Identity & Access

Fake X Login Alerts Are Being Used to Steal Your Password
Criminals are sending convincing 'new device login' emails to X users, hoping to harvest account credentials for follow-on fraud including crypto scams and phishing attacks.

Microsoft sees spike in ACR Stealer attacks lifting passwords and session tokens from browsers
The info-stealer is arriving through fake 'fix this error' prompts and hidden inside JPEG images, and it walks off with the browser cookies that keep users signed in.

On-Device Age Checks: The Quiet Fix to a Loud Privacy Problem
New age verification laws are forcing websites to check how old you are. A newer approach keeps your face on your phone instead of shipping it to a server.

n8n Login Bug Let a Valid Token From One Provider Log You In as Someone Else
The workflow automation platform matched users on a single ID field and ignored who issued the token. On Enterprise setups with more than one login provider, that was enough to walk in as another person.

Oak Raises $60 Million to Replace Fragmented Identity Security Tools With a Single Platform
A new Israeli-American startup wants to give companies one place to see and control every username, AI agent, and automated system that can touch their data.

Microsoft Is Killing SMS Login for Millions of Business Accounts. Here Is What Replaces It.
Starting September 2026, Microsoft will push passkeys as the default way to prove your identity in its business login system. By February 2027, the old text-message codes go dark entirely.

Fake LastPass and Bitwarden emails send users to bogus DocuSign pages
Criminals are impersonating two of the biggest password managers with polished 'policy update' emails that push a malicious file download.

Hackers Are Faking OAuth App IDs to Quietly Test Stolen Microsoft Logins
A new trick lets attackers check stolen Microsoft Entra ID passwords without triggering a single sign-in alert.

Microsoft is killing SMS logins for business accounts. Passkeys take over in September 2026.
Entra ID, the sign-in system used by millions of companies, will switch to passkeys by default. Text-message codes get shut off in February 2027.

Forg365 Sells Ready-Made Microsoft 365 Hijacking Kits on Telegram for $400 a Month
A new phishing service hands criminals automated tools to break into Microsoft 365 accounts and stay there, even after a victim changes their password.

Poisoned Developer Tool Downloaded Nearly 1,500 Times Before Anyone Noticed
Criminals hijacked the publishing credentials for a widely used JavaScript security package and slipped malware into four releases over a single weekend. Developers who installed any of those versions may have handed over passwords, crypto-wallet keys, and cloud access tokens without knowing it.

How ShinyHunters walked into Salesforce accounts without breaking anything
Microsoft says a year of data theft from Salesforce tenants leaned on trusted app connections, not a platform bug.

The Week Trusted Software Turned Hostile: ShareFile, Citrix Bleed 2, and AI Coding Attacks
Automated bug-hunting is cutting both ways, and old flaws are still landing hits because patches sat in a queue.

Varonis Launches Free Entra ID Training Game to Teach Cloud Identity Attacks
Breach at the Beach is a browser-based challenge that walks defenders through the kind of Microsoft Entra ID attacks Varonis researchers say they see in real customer environments.

Forg365: A $400-a-Month Kit That Hijacks Microsoft 365 Logins
A new subscription phishing service uses device codes, session theft and AI-written lures to break into corporate email accounts.