Identity & Access — Page 5

Identity & Access

The 2026 Cybersecurity Stars Awards Land — 95 Categories, One Long Trophy Table

An industry awards program names winners across product, team, and company categories. The interesting question is what — if anything — the list tells us about where defenders are actually winning.

3 min read
Identity & Access

Infostealers Are Now the Front Door for Ransomware Gangs

Credential theft at industrial scale has made exploit-based initial access look quaint. Here's why stolen session tokens are reshaping the attack chain.

2 min read
Identity & Access

When the Pentest Report Goes Quiet, Start Worrying

Stable findings aren't the same as a stable attack surface — and identity paths are usually what the scanners stop seeing first.

3 min read
Identity & Access

$7M Says Autonomous Agents Can Fix the Identity Sprawl Problem

Offroad exits stealth with a bet that AI-driven security agents can manage what platform teams stopped being able to track manually — machine identities, third-party app permissions, and the rest of the non-human identity mess.

2 min read
Identity & Access

Lookalike Open-Source Portals Are SEO-Climbing Their Way to Malware Delivery

A Traffic Distribution System fronts fake project sites to drop Remus Stealer, AnimateClipper, and the SessionGate framework. None of this is an auth problem — but the stolen sessions afterward absolutely are.

2 min read
Identity & Access

A Debug Flag Shipped to Prod Turned M365 Android Apps Into a Token Buffet

Any sideloaded app on the same phone could ask for the signed-in user's Microsoft token and get it. No prompt. No password. Just IPC.

3 min read
Identity & Access

One Click in VS Code Was Enough to Hand Over Your GitHub Token

Researcher Ammar Askar found a clickjack-style flaw in github.dev that leaked full-fat OAuth tokens — read/write, private repos included.

3 min read
Identity & Access

Identity Dark Matter: Why IAM Is Losing Sight of Its Own Users

Enterprise identity has fragmented across SaaS sprawl, machine accounts, and agentic systems — leaving a growing slice of activity that centralized IAM cannot see or govern.

3 min read
Identity & Access

Poisoned npm Package Stole OpenAI Codex Tokens — and the GitHub Repo Looked Fine

codexui-android published clean source code while shipping malicious artifact builds that harvested refresh tokens. The gap between repo and registry is where the attack lived.

2 min read
Identity & Access

MokN Banks $15M to Turn Phishing Infrastructure Against Attackers

The startup's decoy access-point platform tries to catch credential thieves in the act — before stolen logins get used.

2 min read
Identity & Access

Shadow Builders: When Employees Ship Production Apps Without Auth

Vibe-coded internal tools are graduating to public URLs, and most identity stacks never see them coming.

3 min read
Identity & Access

When 'Minor Foothold' Means Full Account Takeover: The Week IAM Bent the Wrong Way

A Claude security plugin, an Azure privilege-escalation chain, and a Kali365 MFA bypass all land in the same news cycle. Identity is still the soft underbelly.

2 min read
Identity & Access

The Perimeter Is Gone. Attackers Already Knew That.

Modern intrusions rarely crack the wall. They walk through the front door, wearing your credentials.

3 min read
Identity & Access

Kali365 Phishing Kit Hijacks Microsoft OAuth Tokens to Silently Bypass MFA

The FBI has flagged a device-code phishing campaign powered by Kali365, a toolkit that steals OAuth tokens tied to Microsoft 365 accounts without ever touching a user's password.

3 min read
Identity & Access

Kali365 and EvilTokens: The New Phishing-as-a-Service Threat

Professional phishing kits lower barriers for attackers, bypassing MFA with ease.

2 min read
© 2026 Threat Vectr