#identity security
33 stories taggedidentity security · page 2 of 3.

SSO Is the New Skeleton Key. Criminals Have Noticed.
One stolen single sign-on password can hand attackers the run of a company. Here's how the break-ins work and what actually stops them.

Changing Your Password No Longer Kicks Hackers Out
A growing wave of attacks steals not passwords but the digital passes that keep you logged in, meaning a password reset leaves the intruder sitting comfortably inside your account.

The Hackers Got Hacked: Inside the Klue Breach and What It Means for Every Business Using Cloud Software
A forgotten service account let criminals walk into a competitive-intelligence platform. Then a second criminal group stole the stolen data. The whole chain is a masterclass in how cloud software trust goes wrong.

Microsoft's New Passkey System Has Flaws That Let Old Hacking Tricks Work Again
A security researcher found three near-exploitable bugs in Windows 11 and Microsoft's cloud login service, just as the company prepares to make passkeys the default for hundreds of millions of users.

Oak Raises $60 Million to Replace Fragmented Identity Security Tools With a Single Platform
A new Israeli-American startup wants to give companies one place to see and control every username, AI agent, and automated system that can touch their data.

Microsoft Is Killing SMS Login for Millions of Business Accounts. Here Is What Replaces It.
Starting September 2026, Microsoft will push passkeys as the default way to prove your identity in its business login system. By February 2027, the old text-message codes go dark entirely.

Microsoft is killing SMS logins for business accounts. Passkeys take over in September 2026.
Entra ID, the sign-in system used by millions of companies, will switch to passkeys by default. Text-message codes get shut off in February 2027.

Varonis Launches Free Entra ID Training Game to Teach Cloud Identity Attacks
Breach at the Beach is a browser-based challenge that walks defenders through the kind of Microsoft Entra ID attacks Varonis researchers say they see in real customer environments.

37 Cybersecurity Deals in One Month: What June 2026's M&A Surge Tells Us
From a $4 billion Accenture mega-deal to a $70 million automated-patching pickup, June was a busy month for security industry consolidation. Here is what moved and why it matters.

Your AI Coding Bots Are Running Unsupervised and Nobody Knows What They Did Last Night
AI agents inside software development teams can write, test, and deploy code on their own, often with no human checking what they did. Most companies have no way to answer a simple question: who authorised that change?

Spanish Startup 8Layers Has Raised $2.9 Million to Track Every Digital Identity Inside a Business
The Madrid company says its platform watches human accounts, software service accounts, and AI agents across cloud tools, then flags suspicious behaviour before it becomes a breach.

The Gentlemen Ransomware Gang Turns Your Own IT Tools Against You
A fast-spreading criminal group is using the software your IT team trusts every day to take over company networks. The real test is not whether they got in. It is what happens next.

Cisco Spends Around $400 Million to Plug a Growing Security Blind Spot: AI Agents
Two rapid-fire acquisitions — Astrix Security and WideField Security — are Cisco's answer to a question most companies haven't thought to ask: who's watching the bots?

ASIO Found State Hackers Pre-Positioned for Sabotage Inside Australian Critical Infrastructure
Australia's domestic intelligence agency says a foreign state actor had stolen valid credentials from IT staff at a critical infrastructure operator — and was staging for disruption, not just espionage.

Account Takeovers Still Outrunning Detection, Vendors Push Behavioral AI as Answer
Compromised credentials remain the cheapest entry point on criminal marketplaces. A new webinar argues behavioral models, not static rules, are the only way to close the gap.