Tag: identity management
69 articles

Identity Fabric Emerges as Key to Modernizing Enterprise Identity Security
In today's complex hybrid and multi-cloud environments, an Identity Fabric weaves together disparate identity systems, providing a unified layer of visibility into how identities interact across applications, APIs, and infrastructure. By bridging the gap between access intent and runtime execution, it shines a light on hidden risks and vulnerabilities, eliminating the identity dark matter that attackers exploit.

Keycloak Flaw Exposes Accounts to Unauthenticated Takeover
A critical flaw in Keycloak, rated 9.1 by Red Hat, allows hackers to hijack any account, including admin ones, by manipulating the password reset process. This vulnerability, CVE-2026-18963, lets attackers take control without even logging in.

Thousands of Leaked AWS Keys Remain Active
A recent scan by Truffle Security uncovered a staggering 9,300+ active AWS keys that were leaked online, including hundreds with full administrative rights, putting sensitive data at risk. These compromised keys were found across various public platforms, with a shocking 88% still authentic and vulnerable to exploitation.

AWS Security Quarantine Policy Falls Short Against Credential Abuse
Leaking AWS credentials can lead to a staggering 99% increase in your bill - but a recent finding by Truffle Security reveals that even AWS' Quarantine Policy may not be enough to stop the damage, with hundreds of leaked root keys still active. This alarming discovery highlights the urgent need for tighter security measures to prevent credential abuse.

Microsoft patches exploited Entra ID flaw amid rising attacks
Microsoft has patched a critical vulnerability in its Entra ID platform, known as CVE-2026-69836, which allowed attackers to execute code remotely with ease, and has already been exploited in recent attacks. This flaw enabled unauthorized threat actors to gain control and wreak havoc, making swift action crucial to prevent further damage.

Identity Takes Center Stage in Cybersecurity as Threats Evolve
In today's evolving threat landscape, protecting identity has become the top priority in cybersecurity - treat it like the crown jewels, because it is. By prioritizing identity protection and having a plan in place to recover quickly, organizations can safeguard the foundation of every mission.

NVIDIA Launches Open Secure AI Alliance to Share Threat-Detecting Tech
Join the Open Secure AI Alliance, a groundbreaking coalition of 37 industry leaders, as they revolutionize AI security by sharing cutting-edge threat-detecting technologies and collaborative defense strategies. Together, they're breaking down silos to safeguard the future of AI and software development.

AI Agents Expose Growing Enterprise Attack Surface
The rapid proliferation of AI agents in enterprise environments - up 466.7% in just one year - has created a massive, high-value target for cybercriminals, with these AI identities often being granted privileged access to core systems. This surge in AI adoption has significantly expanded the enterprise attack surface, making it a prime time for cyber threats to exploit these new vulnerabilities.

Microsoft Entra ID Shifts to Passkey Authentication Default
Microsoft is shaking things up with its Entra ID service by making passkey authentication the default method starting September 2026, and users currently relying on SMS or voice authentication will be automatically transitioned to passkeys. By February 1, 2027, SMS and voice authentication will be phased out, marking a significant shift towards more secure passkey technology.

Varonis Launches Breach at the Beach, a Hands-On Entra ID Training Experience
Get ready to dive into the world of Entra ID with Varonis' immersive Breach at the Beach training experience, where you'll learn to navigate the complex control plane that connects users, applications, and AI-powered workflows. Discover how to defend against threats that exploit non-human identities and automate breaches.

Agentic AI's Identity Crisis Leaves Security Teams Vulnerable
Agentic AI's autonomy and poorly tracked access are creating a perfect storm of identity risk, leaving security teams vulnerable to attacks. As digital actors with broad permissions, these AI agents are operating in the dark, with many organizations lacking visibility into their actions.

AI Agents Emerge as Unchecked Identities in Enterprise Security
The equation for enterprise security is no longer simple: with AI agents now connected to critical business services, controlling identities is no longer enough to control risk. These emerging insiders have quietly become privileged - and potentially invisible - attack paths that security and identity programs must urgently address.

Account Takeovers Rise as Complexity Exposes Identity Vulnerabilities
As attackers increasingly target identities rather than infrastructure, account takeovers are on the rise - and with 22% of breaches involving credential abuse, it's clear that traditional username-and-password security just isn't cutting it. The explosion of identities across cloud services, SaaS apps, and remote environments has created a perfect storm of vulnerability.

AI Agents Expose Security Risks in 93% of Organizations
Most organizations are unwittingly rolling out AI agents with access to sensitive tasks, leaving them vulnerable to security breaches. In fact, only 32% of teams feel very confident they could recover from exposed admin credentials, highlighting a disturbing gap in control and preparedness.

Hackers Exploit Instagram AI Chatbot to Hijack User Accounts
Hackers recently tricked Instagram's AI chatbot into handing over account controls, highlighting a critical vulnerability in AI agent authorization - a problem that's proving tougher to crack than authentication. By falsifying user locations and manipulating the chatbot, attackers were able to change account email addresses and passwords.

Identity Exposures Form Highways for Cyber Attacks
A single compromised identity can become a superhighway for cyber attacks, giving hackers access to nearly every critical workload a business relies on - as seen in a recent incident where a cached AWS access key on one Windows machine put 98% of the company's cloud environment at risk. Identity has become the ultimate attack path, carrying with it a multitude of permissions just waiting to be exploited.

Enterprises Unprepared for Agent AI Risks as Identity Gaps Persist
Enterprises are rolling out Agent AI at scale, but a staggering 57% of identity elements remain unseen and unmanaged, leaving them woefully unprepared for the risks that come with it. This "identity dark matter" now outweighs visible, centrally managed elements, threatening to expose businesses to devastating consequences.

AI Agents Expose Organizations to Identity Security Risks
Most organizations are unwittingly rolling out AI agents that can open the door to identity security breaches, with 93% using or planning to use them for sensitive tasks like password resets and VPN access. Despite this, many admit that these agents create new vulnerabilities.

Attackers Exploit AD CS for Stealthy Privilege Escalation
Malicious actors are exploiting weaknesses in Active Directory Certificate Services (AD CS) to secretly escalate privileges, often disguising their attacks as routine administrative actions. This stealthy tactic allows them to blend in with normal operations, making it a high-impact threat that's often under-monitored.

Cybersecurity Experts Push for Password Paradigm Shift
On World Password Day, cybersecurity experts are sounding the alarm: it's time to rethink our reliance on passwords, as attackers continue to exploit weak visibility and poor credential management to gain access to sensitive systems. The real vulnerability isn't a single weak password, but how credentials spread across organizations, often with employees reusing and sharing access without centralized tracking.

Identity Management Wrestles with AI-Driven Risks
The rapid evolution of Artificial Intelligence is a double-edged sword for IT leaders, bringing unprecedented opportunities for efficiency, but also sophisticated threats and complex identity management challenges. As organizations adopt autonomous digital workers, they must navigate the tension between harnessing AI's power and mitigating its risks to trust and identity.

Microsoft Bolsters Entra with Passkey Support on Windows
Say goodbye to passwords! Microsoft is bolstering Entra with passkey support on Windows, allowing users to authenticate with a face scan, fingerprint, or PIN for added security and convenience.

Weak Passwords Expose Firms to Data Loss Risk
One careless decision - using the same easily-guessable password across multiple environments - left a client vulnerable to disaster, despite a hefty investment in security tools. A simple password like "admin123" pinned in a shared Slack channel created a single point of failure that put the entire system at risk.

Enterprises Face Identity Crisis as Machine Access Surges
As AI agents increasingly reshape enterprise operations and defenses, a new reality sets in: machine identities are surging, outnumbering human users and introducing unprecedented risks that are autonomous, fast-moving, and difficult to control. This seismic shift demands attention, as organizations scale AI and transform their attack surfaces and decision flows.