Tag: identity management
69 articles

AI Agents Fuel 76% Surge in Non-Human Identities
The machines are catching up - a staggering 76% surge in non-human identities, driven by AI agents acting on our behalf, is raising critical questions about governance and control. As these machine-driven identities multiply, gaps in oversight are emerging, threatening to upend traditional operational and policy domains.

Identity Fragmentation Exposes Growing Enterprise Security Risks
As organizations scale, identities are scattering across apps, teams, and systems, creating a blind spot in centralized view and giving rise to what The Hacker News calls Identity Dark Matter. This fragmented state of modern enterprise identity is pushing IAM to the breaking point, exposing growing security risks that demand attention.

Linx Security Bolsters Identity Governance with $50M Funding
Linx Security just secured $50 million to revolutionize identity governance with an AI-native approach, closing gaps that leave organizations vulnerable to attack. With this funding, they'll scale their cutting-edge platform to automate identity management and safeguard enterprises.

NIST Unveils Critical Identity Verification Standard for Federal Workers
The National Institute of Standards and Technology (NIST) has just unveiled a groundbreaking identity verification standard to safeguard the identities of federal workers and contractors, addressing the growing threat of identity theft and cybersecurity breaches. This critical new standard is a major step forward in protecting sensitive information and preventing unauthorized access.

AI security Must-Have: Best Defense Tactics
PwC finds organizations are now prioritizing AI security over cloud and network defenses, reallocating budgets to protect models, training data and inference pipelines from novel attacks. That shift means stronger governance, adversarial testing and monitoring are needed to make AI a strategic asset rather than a new liability.

Salesforce platforms: Must-Have Critical Security Guide
The FBI just flagged active campaigns targeting Salesforce platforms—if you rely on Salesforce for customer data, now’s the time to harden access, rotate tokens, and audit integrations. Take a few simple steps today to prevent data theft, detect suspicious exports, and reduce your risk before attackers strike.

data breaches in schools: Urgent Exclusive Warning
A new ICO warning shows student hacks are increasingly exposing sensitive school data and could be training tomorrow’s cybercriminals. Schools urgently need practical security upgrades, ethics lessons and better funding to protect pupils and restore parental trust.

Active Directory: Risky Stunning Defaults Endanger Hospitals
When attackers used Kerberoasting to cripple Ascension, Senator Wyden warned Microsoft’s defaults may be putting patients at risk — sparking an FTC probe and a wider debate over vendor responsibility versus hospital readiness. It’s a wake-up call: better identity hygiene and safer out‑of‑the‑box settings could be the difference between uninterrupted care and real harm.

watering-hole technique: Exclusive Risky Exposed
When nation‑state actors like APT29 weaponize familiar conveniences — such as “Sign in with Microsoft” flows and popular websites — a routine visit can hand over credentials and session tokens at scale. Amazon’s disclosure shows watering‑hole attacks have evolved, so teams and users should treat federated logins and consent prompts with fresh skepticism and stronger protections.

Iris Experts Group Annual Meeting Highlights Latest Industry Advances
Discover how cutting-edge advances in iris recognition are strengthening national security and redefining biometric technology, as experts unite to tackle challenges and innovate the future of identity protection.

Utilizing Credentials as Distinct Identifiers: A Practical Strategy for NHI Inventories
Discover how using credentials as distinct identifiers can enhance NHI inventory management, streamlining processes and improving accuracy.

Cisco Issues Urgent Alert on Critical RCE Vulnerabilities in Identity Services Engine
Cisco warns of critical RCE vulnerabilities in Identity Services Engine, urging immediate updates to safeguard systems against potential attacks.

3 Essential Insights from the Scattered Spider Attacks on Insurance Companies
Discover 3 key insights from the Scattered Spider attacks targeting insurance companies, highlighting vulnerabilities and effective defense strategies.

Enhancing Digital Security: The Role of Customer Identity & Access Management (CIAM) in Building Trust
Discover how Customer Identity & Access Management (CIAM) enhances digital security and builds trust by safeguarding user identities and access.

Ongoing nOAuth Vulnerability Impacts 9% of Microsoft Entra SaaS Apps Two Years Later
Discover how the ongoing nOAuth vulnerability continues to affect 9% of Microsoft Entra SaaS apps two years later, posing significant security risks.

nOAuth Continues to Thrive in Cloud App Logins with Entra ID
Explore how nOAuth enhances security and user experience in cloud app logins through Entra ID, ensuring seamless access and robust authentication.

Uncovering the Overlooked Dangers in Your Entra Environment
Explore hidden risks in your Entra environment and learn how to safeguard your organization from overlooked vulnerabilities. Stay secure and informed.

Scania Acknowledges Data Breach in Insurance Claim Extortion Case
Scania confirms a data breach linked to an insurance claim extortion case, prompting concerns over data security and potential impacts on stakeholders.

Password-spraying attacks target 80,000 Microsoft Entra ID accounts
Password spraying attacks compromise 80,000 Microsoft Entra ID accounts. Explore the risks and learn strategies to secure your organization’s credentials.

NIST Publishes New Zero Trust Implementation Guidance
NIST releases updated Zero Trust implementation guidance, offering actionable best practices to enhance cybersecurity defenses.

Tackling the Security Challenges Posed by Non-Human Identities
Tackling security challenges from non-human identities using advanced strategies to safeguard digital ecosystems and ensure robust protection.

Over 80,000 Microsoft Entra ID Accounts Targeted Using Open-Source TeamFiltration Tool
Over 80,000 Microsoft Entra ID accounts face risk from the open-source TeamFiltration tool, exposing vulnerabilities to potential attackers.

AI Is Your New Coworker. Does It Need a Badge?
Discover the office revolution as AI becomes your coworker. Does it need a badge? Explore evolving work dynamics between human talent and machine intelligence.

Cyera Boosts Valuation with $540M Funding to Enhance AI-Driven Data Defense
Cyera secures $540M funding to boost its valuation and accelerate AI-driven data defense innovations for enterprise and cloud security.