#identity
91 stories taggedidentity · page 2 of 7.

Passkeys Aren't Magic: Researchers Map 39 Ways to Sidestep Them
A new catalogue from Token shows attackers don't need to break the cryptography behind passkeys to steal accounts. They just walk around it.

When an Employee's Password Shows Up in a Stealer Log, the Session Cookie Is the Real Problem
Infostealer malware grabs more than passwords. It grabs live logins, and that's what lets attackers walk past multi-factor prompts.

AI Agents Are Breaking the Security Model Enterprises Spent a Decade Building
Zero trust was supposed to be the answer to modern cyber risk. Agentic AI may have quietly made it obsolete.

Criminals Pose as IT Support Inside Microsoft Teams to Take Over Company Networks
A hacking campaign called Spring Ring tricked more than 150 employees at ten-plus companies into handing over remote control of their computers, all through a fake Teams call from a fake help desk.

Ransomware Gangs Are Now Paying Insiders to Unlock the Front Door
Criminal groups are bribing employees to hand over company access rather than hacking their way in. It is cheaper, faster, and harder to detect, and the insider threat problem is getting worse.

Dropbox accounts hijacked after attacker abused a Lenovo signup flaw
A weakness in how Lenovo verified email addresses let an attacker create fake Lenovo IDs and walk straight into around 5,000 Dropbox accounts, no password needed.

Russian Hackers Are Phishing EU Officials on WhatsApp and Signal
Eight serious attacks on European government staff have exposed a gap no one planned for: officials trusting consumer messaging apps with sensitive business.

Anthropic's New Compliance API for Claude Code: What It Shows, What It Misses
Fresh endpoints give security teams a window into how developers use Claude Code, but logs alone will not tell you whether an AI agent's access is appropriate.

Why 'Identity Fabric' Is the Phrase Every Security Team Will Hear in 2026
As passwords fade and machine accounts outnumber humans, a new architecture promises to watch every login, token and API call in one place. What it actually means.

When Google Workspace gets breached, the door is usually already open
Most Workspace break-ins start with a tricked employee or a forgotten app connection, not a clever hack. Here is what actually happens in the first hours, and what stops the damage.

CISA Flags Six Actively Exploited Bugs, Including a Citrix NetScaler Flaw
The U.S. cyber agency ordered federal agencies to patch fast, after evidence hackers are already breaking into Citrix, Linux and Microsoft SQL Server systems.

Snowflake kills passwords for service accounts. The cleanup starts now.
The cloud data giant is retiring password logins for machine accounts. Working out what those accounts actually do is the real headache.

Critical Keycloak Bug Lets Anyone Reset Your Password and Log In as You
A 9.1-severity flaw in the popular open-source login server hands attackers full account takeover with no credentials required.

New Phishing Toolkit Registers Attacker Passkeys to Survive Password Resets
A tool called iAuthFlow V2 lets criminals plant a login credential they control inside your account, so changing your password does nothing to lock them out.

Microsoft Confirms Critical Entra ID Flaw Was Exploited, Says No Customer Action Needed
Redmond patched a perfect-10 remote code execution bug in its cloud identity service and says the fix was applied on its side.