#identity
91 stories taggedidentity.

Microsoft is switching off text-message logins for work accounts in February 2027
Entra ID admins have 15 months to move staff onto passkeys or hardware keys before SMS sign-in stops working.

GitLab's Per-User Issue Email Is a Password in Disguise
The private address you use to file issues by email can also push code and start pipelines as you. Treat it like a credential, because it is one.

Fake IT helpdesk calls are opening the door to Microsoft 365 accounts
Microsoft says attackers are ringing staff on personal phones, walking them through passkey 'updates', then pulling SharePoint and OneDrive files.

Attackers Are Logging In, Not Breaking In
AI has cut the time between a stolen password and a full-blown intrusion. The fix isn't another login screen, it's checking the device too.

Windows 11 domain logins broke this week. Here is what actually happened.
A September 2026 security update quietly started enforcing an identity-protection feature. On the wrong kind of network, it locks staff out.

The Most Common Password Is Still 123456. Here Is What Actually Fixes That.
A former CISO at Hyatt and United Airlines says the security industry keeps chasing new tools while ignoring the basics. One basic above all others stands out: multi-factor authentication, which cuts your chance of being hacked by 99 percent.

A Self-Destruct Button for Stolen API Keys
A new proposal wants any leaked API key automatically cancelled within sixty seconds of discovery. Here is why that matters, and why it is harder than it sounds.

When Password Resets Become the Front Door: The Rise of Help Desk Attacks
Multi-factor authentication has pushed criminals to a softer target: the humans who reset it.

When AI Does What It's Told, For the Wrong Person
A new attack technique lets outsiders trigger high-privilege actions inside company AI systems without ever logging in. The flaw isn't in the AI model. It's in how these systems decide who is allowed to ask.

Half of All Real Attacks Now Target Logins, Says Prophet Security Review
A quarter of investigating every alert across customer environments shows identity abuse, help-desk trickery and old-school phishing still doing most of the damage.

2.47 Million Simulated Attacks Suggest We're Measuring the Wrong Things in Phishing Training
New research points out a gap between what most companies track (who clicked a fake link) and what actually matters (whether stolen passwords are being spotted and staff are reporting suspicious emails).

NIST and CISA tell agencies how to stop attackers walking in on stolen login tokens
The joint report tells federal agencies and cloud providers how to lock down the digital passes that keep users signed in across cloud services.

Attackers Are Actively Exploiting a Perfect-10 WSO2 Authentication Flaw
A critical vulnerability in the WSO2 API platform, rated as severe as it gets, lets criminals forge login credentials and walk into the back end of enterprise systems. Exploitation began on September 13.

Why knowing about a threat isn't the same as stopping it
Attackers are turning fresh leaks and new bug disclosures into working break-ins faster than most defenders can read the alert.

N0va phishing kit hunts logins across US and EU businesses
A phishing toolkit called N0va is tricking staff into handing over working accounts, then quietly walking through the front door.