Identity & Access — Page 4

Identity & Access

Account Takeovers Still Outrunning Detection, Vendors Push Behavioral AI as Answer

Compromised credentials remain the cheapest entry point on criminal marketplaces. A new webinar argues behavioral models, not static rules, are the only way to close the gap.

2 min read
Identity & Access

The Service Desk Is the New Phishing Inbox

Help desks keep getting talked out of MFA resets. The fix is less about training and more about treating identity verification like an auth protocol.

3 min read
Identity & Access

Third DraftKings Credential-Stuffing Conspirator Sentenced to 18 Months

Nathan Austad gets a year and a half in federal prison, plus $1.8 million in forfeiture and restitution, closing out the last of the DraftKings account-takeover prosecutions.

2 min read
Identity & Access

Two Scattered Spider Members Plead Guilty as London Trial Opens

Thalha Jubair and Owen Flowers admitted roles in the TfL intrusion and a sprawling SIM-swap and SMS-phishing operation that turned harvested SSO credentials into nine-figure ransom payouts.

3 min read
Identity & Access

Device Code Phishing Is Eating MFA. Behavioral Detection Is the Backstop.

Token theft and consent-grant abuse sidestep the second factor entirely. Defenders are leaning on anomaly detection because the login looks legitimate.

3 min read
Identity & Access

Shadow AI Is an IAM Problem Now, Not a DLP Problem

The risk isn't what employees paste into ChatGPT. It's what tokens, scopes, and service accounts the AI agents they spin up are quietly holding.

3 min read
Identity & Access

Cisco Acquires WideField Security to Wire Identity Intelligence Into Splunk's Agentic SOC

The deal adds credential, session, and blast-radius visibility to Splunk's autonomous detection pipeline — filling a gap that pure log-correlation has always struggled with.

2 min read
Identity & Access

SailPoint to Buy Entro Security for a Reported $200 Million

The acquisition adds non-human identity and secrets management to SailPoint's governance platform — a gap that's become increasingly hard to ignore.

2 min read
Identity & Access

MFA Alone Won't Save You: What Modern Attackers Know That Defenders Don't

A practitioner-focused webinar examines how threat actors sidestep conventional detection controls and why single-layer authentication assumptions are failing organizations.

2 min read
Identity & Access

UK's Under-16 Social Media Ban Turns Every Signup Into an Identity Checkpoint

Spring 2027 rules will force ID uploads or face scans at account creation. The IAM bill comes due — and so does the breach surface.

3 min read
Identity & Access

Zero Trust Turns 15 and Still Can't Get Out of Its Own Way

The 'never trust, always verify' model isn't failing because the idea is wrong. It's failing because organizations keep treating a security philosophy like a SKU.

3 min read
Identity & Access

Behavioral AI Pitched as Triage Layer for Phishing and ATO Floods

A vendor webinar argues that pattern-learning models can cut investigation time on BEC and account takeover incidents. The harder question: what does that mean for breach-notification timelines?

3 min read
Identity & Access

First-Day Passwords Are Still IAM's Soft Underbelly

Temporary onboarding credentials keep showing up in breach forensics. The problem isn't laziness — it's that most IT teams never actually defined what 'temporary' means.

2 min read
Identity & Access

Sovereign Cloud Gives You a Data Center. Identity Governance Gives You Control.

European enterprises spent two years and real money on sovereign cloud deployments. What they found is that data residency is the easy part — and that AI agent identities are the part nobody governed.

3 min read
Identity & Access

The Week Identity Attacks Started Looking Like SaaS

Worm kits in public repos, a subscription RAT that clones live browser sessions, and AI agents that hand over credentials when asked nicely.

3 min read
© 2026 Threat Vectr