Identity & Access — Page 3

AI Agents Need Passports, Not Passwords
As companies hand more decisions to autonomous AI agents, the old rules about who gets access to what are breaking down. Here is what needs to change, and why it matters to everyone.

WhatsApp Is Letting You Ditch Your Phone Number — Here's What That Means for Your Privacy
The world's most-used messaging app is adding usernames, so strangers no longer need your phone number to reach you. It's a meaningful privacy upgrade, but it comes with a scramble.

81 Million Login Attempts: A Massive Password Spray Attack Hit Microsoft 365 Users
Criminals hammered Microsoft accounts with automated login attempts for two weeks. At least 78 accounts were broken into — and many victims had multi-factor authentication switched on, just not set up correctly.

New Phishing Kit 'ARToken' Exposes Full Microsoft 365 Takeover Playbook
Cisco Talos researchers found more than 80 hidden commands inside a phishing service tied to the EvilTokens platform — including tools to steal Microsoft 365 logins, read mailboxes, and quietly hide their tracks.

Cisco Spends Around $400 Million to Plug a Growing Security Blind Spot: AI Agents
Two rapid-fire acquisitions — Astrix Security and WideField Security — are Cisco's answer to a question most companies haven't thought to ask: who's watching the bots?

0ktapus Phishing Campaign Hits 130 Companies, Compromising Nearly 10,000 Accounts
A widespread phishing attack targets employees of Twilio and Cloudflare, exploiting Okta's authentication system.

Drag, Drop, Hijacked: How 'ConsentFix' Steals Microsoft 365 Sessions in Seconds
A new twist on the ClickFix trick turns Microsoft's own sign-in prompts into a session-theft machine — and a step-by-step guide is now circulating on a Russian crime forum.

Nelnet Data Breach Exposes 2.5 Million Student Loan Records
A vulnerability in Nelnet's loan servicing system exposed personal data. Here's what that means for borrowers.

Identity Security as a Career On-Ramp: What One CISO Actually Thinks
Silverfort's John Paul Cunningham argues AI is opening doors in cybersecurity rather than closing them — and identity is where new practitioners should focus first.

IGA Was Built for Employees. Agents Break the Model.
Identity governance assumes a hire date, a manager, and an exit interview. Autonomous AI agents have none of those — and legacy IGA tools can't see the gap.

WhatsApp Starts Username Reservations, Finally Decoupling Identity From Phone Numbers
The optional handle system lets users be reachable without exposing an E.164 number — a meaningful identifier change for a 3-billion-user directory.

BEC Keeps Winning Because It Looks Exactly Like Normal Work
The phishing payload is gone. The pretext is the payload now, and your SEG was never built for that.

Robinhood Rebuilt Its Access-Approval Pipeline — Here's What Actually Changed
The fintech firm's engineering-security team overhauled how developers request and receive system access. The goal: speed without sacrificing control.

Guardian Agents and the Identity Layer That Doesn't Exist Yet
Autonomous agents are inheriting human permissions at machine speed. The IAM stack wasn't built for this, and the governance gap is widening.

Philip Martin Takes the CISO Chair at Uber
The former Coinbase security chief steps into one of tech's more scrutinised security roles, bringing a résumé that spans crypto, defence contracting, and cloud infrastructure.