microsoft uncovers RCE vulnerability in AutoGen Studio through local AI agent misuse.
Jun 19
Shadow AI Is an IAM Problem Now, Not a DLP Problem
Identity & Access
Shadow AI Is an IAM Problem Now, Not a DLP Problem
The risk isn't what employees paste into ChatGPT. It's what tokens, scopes, and service accounts the AI agents they spin up are quietly holding.
Jun 19
Cisco Acquires WideField Security to Wire Identity Intelligence Into Splunk's Agentic SOC
Identity & Access
Cisco Acquires WideField Security to Wire Identity Intelligence Into Splunk's Agentic SOC
The deal adds credential, session, and blast-radius visibility to Splunk's autonomous detection pipeline — filling a gap that pure log-correlation has always struggled with.
Jun 19
© 2026 Threat Vectr