#identity
75 stories taggedidentity.

OAuth Tokens Are Quietly Becoming the Skeleton Key to Google Workspace
Phishing gets the headlines, but stolen app tokens can open Gmail and Drive without ever tripping a login alert.

737 Fake VPN Extensions in Chrome Store Quietly Hijacked Browsers
The free browser add-ons promised to unblock websites for Russian speakers. Instead they routed every page a user visited through servers the operators controlled.

The fake new hire problem: how criminals slip in through remote onboarding
Gaps between background checks, laptop delivery and account setup are letting impostors join companies as staff. Here's how the trick works, and what stops it.

Passwords Are Getting Easier to Fake. Device Trust Is the Fix Companies Are Reaching For.
As AI turbo-charges phishing and credential theft, the old signals that told a company 'this login is fine' are quietly failing. Here's what's replacing them.

Two Million Belgians Exposed by Flaws in the Software They Use to Sign Legal Documents Online
Security researcher James Arnott found that Belgium's most-used digital identity tool could let any malicious website steal a user's PIN, forge their electronic signature, or quietly run attack code on their computer, all without the victim clicking anything suspicious.

One Developer Password Unlocked Everything: Inside a Healthcare Software Provider's Wake-Up Call
A company that thought its segmented cloud setup was secure ran a simulated attack and watched a single stolen developer credential unravel four years of layered defences in minutes.

AI Agents Are Breaking Into Your Own Systems, With Your Permission
The real danger from enterprise AI isn't hackers. It's well-behaved software doing exactly what it was told, just more than anyone intended.

Kali365 Phishing Kit Turns Microsoft's Own Login Page Against US Firms
A new criminal toolkit tricks staff into approving attacker device codes on genuine Microsoft screens, handing over long-lived access to email and cloud files.

Varonis pitches 'intent-based' guardrails for AI agents that stray off task
Agent IBAC watches what an AI agent is trying to do, not just what it is allowed to touch, and pulls the brakes when the two drift apart.

Malware Can Silently Hijack Chrome Passkeys, Researchers Show
Palo Alto's Unit 42 details three attack paths against Google Password Manager that let ordinary user-level malware sign in without a fingerprint, PIN, or on-screen prompt.

Device Code Phishing: The Login Trick That Blew Up in 2026
A login flow built for smart TVs is now one of the fastest-growing routes into corporate accounts, and identity teams are struggling to keep up.

The Network Is Quietly Becoming the Referee for AI Traffic
As AI tools multiply inside companies, firewalls are being asked to do a job they were never designed for: policing conversations between machines that think.

AI agents with too many keys: why permissions are the new identity problem
As companies rush to deploy AI assistants that act on their behalf, security researchers warn the real danger is not the AI itself but the sweeping access rights it inherits.

The US Government Just Changed How Agencies Must Fix Security Flaws. It Is Not Enough.
A new federal directive finally ties patch deadlines to real-world risk. Then AI rewrote the problem.

Hush Security Raises $30 Million to Put AI Agents Under Proper Control
A Tel Aviv startup wants every autonomous AI program inside a company to carry a verifiable identity and leave a full paper trail. Investors just backed that idea to the tune of $30 million.