#identity security
33 stories taggedidentity security.

Certighost: The Windows Certificate Flaw That Hands Attackers the Keys to the Kingdom
A newly disclosed bug, CVE-2026-54121, lets any ordinary staff account quietly promote itself to top-level control of a Windows network by abusing the company's certificate server.

21 Cybersecurity Companies Changed Hands in July 2026
From a billion-dollar identity security deal to a bank buying a British consultancy, July was a busy month for cybersecurity acquisitions. Here is what each deal means in plain English.

When Helpful AI Agents Go Off-Script: The Enterprise Permission Problem
Give an AI assistant vague instructions and the keys to your systems, and it will happily improvise. Security firm Token Security says that's the whole problem.

Four Million Fake App IDs, One Blind Spot: How Hackers Are Slipping Past Microsoft Login Defences
Two criminal campaigns sent over four million spoofed application identities at Microsoft's sign-in system and barely triggered an alert. Here is what happened, who is at risk, and what security teams can do about it.

The Security Metric That Lies: Why Knowing Your Vulnerabilities Is Not the Same as Reducing Your Risk
Security teams are drowning in vulnerability reports yet still cannot answer the one question that matters: are we actually harder to attack today than we were last year? A growing number of experts say the old way of measuring risk is the problem.

Why Modern Hackers Walk In Through the Front Door of Your Website
Security teams have spent years locking up their networks and servers. A new wave of attacks shows that criminals are now coming in through web applications instead, and most defences are not keeping up.

Fixing One Hole at a Time Is No Longer Enough: Why Security Must Follow the Full Attack Path
Criminals no longer stop at the front door. They chain together weaknesses across your apps, accounts, and cloud systems, and security teams testing each piece in isolation are missing the bigger picture.

Burnout, Courage, and 'Good Enough': What One Top Security Chief Learned on the Way to the C-Suite
Ping Identity's CISO Russ Kirby opens up about the mindset that kept him going through a decade of high-pressure security roles, and what still worries him today.

Black Hat 2026: Every Major Security Product Launch You Need to Know
Fifteen vendors dropped new tools at Las Vegas this week. Here is what they actually do, why it matters, and what the pattern of announcements tells us about where the industry thinks the next wave of attacks is coming from.

Why Locking Down What AI Agents Can Do Is Not Enough
A security firm says the real question is not what you told your AI to do. It is how far it can wander if something goes wrong.

AI Isn't Bringing New Attack Tricks. It's Making the Old Ones Much Faster
Security experts say the lesson from AI-assisted hacking isn't panic about sci-fi threats. It's that the basics your organisation has been ignoring for years just got a lot more dangerous to skip.

Okta Is Buying Security Firm Permiso to Catch Identity-Based Attacks
The deal would push Okta beyond managing who can log in and into spotting when a legitimate login is being used to do something it shouldn't.

ShinyHunters Are Phoning Hospital Help Desks: Health-ISAC Sounds the Alarm
A wave of voice-phishing calls is tricking healthcare staff into handing over single sign-on access, and the data theft is following fast.

The Four Ways Criminals Beat Multi-Factor Authentication (And What You Can Do About It)
Multi-factor authentication was supposed to be the lock that hackers couldn't pick. It turns out there are at least four reliable ways through it, and most organisations are leaving at least one door wide open.

Cyera Buys Oasis Security for $1 Billion to Lock Down AI Agents
Data security firm Cyera is acquiring Oasis Security in a deal worth $1 billion, combining two tools that track what AI agents and software bots are allowed to see and do inside company systems.