Tag

#identity

91 stories taggedidentity · page 2 of 7.

A network diagram displayed on a desktop monitor showing multiple red pathways branching around a padlock symbol, representing alternative attack routes bypassi
Identity & Access

Passkeys Aren't Magic: Researchers Map 39 Ways to Sidestep Them

A new catalogue from Token shows attackers don't need to break the cryptography behind passkeys to steal accounts. They just walk around it.

4 min read
A dual-monitor workstation displaying a compromised login session on one screen and an infostealer malware interface on the other, digital fingerprints and sess
Identity & Access

When an Employee's Password Shows Up in a Stealer Log, the Session Cookie Is the Real Problem

Infostealer malware grabs more than passwords. It grabs live logins, and that's what lets attackers walk past multi-factor prompts.

4 min read
A security architecture diagram on a large display showing zero trust framework structures being dismantled and bypassed by autonomous AI agents, traditional se
AI Security

AI Agents Are Breaking the Security Model Enterprises Spent a Decade Building

Zero trust was supposed to be the answer to modern cyber risk. Agentic AI may have quietly made it obsolete.

5 min read
An employee's computer screen showing a Microsoft Teams call interface with a fake IT support representative, while the attacker gains remote desktop access sho
Identity & Access

Criminals Pose as IT Support Inside Microsoft Teams to Take Over Company Networks

A hacking campaign called Spring Ring tricked more than 150 employees at ten-plus companies into handing over remote control of their computers, all through a fake Teams call from a fake help desk.

4 min read
An office environment with an employee at a computer appearing to provide unauthorized access credentials to someone off-screen, with sensitive network diagrams
Identity & Access

Ransomware Gangs Are Now Paying Insiders to Unlock the Front Door

Criminal groups are bribing employees to hand over company access rather than hacking their way in. It is cheaper, faster, and harder to detect, and the insider threat problem is getting worse.

4 min read
A laptop screen showing a Lenovo account signup page with email verification bypass, connected to a Dropbox login session being initiated without proper authent
Identity & Access

Dropbox accounts hijacked after attacker abused a Lenovo signup flaw

A weakness in how Lenovo verified email addresses let an attacker create fake Lenovo IDs and walk straight into around 5,000 Dropbox accounts, no password needed.

4 min read
A European government office desk with a smartphone displaying encrypted messaging apps, surrounded by classified document folders and a computer showing securi
Threat Intelligence

Russian Hackers Are Phishing EU Officials on WhatsApp and Signal

Eight serious attacks on European government staff have exposed a gap no one planned for: officials trusting consumer messaging apps with sensitive business.

4 min read
A security analyst reviewing code on a monitor, with compliance logs and API documentation spread across a desk, a coffee cup at the edge showing concern-worn f
AI Security

Anthropic's New Compliance API for Claude Code: What It Shows, What It Misses

Fresh endpoints give security teams a window into how developers use Claude Code, but logs alone will not tell you whether an AI agent's access is appropriate.

3 min read
A security operations center with multiple displays showing interconnected identity verification systems, access logs, and authentication protocols visualized a
Identity & Access

Why 'Identity Fabric' Is the Phrase Every Security Team Will Hear in 2026

As passwords fade and machine accounts outnumber humans, a new architecture promises to watch every login, token and API call in one place. What it actually means.

4 min read
An office worker at a desk, face obscured, staring at a computer screen showing security alerts and suspicious login notifications during business hours
Identity & Access

When Google Workspace gets breached, the door is usually already open

Most Workspace break-ins start with a tricked employee or a forgotten app connection, not a clever hack. Here is what actually happens in the first hours, and what stops the damage.

3 min read
Multiple server racks in a secure data center with urgent patch deployment notices displayed across monitoring dashboards, showing critical vulnerability indica
Vulnerabilities

CISA Flags Six Actively Exploited Bugs, Including a Citrix NetScaler Flaw

The U.S. cyber agency ordered federal agencies to patch fast, after evidence hackers are already breaking into Citrix, Linux and Microsoft SQL Server systems.

3 min read
A cloud platform dashboard with service account management interface, showing a complex web of machine-to-machine authentications, credentials being deprecated,
Identity & Access

Snowflake kills passwords for service accounts. The cleanup starts now.

The cloud data giant is retiring password logins for machine accounts. Working out what those accounts actually do is the real headache.

4 min read
A Keycloak login interface on a screen with a password reset form, surrounded by visual indicators of vulnerability or security breach
Identity & Access

Critical Keycloak Bug Lets Anyone Reset Your Password and Log In as You

A 9.1-severity flaw in the popular open-source login server hands attackers full account takeover with no credentials required.

4 min read
A smartphone login screen showing multiple authentication methods and security badges, with a shadow figure's fingerprint attempting access in the background
Identity & Access

New Phishing Toolkit Registers Attacker Passkeys to Survive Password Resets

A tool called iAuthFlow V2 lets criminals plant a login credential they control inside your account, so changing your password does nothing to lock them out.

3 min read
Microsoft cloud infrastructure with an Entra ID vulnerability being remotely exploited, followed by a patch installation completing on the server side
Identity & Access

Microsoft Confirms Critical Entra ID Flaw Was Exploited, Says No Customer Action Needed

Redmond patched a perfect-10 remote code execution bug in its cloud identity service and says the fix was applied on its side.

3 min read
© 2026 Threat Vectr