#identity
91 stories taggedidentity · page 5 of 7.

How ShinyHunters walked into Salesforce accounts without breaking anything
Microsoft says a year of data theft from Salesforce tenants leaned on trusted app connections, not a platform bug.

Argentina's Football Association Says Its Email Account May Have Been Hacked After World Cup Win
Someone sent journalists messages from the AFA's official inbox claiming Argentina's victory over Egypt was fixed. The association says it didn't send them.

AI Agents Are Quietly Multiplying Inside Your Company Directory
Every new AI helper needs its own login. Most companies have no idea how many they now have, or what those logins can touch.

Hackers Broke Into an AI Gateway and Found a Door to Everything
A cryptomining attack on an Amazon cloud server was almost certainly the least damaging thing the criminals could have done. Security researchers say AI gateways are becoming one of the most overlooked entry points in enterprise computing.

Passkeys Are Winning the Login Fight. Attackers Are Moving to the Verification Step.
Credential stuffing is fading as passkeys go mainstream. The next account takeover battle is happening at password resets, help desks, and identity checks.

Fake Teams Invites Are Tricking Microsoft 365 Users Into Handing Over Their Accounts
A phishing crew is skipping the fake login page and walking victims straight through Microsoft's own device sign-in flow.

AI Is Making Decisions at Work. Most Companies Have No Rules for That.
Stephen Wilson, field CTO at HashiCorp, says businesses are giving AI tools real operational independence while still applying the loose oversight they used when AI only answered questions.

The Weak Link This Week Wasn't Code. It Was Trust.
From home streaming boxes turned into criminal relays to AI assistants tricked by hidden instructions, this week's incidents share one root cause: systems trusting the wrong thing.

WhatsApp Is Letting You Ditch Your Phone Number — Here's What That Means for Your Privacy
The world's most-used messaging app is adding usernames, so strangers no longer need your phone number to reach you. A meaningful privacy upgrade, but it comes with a scramble.

81 Million Login Attempts: A Massive Password Spray Attack Hit Microsoft 365 Users
Criminals hammered Microsoft accounts with automated login attempts for two weeks. At least 78 accounts were broken into, and some victims had multi-factor authentication switched on but not configured to cover the login route the attackers actually used.

0ktapus Phishing Campaign Hits 130 Companies, Compromising Nearly 10,000 Accounts
A phishing campaign exploiting Okta's authentication system has breached 9,931 accounts across 130 organizations, with Twilio, Cloudflare and DoorDash among the victims.

Drag, Drop, Hijacked: How 'ConsentFix' Steals Microsoft 365 Sessions in Seconds
A new twist on the ClickFix trick turns Microsoft's own sign-in prompts into a session-theft machine, and a step-by-step guide is now circulating on a Russian crime forum.

Twenty Years of Getting It Wrong: The Breaches and Blunders That Defined Modern Cybersecurity
From MGM's identity disaster to MOVEit's patch pile-up, the same failure modes keep appearing in postmortems. That's the problem.

Identity Security as a Career On-Ramp: What One CISO Actually Thinks
Silverfort's John Paul Cunningham argues AI is opening doors in cybersecurity rather than closing them, and identity is where new practitioners should focus first.

Context Manipulation Attack 'BioShocking' Turns Agentic Browsers Into Credential Thieves
Researchers show how poisoned context fed to AI-driven browser agents causes them to drop safety guardrails and quietly exfiltrate stored credentials.