#identity security
36 stories taggedidentity security · page 2 of 3.

Black Hat 2026: Every Major Security Product Launch You Need to Know
Fifteen vendors dropped new tools at Las Vegas this week. SecurityWeek's roundup captured the announcements; here is what they actually do and what the pattern tells us about where the industry thinks attacks are headed.

Why Locking Down What AI Agents Can Do Is Not Enough
A security firm says the real question is not what you told your AI to do. It is how far it can wander if something goes wrong.

AI Isn't Bringing New Attack Tricks. It's Making the Old Ones Much Faster
Security experts say the lesson from AI-assisted hacking isn't panic about sci-fi threats. It's that the basics your organisation has been ignoring for years just got a lot more dangerous to skip.

Okta Is Buying Security Firm Permiso to Catch Identity-Based Attacks
The deal would push Okta beyond managing who can log in and into spotting when a legitimate login is being used to do something it shouldn't.

ShinyHunters Are Phoning Hospital Help Desks: Health-ISAC Sounds the Alarm
A wave of voice-phishing calls is tricking healthcare staff into handing over single sign-on access, and the data theft is following fast.

The Four Ways Criminals Beat Multi-Factor Authentication (And What You Can Do About It)
Multi-factor authentication was supposed to be the lock that hackers couldn't pick. It turns out there are at least four reliable routes through it, and most organisations are leaving at least one wide open.

Cyera Buys Oasis Security for $1 Billion to Lock Down AI Agents
Data security firm Cyera is acquiring Oasis Security in a deal worth $1 billion, combining two platforms that track what AI agents and software bots are permitted to see and do inside company systems.

SSO Is the New Skeleton Key. Criminals Have Noticed.
One stolen single sign-on password can hand attackers the run of a company. Here's how the break-ins work and what actually stops them.

Changing Your Password No Longer Kicks Hackers Out
A growing wave of attacks steals not passwords but the digital passes that keep you logged in, meaning a password reset leaves the intruder sitting comfortably inside your account.

The Hackers Got Hacked: Inside the Klue Breach and What It Means for Every Business Using Cloud Software
A forgotten service account let criminals walk into a competitive-intelligence platform. Then a second criminal group stole the stolen data. The whole chain shows exactly how cloud software trust goes wrong.

Microsoft's New Passkey System Has Flaws That Let Old Hacking Tricks Work Again
A security researcher found three near-exploitable bugs in Windows 11 and Microsoft's cloud login service, just as the company prepares to make passkeys the default sign-in method for hundreds of millions of users.

Oak Raises $60 Million to Replace Fragmented Identity Security Tools With a Single Platform
A new Israeli-American startup wants to give companies one place to see and control every username, AI agent, and automated system that can touch their data.

Microsoft is killing SMS logins for business accounts. Passkeys take over in September 2026.
Entra ID, the sign-in system used by millions of companies, will switch to passkeys by default. Text-message codes get shut off in February 2027.

Varonis Launches Free Entra ID Training Game to Teach Cloud Identity Attacks
Breach at the Beach is a browser-based challenge that walks defenders through the kind of Microsoft Entra ID attacks Varonis researchers say they see in real customer environments.

37 Cybersecurity Deals in One Month: What June 2026's M&A Surge Tells Us
From a $4 billion Accenture mega-deal to a $70 million automated-patching pickup, June was a busy month for security industry consolidation. Here is what moved and why it matters.