#authentication
22 stories taggedauthentication.

GitLab's Per-User Issue Email Is a Password in Disguise
The private address you use to file issues by email can also push code and start pipelines as you. Treat it like a credential, because it is one.

The Most Common Password Is Still 123456. Here Is What Actually Fixes That.
A former CISO at Hyatt and United Airlines says the security industry keeps chasing new tools while ignoring the basics. One basic above all others stands out: multi-factor authentication, which cuts your chance of being hacked by 99 percent.

Passkeys Aren't Magic: Researchers Map 39 Ways to Sidestep Them
A new catalogue from Token shows attackers don't need to break the cryptography behind passkeys to steal accounts. They just walk around it.

Microsoft Exchange Online buckles: email delays, sign-in errors hit tens of thousands
Microsoft says it has spotted a shared authentication fault behind a widespread Exchange Online outage causing missing emails and login failures.

Why 'Identity Fabric' Is the Phrase Every Security Team Will Hear in 2026
As passwords fade and machine accounts outnumber humans, a new architecture promises to watch every login, token and API call in one place. What it actually means.

Snowflake kills passwords for service accounts. The cleanup starts now.
The cloud data giant is retiring password logins for machine accounts. Working out what those accounts actually do is the real headache.

Passing the Login Test Does Not Mean You Let In the Right Person
Multi-factor authentication is a genuine security win, but organisations that mistake 'logged in successfully' for 'identity confirmed' are handing attackers a very comfortable seat at the table.

Claude Goes Dark: Anthropic Confirms Major Outage Across Login and Core Services
Anthropic's status page flagged authentication failures and degraded performance starting 21:58 UTC on 16 August 2026, hitting Claude.ai, Claude Code and Claude Cowork.

Passkeys Aren't Bulletproof: Three New Attacks Sidestep the 'Phishing-Proof' Login
Researchers show how signed login material, malware on synced devices, and clever redirection can defeat passkeys without cracking a single key.

The Four Ways Criminals Beat Multi-Factor Authentication (And What You Can Do About It)
Multi-factor authentication was supposed to be the lock that hackers couldn't pick. It turns out there are at least four reliable routes through it, and most organisations are leaving at least one wide open.

Changing Your Password No Longer Kicks Hackers Out
A growing wave of attacks steals not passwords but the digital passes that keep you logged in, meaning a password reset leaves the intruder sitting comfortably inside your account.

Microsoft's New Passkey System Has Flaws That Let Old Hacking Tricks Work Again
A security researcher found three near-exploitable bugs in Windows 11 and Microsoft's cloud login service, just as the company prepares to make passkeys the default sign-in method for hundreds of millions of users.

Google rolls out selfie video sign-in for locked-out account holders
The new recovery option sits alongside email and phone number checks, and is aimed at people who cannot get back into their Google account any other way.

What is a VPN and when do you actually need one?
VPNs encrypt your internet traffic and hide your real IP address, but they are not a privacy cure-all. Here is when one genuinely helps and when it does not.

What is zero trust? A plain-English guide
Zero trust means your network stops assuming anyone inside it is safe, and checks every user and device every single time.