Skip to main content

Tag: identity management

69 articles

Rows of servers and network equipment fill a large IT infrastructure room, conveying complexity and interconnectedness.

Identity Fabric Emerges as Key to Modernizing Enterprise Identity Security

In today's complex hybrid and multi-cloud environments, an Identity Fabric weaves together disparate identity systems, providing a unified layer of visibility into how identities interact across applications, APIs, and infrastructure. By bridging the gap between access intent and runtime execution, it shines a light on hidden risks and vulnerabilities, eliminating the identity dark matter that attackers exploit.

Analyst 207
A generic login screen on a laptop in a quiet, institutional setting with soft daylight.

Keycloak Flaw Exposes Accounts to Unauthenticated Takeover

A critical flaw in Keycloak, rated 9.1 by Red Hat, allows hackers to hijack any account, including admin ones, by manipulating the password reset process. This vulnerability, CVE-2026-18963, lets attackers take control without even logging in.

Analyst 207
Rows of computer servers and storage systems in a brightly-lit data center with highlighted server screens and scattered…

Thousands of Leaked AWS Keys Remain Active

A recent scan by Truffle Security uncovered a staggering 9,300+ active AWS keys that were leaked online, including hundreds with full administrative rights, putting sensitive data at risk. These compromised keys were found across various public platforms, with a shocking 88% still authentic and vulnerable to exploitation.

Analyst 207
Server room interior with rack-mounted equipment and blurred credential symbol.

AWS Security Quarantine Policy Falls Short Against Credential Abuse

Leaking AWS credentials can lead to a staggering 99% increase in your bill - but a recent finding by Truffle Security reveals that even AWS' Quarantine Policy may not be enough to stop the damage, with hundreds of leaked root keys still active. This alarming discovery highlights the urgent need for tighter security measures to prevent credential abuse.

Analyst 207
Secure server room with rows of computer servers and networking equipment.

Microsoft patches exploited Entra ID flaw amid rising attacks

Microsoft has patched a critical vulnerability in its Entra ID platform, known as CVE-2026-69836, which allowed attackers to execute code remotely with ease, and has already been exploited in recent attacks. This flaw enabled unauthorized threat actors to gain control and wreak havoc, making swift action crucial to prevent further damage.

Analyst 207
Secure door with keycard reader and biometric scanner slightly ajar, showing daylight.

Identity Takes Center Stage in Cybersecurity as Threats Evolve

In today's evolving threat landscape, protecting identity has become the top priority in cybersecurity - treat it like the crown jewels, because it is. By prioritizing identity protection and having a plan in place to recover quickly, organizations can safeguard the foundation of every mission.

Analyst 207
Diverse professionals gather around a large table in a bright, neutral room, engaged in discussion and reviewing technology.

NVIDIA Launches Open Secure AI Alliance to Share Threat-Detecting Tech

Join the Open Secure AI Alliance, a groundbreaking coalition of 37 industry leaders, as they revolutionize AI security by sharing cutting-edge threat-detecting technologies and collaborative defense strategies. Together, they're breaking down silos to safeguard the future of AI and software development.

Analyst 207
Modern office interior with employees working at computer workstations and a partially open server room door in the…

AI Agents Expose Growing Enterprise Attack Surface

The rapid proliferation of AI agents in enterprise environments - up 466.7% in just one year - has created a massive, high-value target for cybercriminals, with these AI identities often being granted privileged access to core systems. This surge in AI adoption has significantly expanded the enterprise attack surface, making it a prime time for cyber threats to exploit these new vulnerabilities.

Analyst 207
Person holding smartphone with biometric authentication, in modern office setting.

Microsoft Entra ID Shifts to Passkey Authentication Default

Microsoft is shaking things up with its Entra ID service by making passkey authentication the default method starting September 2026, and users currently relying on SMS or voice authentication will be automatically transitioned to passkeys. By February 1, 2027, SMS and voice authentication will be phased out, marking a significant shift towards more secure passkey technology.

Analyst 207
People stand on a beach with a subtle network infrastructure pattern in the background.

Varonis Launches Breach at the Beach, a Hands-On Entra ID Training Experience

Get ready to dive into the world of Entra ID with Varonis' immersive Breach at the Beach training experience, where you'll learn to navigate the complex control plane that connects users, applications, and AI-powered workflows. Discover how to defend against threats that exploit non-human identities and automate breaches.

Analyst 207
Rows of computer servers and network equipment in a modern data center, with one server highlighted.

Agentic AI's Identity Crisis Leaves Security Teams Vulnerable

Agentic AI's autonomy and poorly tracked access are creating a perfect storm of identity risk, leaving security teams vulnerable to attacks. As digital actors with broad permissions, these AI agents are operating in the dark, with many organizations lacking visibility into their actions.

Analyst 207
Blurred laptop screen on office table surrounded by coworkers.

AI Agents Emerge as Unchecked Identities in Enterprise Security

The equation for enterprise security is no longer simple: with AI agents now connected to critical business services, controlling identities is no longer enough to control risk. These emerging insiders have quietly become privileged - and potentially invisible - attack paths that security and identity programs must urgently address.

Analyst 207
Blurred laptop screen on a cluttered office desk with subtle signs of disarray.

Account Takeovers Rise as Complexity Exposes Identity Vulnerabilities

As attackers increasingly target identities rather than infrastructure, account takeovers are on the rise - and with 22% of breaches involving credential abuse, it's clear that traditional username-and-password security just isn't cutting it. The explosion of identities across cloud services, SaaS apps, and remote environments has created a perfect storm of vulnerability.

Analyst 207
Employees work on laptops in a brightly-lit office space with rows of computer workstations and technology equipment.

AI Agents Expose Security Risks in 93% of Organizations

Most organizations are unwittingly rolling out AI agents with access to sensitive tasks, leaving them vulnerable to security breaches. In fact, only 32% of teams feel very confident they could recover from exposed admin credentials, highlighting a disturbing gap in control and preparedness.

Analyst 207
Smartphone with chatbot interface on screen, conveying vulnerability.

Hackers Exploit Instagram AI Chatbot to Hijack User Accounts

Hackers recently tricked Instagram's AI chatbot into handing over account controls, highlighting a critical vulnerability in AI agent authorization - a problem that's proving tougher to crack than authentication. By falsifying user locations and manipulating the chatbot, attackers were able to change account email addresses and passwords.

Analyst 207
Ordinary office setting with interconnected devices and a central computer screen displaying a blurred network map.

Identity Exposures Form Highways for Cyber Attacks

A single compromised identity can become a superhighway for cyber attacks, giving hackers access to nearly every critical workload a business relies on - as seen in a recent incident where a cached AWS access key on one Windows machine put 98% of the company's cloud environment at risk. Identity has become the ultimate attack path, carrying with it a multitude of permissions just waiting to be exploited.

Analyst 207
Dimly lit server room with rows of humming equipment, some areas shrouded in shadows.

Enterprises Unprepared for Agent AI Risks as Identity Gaps Persist

Enterprises are rolling out Agent AI at scale, but a staggering 57% of identity elements remain unseen and unmanaged, leaving them woefully unprepared for the risks that come with it. This "identity dark matter" now outweighs visible, centrally managed elements, threatening to expose businesses to devastating consequences.

Analyst 207
Empty office cubicle with laptop and smartphone on desk, surrounded by blurred office equipment and natural light from a…

AI Agents Expose Organizations to Identity Security Risks

Most organizations are unwittingly rolling out AI agents that can open the door to identity security breaches, with 93% using or planning to use them for sensitive tasks like password resets and VPN access. Despite this, many admit that these agents create new vulnerabilities.

Analyst 207
Windows office workstations with computers and monitors in daylight-lit setting, highlighting potential vulnerabilities in…

Attackers Exploit AD CS for Stealthy Privilege Escalation

Malicious actors are exploiting weaknesses in Active Directory Certificate Services (AD CS) to secretly escalate privileges, often disguising their attacks as routine administrative actions. This stealthy tactic allows them to blend in with normal operations, making it a high-impact threat that's often under-monitored.

Analyst 207
Person sitting at desk with laptop, surrounded by office equipment and network infrastructure.

Cybersecurity Experts Push for Password Paradigm Shift

On World Password Day, cybersecurity experts are sounding the alarm: it's time to rethink our reliance on passwords, as attackers continue to exploit weak visibility and poor credential management to gain access to sensitive systems. The real vulnerability isn't a single weak password, but how credentials spread across organizations, often with employees reusing and sharing access without centralized tracking.

Analyst 207
A lone workstation glows brightly in a dimly lit server room with rows of computer servers in the background.

Identity Management Wrestles with AI-Driven Risks

The rapid evolution of Artificial Intelligence is a double-edged sword for IT leaders, bringing unprecedented opportunities for efficiency, but also sophisticated threats and complex identity management challenges. As organizations adopt autonomous digital workers, they must navigate the tension between harnessing AI's power and mitigating its risks to trust and identity.

Analyst 207
Windows computer on a desk with a laptop screen showing an authentication prompt and a nearby smartphone, in a bright…

Microsoft Bolsters Entra with Passkey Support on Windows

Say goodbye to passwords! Microsoft is bolstering Entra with passkey support on Windows, allowing users to authenticate with a face scan, fingerprint, or PIN for added security and convenience.

Analyst 207
Laptop screen shows Slack channel with plain-text password pinned amidst cluttered workspace.

Weak Passwords Expose Firms to Data Loss Risk

One careless decision - using the same easily-guessable password across multiple environments - left a client vulnerable to disaster, despite a hefty investment in security tools. A simple password like "admin123" pinned in a shared Slack channel created a single point of failure that put the entire system at risk.

Analyst 207
A lone figure stands before a shattered mirror, with a broken smartphone nearby and humming machines in the background.

Enterprises Face Identity Crisis as Machine Access Surges

As AI agents increasingly reshape enterprise operations and defenses, a new reality sets in: machine identities are surging, outnumbering human users and introducing unprecedented risks that are autonomous, fast-moving, and difficult to control. This seismic shift demands attention, as organizations scale AI and transform their attack surfaces and decision flows.

Analyst 207