Tag: identity
-
Kubernetes Attack Lets Hackers Steal SPIFFE Workload Identities and Impersonate Applications
A post-exploitation technique that lets attackers with root-level access to a Kubernetes node steal workload identities issued through SPIFFE/SPIRE and impersonate legitimate applications running on the same host. The technique undermines the node-trust assumption behind cloud-native machine identity systems, potentially enabling attackers to access services protected by mutual TLS and identity-based authorization. Palo Alto Networks…
-
U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog
Tags: api, authentication, backup, cisa, cisco, cve, cybersecurity, exploit, flaw, google, identity, infrastructure, kev, service, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acronis Backup, CiscoISE, and Google Pixelflaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-76460 is an authentication bypass vulnerability affecting an API in Cisco Identity Services Engine (ISE). The flaw…
-
Cisco warns of max severity ISE zero-day exploited in attacks
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisco-warns-of-identity-service-engine-zero-day-exploited-in-attacks/
-
Enterprise at Scale: MCP’s Emerging Identity and Governance Foundation
What Enterprise Problems Must MCP Deployments Address? Run an agent-heavy workflow inside a real organization, and you immediately hit questions that per-user, per-tool authorization fails to address: How does an agent get credentials without asking the user, especially when the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/enterprise-at-scale-mcps-emerging-identity-and-governance-foundation/
-
CISA and NIST Issue Guidance to Protect Cloud Identity Tokens
CISA and NIST issued final guidance to help protect cloud identity tokens and assertions First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cisa-nist-cloud-identity-token/
-
N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity.From there, a single compromised identity can open the door to sensitive data, business systems, and additional cloud First…
-
Smishing Triad Hackers Use JWR Phishing Kit to Steal Cards, OTPs and Bank Credentials
A large-scale SMS phishing campaign linked to the Smishing Triad is using a sophisticated phishing kit dubbed JWR to harvest payment-card data, one-time passwords, online-banking credentials, identity information, and digital-wallet logins. Group-IB attributed the activity to an operator sub-cluster tracked as Outsider, which appears to operate as a customer within the wider phishing-as-a-service ecosystem rather…
-
NIST and CISA finalize playbook to stop token theft and forgery
NIST and CISA have finalized guidelines to help federal agencies and cloud service providers (CSPs) protect identity and access tokens from forgery, theft, and misuse. The … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/16/nist-cisa-cloud-token-security-guidance/
-
NIST Issues New Guidance to Protect SSO and API Tokens From Theft and Forgery
The National Institute of Standards and Technology (NIST) has published new implementation guidance to safeguard identity tokens, access tokens, and assertions used in single sign-on, cloud federation, and application programming interface (API) environments. Released on September 15, 2026, NIST Internal Report 8587, titled >>Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for…
-
12 Best CIEM Tools Compared (2026): Features Pricing
Quick Answer: CIEM bills per identity or per cloud resource, and the count that matters is non-human identities machines outnumber people many-fold and inflate quotes fast. Tenable (Ermetic) and Wiz lead platform CIEM; Britive prices standalone JIT; CyberArk monetizes enforcement. Retirement alert: Microsoft Entra Permissions Management has been discontinued plan migrations, not renewals. Entitlement sprawl…
-
CISA Warns Hackers Exploit 17 Active Directory Techniques to Gain Control of Enterprise Networks
Tags: cisa, control, cyber, cybersecurity, defense, exploit, guide, hacker, identity, infrastructure, international, networkThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has collaborated with international partners to guide the defense of Active Directory (AD). They warn that attackers exploit 17 common techniques to gain control of identity infrastructure. The guide, released on September 15, was co-authored by the Australian Signals Directorate’s Australian Cyber Security Center, CISA, the NSA,…
-
The Hugging Face Wake-Up Call: What an Autonomous AI Attack Means for CISOs
The Hugging Face Wake-Up Call: What an Autonomous AI Attack Means for CISOs andrew.gertz@t“¦ Wed, 09/16/2026 – 01:04 Data Breach Data Security Encryption Key Management Identity & Access Management Camille Charaudeau – Global Vice President, Strategy & Innovation More About… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/the-hugging-face-wake-up-call-what-an-autonomous-ai-attack-means-for-cisos/
-
The Hugging Face Wake-Up Call: What an Autonomous AI Attack Means for CISOs
The Hugging Face Wake-Up Call: What an Autonomous AI Attack Means for CISOs andrew.gertz@t“¦ Wed, 09/16/2026 – 01:04 Data Breach Data Security Encryption Key Management Identity & Access Management Camille Charaudeau – Global Vice President, Strategy & Innovation More About… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/the-hugging-face-wake-up-call-what-an-autonomous-ai-attack-means-for-cisos/
-
The Hugging Face Wake-Up Call: What an Autonomous AI Attack Means for CISOs
The Hugging Face Wake-Up Call: What an Autonomous AI Attack Means for CISOs andrew.gertz@t“¦ Wed, 09/16/2026 – 01:04 Data Breach Data Security Encryption Key Management Identity & Access Management Camille Charaudeau – Global Vice President, Strategy & Innovation More About… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/the-hugging-face-wake-up-call-what-an-autonomous-ai-attack-means-for-cisos/
-
The Hugging Face Wake-Up Call: What an Autonomous AI Attack Means for CISOs
The Hugging Face Wake-Up Call: What an Autonomous AI Attack Means for CISOs andrew.gertz@t“¦ Wed, 09/16/2026 – 01:04 Data Breach Data Security Encryption Key Management Identity & Access Management Camille Charaudeau – Global Vice President, Strategy & Innovation More About… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/the-hugging-face-wake-up-call-what-an-autonomous-ai-attack-means-for-cisos/
-
The Hugging Face Wake-Up Call: What an Autonomous AI Attack Means for CISOs
The Hugging Face Wake-Up Call: What an Autonomous AI Attack Means for CISOs andrew.gertz@t“¦ Wed, 09/16/2026 – 01:04 Data Breach Data Security Encryption Key Management Identity & Access Management Camille Charaudeau – Global Vice President, Strategy & Innovation More About… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/the-hugging-face-wake-up-call-what-an-autonomous-ai-attack-means-for-cisos/
-
The Hugging Face Wake-Up Call: What an Autonomous AI Attack Means for CISOs
The Hugging Face Wake-Up Call: What an Autonomous AI Attack Means for CISOs andrew.gertz@t“¦ Wed, 09/16/2026 – 01:04 Data Breach Data Security Encryption Key Management Identity & Access Management Camille Charaudeau – Global Vice President, Strategy & Innovation More About… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/the-hugging-face-wake-up-call-what-an-autonomous-ai-attack-means-for-cisos/
-
The Hugging Face Wake-Up Call: What an Autonomous AI Attack Means for CISOs
The Hugging Face Wake-Up Call: What an Autonomous AI Attack Means for CISOs andrew.gertz@t“¦ Wed, 09/16/2026 – 01:04 Data Breach Data Security Encryption Key Management Identity & Access Management Camille Charaudeau – Global Vice President, Strategy & Innovation More About… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/the-hugging-face-wake-up-call-what-an-autonomous-ai-attack-means-for-cisos/
-
Crypto Agility: Digital Trust Is Becoming a Full-Time Job
Shrinking Certificates, ACME, mTLS and PQC Redefine Enterprise Security Posture Certificate lifespans are shrinking, making automated life cycle management essential. ACME is replacing manual renewal, mTLS is extending cryptographic identity across internal services, and post-quantum deadlines are approaching. Here’s how leaders can build crypto agility now. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/blogs/crypto-agility-digital-trust-becoming-full-time-job-p-4186
-
AI is now leading driver of new cybersecurity spending
AI investments are expected to help automate security operations and enhance identity and access management. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ai-leading-driver-cybersecurity-spending/830418/
-
eBook: Identity-First Threat Intelligence
Attackers increasingly bypass traditional defenses by logging in with credentials that have already been stolen, exposed, or sold on the Dark Web. As infostealer malware … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/15/enzoic-ebook-identity-first-threat-intelligence/
-
The Next Evolution of Identity: Extending IAM Across People, Machines, and AI
Services Services Tailored consulting, engineering and managed security services to meet your unique needs. Application Security Ensure all software releases are secure Ensure all software releases are secure — www.guidepointsecurity.com/application-security/ Application Security Confidently use AI to fuel organizational success. –… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/the-next-evolution-of-identity-extending-iam-across-people-machines-and-ai/
-
UK rolls out digital ID for alcohol sales
Changes to the law that will enable the retail and hospitality industry to introduce digital identity checks for alcohol sales are being rolled out First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650188/UK-rolls-out-digital-ID-for-alcohol-sales
-
AI Agent Identity and Access Control: A Framework for B2B SaaS
An AI agent needs four things human IAM does not provide: an identity of its own rather than a borrowed one, delegation semantics that keep the human’s authority visible without impersonating them, authorization scoped to a task rather than a… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/ai-agent-identity-and-access-control-a-framework-for-b2b-saas/
-
Hackers Turn Windows Shadow Copies Into a Tool for Credential Theft and Ransomware
Threat actors are increasingly weaponizing Microsoft’s Volume Shadow Copy Service (VSS) for two distinct objectives: removing recovery options before ransomware deployment and extracting credential material from protected Windows files. The shift means VSS telemetry should no longer be treated as a simple backup or disk-maintenance event, but as behavior requiring process, identity, and endpoint context.…
-
Assume Breach Must Now Mean Assume Impersonation
‘Assume breach’ is a useful operating principle for enterprise security: Build as if an attacker will eventually get past the perimeter. That mindset led teams to adopt Zero Trust, stronger endpoint controls, network segmentation, and tighter identity and access management. The premise… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/assume-breach-must-now-mean-assume-impersonation/
-
Detecting OAuth consent phishing in Microsoft 365 audit logs
OAuth consent phishing is a practical identity attack that abuses the trust users place in application consent prompts. Instead of stealing a password directly, the attacker persuades a user to grant a malicious app access to mailbox data, profile information,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/detecting-oauth-consent-phishing-in-microsoft-365-audit-logs/
-
153 Million Driver’s Licenses for Sale: Why Identity Verification Is Broken
A reported dark-web service offering more than 153 million U.S. and Canadian driver’s-license scans for sale has brought the hidden cost of identity verification into focus. Tom, Scott, and Kevin discuss the alleged breach and FBI inquiry, why a license… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/153-million-drivers-licenses-for-sale-why-identity-verification-is-broken/

