#identity security
36 stories taggedidentity security.

CISA Wants You to Leave a Trap Out for Hackers
America's cyber-defence agency has published detailed guidance on using decoys, fake password files, and tripwire accounts to catch attackers who have already slipped inside a network.

GhostCode Phishing Kit Turns Microsoft's Own Login Flow Against You
A new tool called GhostCode abuses a legitimate Microsoft sign-in mechanism to steal account access, register attacker-controlled devices, and survive password resets, all in under 90 seconds.

Machine Accounts Are Now the Likeliest Way Into Your Company, and Almost Nobody Is Watching Them
A new SpyCloud survey of 750 security leaders finds that automated accounts and AI agents have become the single most common entry point for attackers, yet fewer than four in ten organisations are actively monitoring them.

ShinyHunters Claimed It Broke Into ReliaQuest. The Reality Is More Complicated.
A cybersecurity company's own employee fell for a fake login page, handing criminals limited access. What happened next is actually a story about defences holding.

AI Agents Are Breaking Cloud Security Faster Than Human Hackers Ever Could
Automated attackers can test thousands of ways into a company's cloud systems in minutes. Most security teams are still thinking at human speed.

Why Security Teams Are Ditching the Quarterly Scan for Something That Never Stops
A growing number of organisations are replacing old-school vulnerability scanning with a continuous approach called CTEM. The idea sounds simple. The culture change is anything but.

Okta Beats Earnings Forecasts as Companies Rush to Secure AI Agents
The identity security firm raised its annual outlook after a stronger-than-expected quarter, with demand rising from businesses trying to control who, and what, can access their systems.

Certighost: The Windows Certificate Flaw That Hands Attackers the Keys to the Kingdom
A newly disclosed bug, CVE-2026-54121, lets any ordinary staff account quietly promote itself to top-level control of a Windows network by abusing the company's certificate server.

21 Cybersecurity Companies Changed Hands in July 2026
From a billion-dollar identity security deal to a bank buying a British consultancy, July was a busy month for cybersecurity acquisitions. Here is what each deal means in plain English.

When Helpful AI Agents Go Off-Script: The Enterprise Permission Problem
Give an AI assistant vague instructions and the keys to your systems, and it will happily improvise. Security firm Token Security says that's the whole problem.

Four Million Fake App IDs, One Blind Spot: How Hackers Are Slipping Past Microsoft Login Defences
Two criminal campaigns sent over four million spoofed application identities at Microsoft's sign-in system and barely triggered an alert. Here is what happened, who is at risk, and what security teams can do.

The Security Metric That Lies: Why Knowing Your Vulnerabilities Is Not the Same as Reducing Your Risk
Security teams are drowning in vulnerability reports yet still can't answer the one question that matters: are we actually harder to attack today than we were last year? The old way of measuring risk is the problem.

Why Modern Hackers Walk In Through the Front Door of Your Website
Security teams have spent years locking up their networks and servers. A new wave of attacks shows that criminals are now coming in through web applications instead, and most defences are not keeping up.

Fixing One Hole at a Time Is No Longer Enough: Why Security Must Follow the Full Attack Path
Criminals no longer stop at the front door. They chain weaknesses across apps, accounts, and cloud systems, and security teams testing each piece in isolation are missing the bigger picture.

Burnout, Courage, and 'Good Enough': What One Top Security Chief Learned on the Way to the C-Suite
Ping Identity's CISO Russ Kirby on the mindset that carried him through a decade of high-pressure security roles, and what still keeps him up at night.