Identity & Access — Page 5

The 2026 Cybersecurity Stars Awards Land — 95 Categories, One Long Trophy Table
An industry awards program names winners across product, team, and company categories. The interesting question is what — if anything — the list tells us about where defenders are actually winning.

Infostealers Are Now the Front Door for Ransomware Gangs
Credential theft at industrial scale has made exploit-based initial access look quaint. Here's why stolen session tokens are reshaping the attack chain.

When the Pentest Report Goes Quiet, Start Worrying
Stable findings aren't the same as a stable attack surface — and identity paths are usually what the scanners stop seeing first.

$7M Says Autonomous Agents Can Fix the Identity Sprawl Problem
Offroad exits stealth with a bet that AI-driven security agents can manage what platform teams stopped being able to track manually — machine identities, third-party app permissions, and the rest of the non-human identity mess.

Lookalike Open-Source Portals Are SEO-Climbing Their Way to Malware Delivery
A Traffic Distribution System fronts fake project sites to drop Remus Stealer, AnimateClipper, and the SessionGate framework. None of this is an auth problem — but the stolen sessions afterward absolutely are.

A Debug Flag Shipped to Prod Turned M365 Android Apps Into a Token Buffet
Any sideloaded app on the same phone could ask for the signed-in user's Microsoft token and get it. No prompt. No password. Just IPC.

One Click in VS Code Was Enough to Hand Over Your GitHub Token
Researcher Ammar Askar found a clickjack-style flaw in github.dev that leaked full-fat OAuth tokens — read/write, private repos included.

Identity Dark Matter: Why IAM Is Losing Sight of Its Own Users
Enterprise identity has fragmented across SaaS sprawl, machine accounts, and agentic systems — leaving a growing slice of activity that centralized IAM cannot see or govern.

Poisoned npm Package Stole OpenAI Codex Tokens — and the GitHub Repo Looked Fine
codexui-android published clean source code while shipping malicious artifact builds that harvested refresh tokens. The gap between repo and registry is where the attack lived.

MokN Banks $15M to Turn Phishing Infrastructure Against Attackers
The startup's decoy access-point platform tries to catch credential thieves in the act — before stolen logins get used.

Shadow Builders: When Employees Ship Production Apps Without Auth
Vibe-coded internal tools are graduating to public URLs, and most identity stacks never see them coming.

When 'Minor Foothold' Means Full Account Takeover: The Week IAM Bent the Wrong Way
A Claude security plugin, an Azure privilege-escalation chain, and a Kali365 MFA bypass all land in the same news cycle. Identity is still the soft underbelly.

The Perimeter Is Gone. Attackers Already Knew That.
Modern intrusions rarely crack the wall. They walk through the front door, wearing your credentials.

Kali365 Phishing Kit Hijacks Microsoft OAuth Tokens to Silently Bypass MFA
The FBI has flagged a device-code phishing campaign powered by Kali365, a toolkit that steals OAuth tokens tied to Microsoft 365 accounts without ever touching a user's password.

Kali365 and EvilTokens: The New Phishing-as-a-Service Threat
Professional phishing kits lower barriers for attackers, bypassing MFA with ease.