#IAM
36 stories taggedIAM.

Ransomware Group The Gentlemen Claims Attack on German Secure-File Firm FTAPI Software
A criminal gang that has posted dozens of claimed victims in recent months has listed FTAPI Software on its dark-web extortion site. The Munich company serves hospitals, insurers and public agencies across Europe. Nothing has been confirmed.

The Most Common Password Is Still 123456. Here Is What Actually Fixes That.
A former CISO at Hyatt and United Airlines says the security industry keeps chasing new tools while ignoring the basics. One basic above all others stands out: multi-factor authentication, which cuts your chance of being hacked by 99 percent.

The Secret Instructions Hiding Inside Your Company's AI Assistant
A security firm is warning that criminals can hide malicious commands inside ordinary documents, and AI agents will follow those commands without question.

AI Agents Are Breaking Cloud Security Faster Than Human Hackers Ever Could
Automated attackers can test thousands of ways into a company's cloud systems in minutes. Most security teams are still thinking at human speed.

Why 'Identity Fabric' Is the Phrase Every Security Team Will Hear in 2026
As passwords fade and machine accounts outnumber humans, a new architecture promises to watch every login, token and API call in one place. What it actually means.

Hired to Build, Judged on the Breach That Never Happened
The skills that land someone a CISO job are rarely the ones the board scores them on a year later. That gap is quietly ending careers.

Apollo Global Hit by Social Engineering Attack That Exposed Names and Social Security Numbers
A phone-based scam tricked Apollo Global Management's IT support staff into handing over access. Names, contact details, and Social Security numbers may have been stolen.

9,300 leaked AWS keys still work, and 768 hand over full control of a company's cloud
Truffle Security tracked exposed Amazon cloud keys for four years. Most were never rotated, and 88% still logged in on the day of testing.

IAM Compliance: What the Rules Actually Require, and How to Prove It
Regulators increasingly expect continuous evidence that identity controls work, not just paperwork saying they exist.

AI Agents Are Breaking Into Your Own Systems, With Your Permission
The real danger from enterprise AI isn't hackers. It's well-behaved software doing exactly what it was told, just more than anyone intended.

Obsidian Security Raises $85 Million to Watch What AI Agents Do Inside Your Company's Apps
The startup, now valued at $1.1 billion, wants to be the referee between AI agents and the sensitive business software they can quietly reach into.

DataBahn Raises $40 Million to Put AI in Charge of Enterprise Data Pipelines
The Texas startup wants companies to stop moving every byte of data everywhere and start routing only what actually matters, in real time.

AI agents are approving transactions and nobody is watching
A new report finds most companies have handed financial controls to AI systems they cannot audit, trace, or investigate in real time.

AI agents with too many keys: why permissions are the new identity problem
As companies rush to deploy AI assistants that act on their behalf, security researchers warn the real danger is not the AI itself but the sweeping access rights it inherits.

Two Cloud Giants, Two Flaws, Zero Bug Bounties: The 'Confused Deputy' Problem That Won't Go Away
A security researcher found ways to silently hijack administrator control over both Microsoft Azure and Google Cloud infrastructure. Neither company paid a reward. One quietly fixed its flaw without saying so.