#identity
75 stories taggedidentity · page 3 of 5.

AI Agents Are Quietly Multiplying Inside Your Company Directory
Every new AI helper needs its own login. Most companies have no idea how many they now have, or what those logins can touch.

Hackers Broke Into an AI Gateway and Found a Door to Everything
A cryptomining attack on an Amazon cloud server was almost certainly the least damaging thing the criminals could have done. Security researchers say AI gateways are becoming one of the most overlooked entry points in enterprise computing.

Passkeys Are Winning the Login Fight. Attackers Are Moving to the Verification Step.
Credential stuffing is fading as passkeys go mainstream. The next account takeover battle is happening at password resets, help desks, and identity checks.

Fake Teams Invites Are Tricking Microsoft 365 Users Into Handing Over Their Accounts
A phishing crew is skipping the fake login page and walking victims straight through Microsoft's own device sign-in flow.

AI Is Making Decisions at Work. Most Companies Have No Rules for That.
Security expert Stephen Wilson says businesses are handing AI tools more and more independence, but treating them with the same loose oversight they used when AI just answered questions.

The Weak Link This Week Wasn't Code. It Was Trust.
From home streaming boxes turned into criminal relays to AI assistants tricked by hidden instructions, this week's incidents share one root cause: systems trusting the wrong thing.

WhatsApp Is Letting You Ditch Your Phone Number — Here's What That Means for Your Privacy
The world's most-used messaging app is adding usernames, so strangers no longer need your phone number to reach you. It's a meaningful privacy upgrade, but it comes with a scramble.

81 Million Login Attempts: A Massive Password Spray Attack Hit Microsoft 365 Users
Criminals hammered Microsoft accounts with automated login attempts for two weeks. At least 78 accounts were broken into — and many victims had multi-factor authentication switched on, just not set up correctly.

0ktapus Phishing Campaign Hits 130 Companies, Compromising Nearly 10,000 Accounts
A widespread phishing attack targets employees of Twilio and Cloudflare, exploiting Okta's authentication system.

Drag, Drop, Hijacked: How 'ConsentFix' Steals Microsoft 365 Sessions in Seconds
A new twist on the ClickFix trick turns Microsoft's own sign-in prompts into a session-theft machine — and a step-by-step guide is now circulating on a Russian crime forum.

Twenty Years of Getting It Wrong: The Breaches and Blunders That Defined Modern Cybersecurity
From MGM's identity disaster to MOVEit's patch pile-up, the same failure modes keep appearing in postmortems. That's the problem.

Identity Security as a Career On-Ramp: What One CISO Actually Thinks
Silverfort's John Paul Cunningham argues AI is opening doors in cybersecurity rather than closing them — and identity is where new practitioners should focus first.

Context Manipulation Attack 'BioShocking' Turns Agentic Browsers Into Credential Thieves
Researchers demonstrate how feeding poisoned context to AI-driven browser agents causes them to quietly drop safety guardrails and exfiltrate stored credentials.

BEC Isn't an Email Problem. It's a Supply Chain.
Underground forums show Business Email Compromise as a multi-stage operation — account access, target research, and mules — not a clever phishing lure.

WhatsApp Starts Username Reservations, Finally Decoupling Identity From Phone Numbers
The optional handle system lets users be reachable without exposing an E.164 number — a meaningful identifier change for a 3-billion-user directory.