#identity
75 stories taggedidentity · page 2 of 5.

The AI helpers your staff installed without telling IT
Autonomous AI agents are quietly attaching themselves to company accounts, often with wide permissions and no oversight. Here is what that means and how to get a grip on it.

A Single Default Setting in Azure Automation Could Have Let Hackers Steal Any Tenant's Cloud Identity
A researcher found that Microsoft's cloud automation service was, by default, leaving account identities visible to the public internet, giving any attacker a path to impersonate other organisations' privileged accounts.

AI Agents Need More Than a Watchful Eye. They Need a Leash.
Watching what AI agents do inside your systems is useful. Stopping them doing the wrong thing is the harder job, and the one security teams keep tripping over.

Google rolls out selfie video sign-in for locked-out account holders
The new recovery option sits alongside email and phone number checks, and is aimed at people who cannot get back into their Google account any other way.

What is multi-factor authentication and why does it matter?
MFA blocks the vast majority of automated account takeovers, even when your password is already stolen.

When your AI helper has admin rights: the new ransomware fast lane
Enterprise AI assistants with over-broad permissions can turn a routine break-in into a company-wide ransomware event in minutes, Acronis warns.

Why Stolen Logins Keep Opening the Door to Power Grids and Water Plants
Attackers rarely need fancy exploits when a valid password and an unchecked laptop will do. A look at why device trust is the missing half of Zero Trust in critical infrastructure.

Fake X Login Alerts Are Being Used to Steal Your Password
Criminals are sending convincing 'new device login' emails to X users, hoping to harvest account credentials for follow-on fraud including crypto scams and phishing attacks.

n8n Login Bug Let a Valid Token From One Provider Log You In as Someone Else
The workflow automation platform matched users on a single ID field and ignored who issued the token. On Enterprise setups with more than one login provider, that was enough to walk in as another person.

AI Agents Are Making Security Playbooks Obsolete. Identity Is the Fix.
Security teams built their rules for humans clicking buttons. AI agents click a thousand buttons a second, and the old playbook cannot keep up.

AI Can Build a Dossier on Your CEO in Ten Minutes. Most Companies Have No Answer for That.
Artificial intelligence tools have turned the slow, skilled work of researching a target executive into a task anyone with a browser can do. Security teams have not caught up.

Fake Emails Now Beat Software Flaws as the Number-One Way Ransomware Gets In
A Sophos survey of more than 2,000 organisations hit by ransomware finds that phishing and malicious emails now cause half of all attacks, while stolen passwords are defeating even multi-factor authentication at an alarming rate.

Hackers Are Faking OAuth App IDs to Quietly Test Stolen Microsoft Logins
A new trick lets attackers check stolen Microsoft Entra ID passwords without triggering a single sign-in alert.

How ShinyHunters walked into Salesforce accounts without breaking anything
Microsoft says a year of data theft from Salesforce tenants leaned on trusted app connections, not a platform bug.

Argentina's Football Association Says Its Email Account May Have Been Hacked After World Cup Win
Someone sent journalists messages from the AFA's official inbox claiming Argentina's victory over Egypt was fixed. The association says it didn't send them.