Tag

#identity

91 stories taggedidentity.

Full-frame edge-to-edge overhead photoreal shot of a modern office desk at dusk, a smartphone displaying a generic passkey biometric prompt glow next to a small
Identity & Access

Microsoft is switching off text-message logins for work accounts in February 2027

Entra ID admins have 15 months to move staff onto passkeys or hardware keys before SMS sign-in stops working.

3 min read
Full-frame edge-to-edge photoreal overhead shot of a developer workstation at dusk, a mechanical keyboard and an open laptop showing an abstract green-on-dark t
Identity & Access

GitLab's Per-User Issue Email Is a Password in Disguise

The private address you use to file issues by email can also push code and start pipelines as you. Treat it like a credential, because it is one.

4 min read
Full-frame edge-to-edge photoreal editorial shot of a smartphone lying face-up on a dark office desk, screen showing a generic unknown-caller interface glowing
Identity & Access

Fake IT helpdesk calls are opening the door to Microsoft 365 accounts

Microsoft says attackers are ringing staff on personal phones, walking them through passkey 'updates', then pulling SharePoint and OneDrive files.

4 min read
Full-frame edge-to-edge photoreal news-editorial image of a glowing laptop keyboard at night with a faint holographic key hovering above the enter key, cool blu
Identity & Access

Attackers Are Logging In, Not Breaking In

AI has cut the time between a stolen password and a full-blown intrusion. The fix isn't another login screen, it's checking the device too.

4 min read
Full-frame edge-to-edge photoreal news-editorial shot of a darkened corporate office at night, several unattended desktop monitors glowing with generic blue log
Identity & Access

Windows 11 domain logins broke this week. Here is what actually happened.

A September 2026 security update quietly started enforcing an identity-protection feature. On the wrong kind of network, it locks staff out.

4 min read
Photoreal news-editorial 16:9 image of a single smartphone lying flat on a plain concrete desk, its screen glowing with a generic six-digit authentication code
Identity & Access

The Most Common Password Is Still 123456. Here Is What Actually Fixes That.

A former CISO at Hyatt and United Airlines says the security industry keeps chasing new tools while ignoring the basics. One basic above all others stands out: multi-factor authentication, which cuts your chance of being hacked by 99 percent.

4 min read
Close-up of a server rack's status lights blinking red and green in rapid succession, with a hand hovering near an emergency shutdown switch mounted on the equi
Identity & Access

A Self-Destruct Button for Stolen API Keys

A new proposal wants any leaked API key automatically cancelled within sixty seconds of discovery. Here is why that matters, and why it is harder than it sounds.

3 min read
A help desk operator's phone in their hand displaying a password reset request form, with a computer monitor behind showing multi-factor authentication dialogs,
Identity & Access

When Password Resets Become the Front Door: The Rise of Help Desk Attacks

Multi-factor authentication has pushed criminals to a softer target: the humans who reset it.

4 min read
A corporate AI system interface showing permission levels and access control mechanisms, with an unauthorized command being executed through a permission bypass
AI Security

When AI Does What It's Told, For the Wrong Person

A new attack technique lets outsiders trigger high-privilege actions inside company AI systems without ever logging in. The flaw isn't in the AI model. It's in how these systems decide who is allowed to ask.

4 min read
A security analyst's workstation displaying a real-time threat dashboard with login attempts, phishing emails, and identity abuse alerts covering the screens, w
Threat Intelligence

Half of All Real Attacks Now Target Logins, Says Prophet Security Review

A quarter of investigating every alert across customer environments shows identity abuse, help-desk trickery and old-school phishing still doing most of the damage.

4 min read
A corporate training session with employees on computers taking a simulated phishing test, with research charts and data analysis visible on a presentation scre
Identity & Access

2.47 Million Simulated Attacks Suggest We're Measuring the Wrong Things in Phishing Training

New research points out a gap between what most companies track (who clicked a fake link) and what actually matters (whether stolen passwords are being spotted and staff are reporting suspicious emails).

3 min read
A federal office building interior with security personnel at desks reviewing documentation, multiple computer terminals showing authentication tokens and acces
Policy & Regulation

NIST and CISA tell agencies how to stop attackers walking in on stolen login tokens

The joint report tells federal agencies and cloud providers how to lock down the digital passes that keep users signed in across cloud services.

4 min read
An enterprise data center with highlighted API server infrastructure, digital locks breaking open, and credential tokens flowing through network pathways as ala
Vulnerabilities

Attackers Are Actively Exploiting a Perfect-10 WSO2 Authentication Flaw

A critical vulnerability in the WSO2 API platform, rated as severe as it gets, lets criminals forge login credentials and walk into the back end of enterprise systems. Exploitation began on September 13.

4 min read
A cybersecurity analyst working late into the evening, surrounded by monitors displaying vulnerability bulletins and exploit code, racing against time as clock
Identity & Access

Why knowing about a threat isn't the same as stopping it

Attackers are turning fresh leaks and new bug disclosures into working break-ins faster than most defenders can read the alert.

4 min read
A corporate office worker at a desk, illuminated by monitor light, typing credentials into a login form on their screen while unaware of malicious intent, with
Identity & Access

N0va phishing kit hunts logins across US and EU businesses

A phishing toolkit called N0va is tricking staff into handing over working accounts, then quietly walking through the front door.

4 min read
© 2026 Threat Vectr