Tag

#identity security

36 stories taggedidentity security.

Illustration: a dimly lit server room with a single glowing manila folder sitting on top of a metal rack
Policy & Regulation

CISA Wants You to Leave a Trap Out for Hackers

America's cyber-defence agency has published detailed guidance on using decoys, fake password files, and tripwire accounts to catch attackers who have already slipped inside a network.

5 min read
A glowing blue padlock made of translucent code fragments slowly dissolving into streams of light against a dark server room background, with rows of blinking r
Identity & Access

GhostCode Phishing Kit Turns Microsoft's Own Login Flow Against You

A new tool called GhostCode abuses a legitimate Microsoft sign-in mechanism to steal account access, register attacker-controlled devices, and survive password resets, all in under 90 seconds.

4 min read
A data center environment with server racks, focusing on indicator lights and automated processes, with transparent overlay showing invisible machine account lo
Identity & Access

Machine Accounts Are Now the Likeliest Way Into Your Company, and Almost Nobody Is Watching Them

A new SpyCloud survey of 750 security leaders finds that automated accounts and AI agents have become the single most common entry point for attackers, yet fewer than four in ten organisations are actively monitoring them.

4 min read
A cybersecurity operations center with multiple monitors showing successful threat detection and blocked breach attempts, representing defended systems
Threat Intelligence

ShinyHunters Claimed It Broke Into ReliaQuest. The Reality Is More Complicated.

A cybersecurity company's own employee fell for a fake login page, handing criminals limited access. What happened next is actually a story about defences holding.

3 min read
A cloud security dashboard rapidly cycling through thousands of failed login attempts and vulnerability scans, progress bars filling at inhuman speed, red alert
Cloud Security

AI Agents Are Breaking Cloud Security Faster Than Human Hackers Ever Could

Automated attackers can test thousands of ways into a company's cloud systems in minutes. Most security teams are still thinking at human speed.

4 min read
A security operations center with multiple monitors displaying continuous vulnerability scanning dashboards, showing real-time threat detection in progress rath
Vulnerabilities

Why Security Teams Are Ditching the Quarterly Scan for Something That Never Stops

A growing number of organisations are replacing old-school vulnerability scanning with a continuous approach called CTEM. The idea sounds simple. The culture change is anything but.

4 min read
A corporate office building exterior at dusk with security cameras and access points visible, reflecting confidence and growth, with abstract data streams flowi
Identity & Access

Okta Beats Earnings Forecasts as Companies Rush to Secure AI Agents

The identity security firm raised its annual outlook after a stronger-than-expected quarter, with demand rising from businesses trying to control who, and what, can access their systems.

3 min read
A Windows Server control panel with certificate management tools open, showing how unauthorized privilege escalation could occur through certificate authority a
Vulnerabilities

Certighost: The Windows Certificate Flaw That Hands Attackers the Keys to the Kingdom

A newly disclosed bug, CVE-2026-54121, lets any ordinary staff account quietly promote itself to top-level control of a Windows network by abusing the company's certificate server.

4 min read
A financial trading floor or merger room with large screens displaying acquisition announcements and deal values, executives reviewing contracts, representing c
Threat Intelligence

21 Cybersecurity Companies Changed Hands in July 2026

From a billion-dollar identity security deal to a bank buying a British consultancy, July was a busy month for cybersecurity acquisitions. Here is what each deal means in plain English.

4 min read
An AI agent interface window showing a vague command being interpreted with improvised system-level actions executing, permission structure breakdown visualized
AI Security

When Helpful AI Agents Go Off-Script: The Enterprise Permission Problem

Give an AI assistant vague instructions and the keys to your systems, and it will happily improvise. Security firm Token Security says that's the whole problem.

4 min read
A security operations center where analysts are tracking millions of spoofed login attempts on large dashboard displays, threat intelligence feeds scrolling acr
Identity & Access

Four Million Fake App IDs, One Blind Spot: How Hackers Are Slipping Past Microsoft Login Defences

Two criminal campaigns sent over four million spoofed application identities at Microsoft's sign-in system and barely triggered an alert. Here is what happened, who is at risk, and what security teams can do.

5 min read
A security operations center dashboard overwhelmed with thousands of vulnerability alerts and scan results covering every inch of multiple monitors, with a mana
Vulnerabilities

The Security Metric That Lies: Why Knowing Your Vulnerabilities Is Not the Same as Reducing Your Risk

Security teams are drowning in vulnerability reports yet still can't answer the one question that matters: are we actually harder to attack today than we were last year? The old way of measuring risk is the problem.

4 min read
A web application login page displayed on a monitor with a padlock icon, while in the background a network diagram shows multiple breach points, red lines indic
Vulnerabilities

Why Modern Hackers Walk In Through the Front Door of Your Website

Security teams have spent years locking up their networks and servers. A new wave of attacks shows that criminals are now coming in through web applications instead, and most defences are not keeping up.

3 min read
An expansive network diagram showing multiple interconnected systems—applications, cloud services, and accounts—with red lines tracing a complex attack path tha
Vulnerabilities

Fixing One Hole at a Time Is No Longer Enough: Why Security Must Follow the Full Attack Path

Criminals no longer stop at the front door. They chain weaknesses across apps, accounts, and cloud systems, and security teams testing each piece in isolation are missing the bigger picture.

4 min read
A security leader's office at dusk, with desk covered in incident reports and a computer screen glowing with security dashboards, conveying the weight of respon
Opinion

Burnout, Courage, and 'Good Enough': What One Top Security Chief Learned on the Way to the C-Suite

Ping Identity's CISO Russ Kirby on the mindset that carried him through a decade of high-pressure security roles, and what still keeps him up at night.

3 min read
© 2026 Threat Vectr