Tag: identity
-
What the Minnesota Water Attacks Reveal About Securing Remote Access to Critical Infrastructure
Tags: access, ai, attack, authentication, cisa, control, corporate, credentials, cyberattack, data-breach, exploit, Hardware, identity, infrastructure, Internet, law, least-privilege, malware, mfa, monitoring, network, password, risk, router, supply-chain, technology, vpn, zero-day, zero-trustWhen headlines break about cyberattacks targeting critical infrastructure, the conversation often turns immediately to zero-day exploits, advanced malware, and other sophisticated techniques. The recent attacks on municipal water systems across at least seven US states, including more than 30 Minnesota water and wastewater utilities, illustrate why this assumption can be misleading. As a “recovering CISO” who…
-
Grip AI Security Platform First AI Security
Discover the Grip AI Security Platform. Gain visibility into AI applications, agents, identities, and permissions with identity-first AI governance. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/grip-ai-security-platform-identity-first-ai-security/
-
Non-human identity (NHI) programs stall on detection, not policy
First seen on scworld.com Jump to article: www.scworld.com/perspective/non-human-identity-nhi-programs-stall-on-detection-not-policy
-
When AI Hackers Meet Machine Identity: The Ignored Attack Surface
The Salesloft Drift breach hit 700+ companies with stolen OAuth tokens and never touched a password. Machine identities now outnumber humans 80 to 1, and AI-powered attackers are harvesting them at machine speed. Here is why human-shaped IAM cannot protect AI agents, and what to fix in 90 days. First seen on securityboulevard.com Jump to…
-
Okta übernimmt Permiso Security und erweitert seine Identity Threat Detection
Okta übernimmt Permiso Security und erweitert seine Plattform um Funktionen zur Erkennung und Abwehr von Identitätsbedrohungen in Cloud- und KI-Umgebungen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/okta-uebernimmt-permiso-security-und-erweitert-seine-identity-threat-detection/a45972/
-
HackerOne Mandates ID Verification Before Bug Bounty Report Submissions
HackerOne has rolled out a significant policy change requiring all hackers to complete identity verification before submitting reports to Bug Bounty Programs (BBPs). The update, effective immediately, aims to strengthen platform integrity and meet regulatory compliance requirements for reward payments. Under the new policy, hackers must verify their identity before becoming eligible for any bounty…
-
Okta Buys Permiso to Extend ITDR Beyond Native Identity Logs
Customers Gain Broader Identity Telemetry Across Cloud and Directory Services. Okta said its planned acquisition of Permiso will expand identity threat detection beyond native Okta telemetry by adding thousands of risk signals, AI agent security capabilities and graph-based correlation that combines identity exposures with active threats to improve detection and response. First seen on govinfosecurity.com…
-
eSecurityPlanet Podcast: Semperis Global Field CTO Marty Momdjian
Identity systems sit at the center of enterprise security, but they are also one of the first places attackers look when launching ransomware and other disruptive cyberattacks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/video/esecurityplanet-podcast-semperis-global-field-cto-marty-momdjian/
-
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators.Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019.The…
-
USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports
The organization behind Team USA’s Olympic/Paralympic fencing teams has automated identity verification to handle growing membership, cutting manual review time while ensuring athletes compete in the correct categories. First seen on darkreading.com Jump to article: www.darkreading.com/identity-access-management-security/usa-fencing-hidden-identity-challenge-amateur-sports
-
How SSO and SCIM help ad monetization platforms scale
Learn how SSO, SCIM, RBAC, MFA, and tenant isolation help ad monetization platforms scale securely while meeting enterprise identity requirements. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/07/how-sso-and-scim-help-ad-monetization-platforms-scale/
-
The Identity Mesh: Federated Trust for Multi-Agent AI
Agents can already prove who they are. What no standard has cleanly solved is passing scoped authority down a multi-hop chain across organizations. Here is the real state of agent identity in 2026, minus the blockchain hype. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/07/the-identity-mesh-federated-trust-for-multi-agent-ai/
-
AiTM Phishing Becomes Top Initial Access Threat to Law Firms
AiTM phishing is now the top entry point into law firms, with identity behind 56% of threats First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/aitm-phishing-top-entry-point-law/
-
Okta’s deal for Permiso aims to close gaps in identity threat detection
Ely Kahn, Okta’s chief product officer, told CyberScoop the deal enriches the company’s current threat detection tools and gives it deeper visibility into AI agent activity across enterprise systems. First seen on cyberscoop.com Jump to article: cyberscoop.com/okta-acquires-permiso-security-ai-identity-threat-detection/
-
Okta buys AI security startup Permiso, source says for about $200M
The deal gives Okta identity threat detection capabilities as enterprises seek to secure AI agents and other non-human identities across cloud environments. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/30/okta-buys-ai-security-startup-permiso-source-says-for-about-200m/
-
1Password CEO: AI Spending Needs Identity-Based Governance
Human Oversight Remains Essential as AI Spending Accelerates Across Enterprises. 1Password CEO David Faugno says enterprises need identity-driven AI governance that connects users, models, spending and business outcomes while enforcing budget controls, human oversight and zero-standing privilege to improve security and demonstrate measurable return on AI investments. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/1password-ceo-ai-spending-needs-identity-based-governance-a-32351
-
Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
Security researcher Aleksandr Krasnov reveals dormant non-human identities can create security blind spots and releases NHI Hound, an open source tool to sniff out trust paths. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/non-human-identity-sprawl-creates-a-new-cloud-attack-path
-
Your Money Was Never the Target. Your Identity Was
Identity Theft, Not Transaction Systems, Now Drives the Biggest Banking Fraud Risks Bank of Baroda’s recent breach shows why core systems unaffected is no longer enough. While transactions remained secure, leaked KYC data can fuel mule accounts, synthetic identity fraud and account takeovers, making customer identity – not banking infrastructure – the real target. First…
-
Aembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent Interoperability
Silver Spring, MD, USA, July 28th, 2026, CyberNewswire To reduce identity risk when third-party AI agents access business systems, Aembit is launching a new integration with Snowflake to help enterprises securely govern third-party agents across platforms. Aembit, the identity and access management company for agentic AI, today announced a new integration with Snowflake, the AI…
-
5 Things To Know About Cyera’s Deal To Acquire Oasis Security
Tags: identityCyera announced Tuesday it has reached an agreement to acquire Oasis Security, a specialist in non-human identity security, in a deal reportedly valued at $1 billion. First seen on crn.com Jump to article: www.crn.com/news/security/2026/5-things-to-know-about-cyera-s-deal-to-acquire-oasis-security
-
Is Your SSO Protected Against Modern Credential Attacks?
A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure modern SSO environments and the applications they protect. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/is-your-sso-protected-against-modern-credential-attacks/
-
Phishing the agent: Why identity controls are essential to secure and manage AIs
First seen on scworld.com Jump to article: www.scworld.com/resource/phishing-the-agent-why-identity-controls-are-essential-to-secure-and-manage-ais
-
Keyfactor expands partner program for machine identity and post-quantum services
First seen on scworld.com Jump to article: www.scworld.com/news/keyfactor-expands-partner-program-for-machine-identity-and-post-quantum-services
-
Keyfactor Expands Into AI Agent Identity With Cofide Deal
Deal Extends Certificate-Based Trust Framework to AI Agents and Software Workloads. Cleveland-based Keyfactor plans to acquire London-based startup Cofide to expand its trust platform into software workloads and autonomous AI agents, betting enterprise demand for dynamic, standards-based machine identities will accelerate as AI adoption grows. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/keyfactor-expands-into-ai-agent-identity-cofide-deal-a-32331
-
What the identity attack surface looks like when trust becomes the target
In this Help Net Security video, Joel Moses, VP, Strategic Engineering at F5, explains how attackers use identity instead of breaking through it. He walks through MFA fatigue, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/27/identity-attack-surface-video/
-
IdP Dependency Mapping: How to Find Your Identity Single Points of Failure
Tags: identityFirst seen on scworld.com Jump to article: www.scworld.com/tech-explainer/idp-dependency-mapping-how-to-find-your-identity-single-points-of-failure
-
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
Microsoft addressed a public-by-default configuration and chain of code flaws in Azure Automation which could have let attackers seize another tenant’s identity and access other tenants’ data, credentials, and cloud workloads. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/default-azure-automation-setting-cross-tenant-identity-takeover
-
Meta tackles AI-generated accounts with a free Facebook verification badge
Meta has introduced Facebook Verified, a free badge meant to show that a person behind a profile has completed identity verification through a selfie check. (Source: Meta) The … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/24/meta-facebook-verified-badge-selfie-verification/
-
Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos
An Illinois man has pleaded guilty to a phishing and account-compromise scheme that targeted thousands of Snapchat users, leading to the theft of private images from numerous women. Federal prosecutors stated that Kyle Svara, 27, of Oswego, Illinois, admitted to charges including aggravated identity theft, wire fraud, computer fraud, conspiracy to commit computer fraud, and…
-
Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we’ve collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so many approaches, from prompt filtering to identity-layer access controls. Where we’ve collectively landed is…

