Tag

#identity

91 stories taggedidentity · page 3 of 7.

An email inbox interface showing multiple messages, with several appearing legitimate but flagged by security analysis tools, while an endpoint protection panel
Identity & Access

AI-powered phishing is slipping past email filters. Here's how to catch it after the click.

Email gateways can't spot every AI-written lure. The catch now happens at the identity and endpoint layer.

4 min read
A security operations center with massive wall displays showing login attempt metrics, graphs spiking dramatically upward, failed authentication patterns highli
Identity & Access

Password Spraying Attacks Jump 155-Fold as Attackers Hunt for MFA Blind Spots

Huntress logged more than 81 million login attempts in a single two-week campaign, with attackers targeting old sign-in methods that skip multi-factor checks.

3 min read
Gmail and Google Drive interface open on a computer screen with access granted through stolen OAuth tokens, showing unauthorized file access and email reading w
Cloud Security

OAuth Tokens Are Quietly Becoming the Skeleton Key to Google Workspace

Phishing gets the headlines, but stolen app tokens can open Gmail and Drive without ever tripping a login alert.

4 min read
A web browser window showing the extension management page with numerous fake VPN add-ons installed, their permission requests and data collection warnings visi
Identity & Access

737 Fake VPN Extensions in Chrome Store Quietly Hijacked Browsers

The free browser add-ons promised to unblock websites for Russian speakers. Instead they routed every page a user visited through servers the operators controlled.

4 min read
An HR onboarding workflow diagram displayed on a corporate system, showing gaps between background check completion, laptop shipment, and account activation sta
Identity & Access

The fake new hire problem: how criminals slip in through remote onboarding

Gaps between background checks, laptop delivery and account setup are letting impostors join companies as staff. Here's how the trick works, and what stops it.

4 min read
A security operations center during a credential compromise alert, multiple screens showing device fingerprinting data, biometric readings, and behavioral analy
Identity & Access

Passwords Are Getting Easier to Fake. Device Trust Is the Fix Companies Are Reaching For.

AI is turbocharging phishing and credential theft, and the old signals that told a company a login was fine are quietly failing. Here is what is replacing them.

4 min read
A Belgian government office with digital identity infrastructure documentation spread across a desk, a security researcher's laptop showing vulnerability analys
Identity & Access

Two Million Belgians Exposed by Flaws in the Software They Use to Sign Legal Documents Online

Security researcher James Arnott found that Belgium's most-used digital identity tool could let any malicious website steal a user's PIN, forge their electronic signature, or quietly run attack code on their computer, all without the victim clicking anything suspicious.

4 min read
A network diagram displayed on a monitor with cloud infrastructure icons and security layers, showing a single credential point glowing red as lines of compromi
Cloud Security

One Developer Password Unlocked Everything: Inside a Healthcare Software Provider's Wake-Up Call

A company that thought its segmented cloud setup was secure ran a simulated attack and watched a single stolen developer credential unravel four years of layered defences in minutes.

4 min read
An enterprise office environment with employees using AI-assisted software tools at their workstations, network visualizations showing automated agents making u
AI Security

AI Agents Are Breaking Into Your Own Systems, With Your Permission

The real danger from enterprise AI isn't hackers. It's well-behaved software doing exactly what it was told, just more than anyone intended.

4 min read
A Windows login screen being displayed on a corporate office computer, with device approval prompts visible and attacker control indicators in the system tray
Identity & Access

Kali365 Phishing Kit Turns Microsoft's Own Login Page Against US Firms

A criminal toolkit tricks staff into approving attacker device codes on genuine Microsoft screens, handing over long-lived access to email and cloud files.

3 min read
A computer screen showing an AI agent's intended actions versus its permitted scope, with visual indicators showing where the agent's behavior deviates from gua
AI Security

Varonis pitches 'intent-based' guardrails for AI agents that stray off task

Agent IBAC watches what an AI agent is trying to do, not just what it is allowed to touch, and pulls the brakes when the two drift apart.

4 min read
Security researcher at workstation displaying Chrome browser and password manager interface, malware attack path diagrams and vulnerability demonstrations on mu
Identity & Access

Malware Can Silently Hijack Chrome Passkeys, Researchers Show

Palo Alto's Unit 42 details three attack paths against Google Password Manager that let ordinary user-level malware sign in without a fingerprint, PIN, or on-screen prompt.

3 min read
A smart TV setup with a device code login screen displayed, corporate office network architecture visible in the background, breach pathways illustrated through
Identity & Access

Device Code Phishing: The Login Trick That Blew Up in 2026

A login flow built for smart TVs is now one of the fastest-growing routes into corporate accounts, and identity teams are struggling to keep up.

4 min read
A network infrastructure diagram showing a firewall device at the center, surrounded by AI agent communication streams flowing in multiple directions, with the
AI Security

The Network Is Quietly Becoming the Referee for AI Traffic

As AI tools multiply inside companies, firewalls are being asked to do a job they were never designed for: policing conversations between machines that think.

4 min read
An AI agent with multiple oversized keys floating around it, each granting access to different company systems, with security researchers observing from the sid
Identity & Access

AI agents with too many keys: why permissions are the new identity problem

As companies rush to deploy AI assistants that act on their behalf, security researchers warn the real danger is not the AI itself but the sweeping access rights it inherits.

4 min read
© 2026 Threat Vectr