Tag: identity
-
Stop Building a 2003 SOC with AI: Local Context, Failure Modes and Your Path (Part 3)
In Part 1 of this series, we dumped a pile of uncomfortable questions on you and promised answers. In Part 2 of the series, we talked about why 1990s-2000s alert triage must die. The core thesis, if you recall: if you add AI agents into a legacy, swivel-chair SOC structure, you are essentially building a robotic…
-
Secrets Management in the Age of AI: Why Vaults Fall Short and What Replaces Them
Machine identities now outnumber human ones 109 to 1, and four 2026 acquisitions worth $26.6B prove vaults can’t keep up. What ephemeral secrets and workload identity replace them with. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/secrets-management-in-the-age-of-ai-why-vaults-fall-short-and-what-replaces-them/
-
88 ID Verification Breaches Show the Cost of Collecting Identity Data
88 ID-verification breaches exposed billions of records, highlighting the growing risks of collecting sensitive identity and biometric data. A new report from Mysterium VPN compiles 88 documented incidents since 2011 where data collected specifically to verify someone’s identity or age got breached, exposed, or sold. The confirmed and researcher-verified total sits at 2.15 billion records,…
-
CISA Red Team Achieves Full Domain Compromise Across Critical Infrastructure Networks
CISA’s latest red team assessment shows how common failures in Active Directory, cloud identity, and SOC processes can turn a phishing foothold into an enterprise-wide compromise. The August 25 advisory contrasts two critical-infrastructure organizations: one missed the intrusion entirely, while the other contained initial access quickly but still exposed major identity and cloud security weaknesses.…
-
Can You Hear Me Now? Show Me Your Papers
The FCC’s proposed phone-service KYC rules could reduce fraud but also turn mobile numbers into identity-linked credentials with major privacy implications. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/can-you-hear-me-now-show-me-your-papers/
-
Anthropic Expands Claude MCP Security With Enterprise-Managed Identity Controls
Anthropic has expanded Claude Enterprise’s Model Context Protocol (MCP) security capabilities with enterprise-managed authorization, allowing organizations to centrally provision and govern connector access through their identity provider (IdP). The feature, now generally available, removes the need for individual users to authorize each MCP connector after an administrator enables it. Instead, administrators can authorize a connector…
-
Anthropic Expands Claude MCP Security With Enterprise-Managed Identity Controls
Anthropic has expanded Claude Enterprise’s Model Context Protocol (MCP) security capabilities with enterprise-managed authorization, allowing organizations to centrally provision and govern connector access through their identity provider (IdP). The feature, now generally available, removes the need for individual users to authorize each MCP connector after an administrator enables it. Instead, administrators can authorize a connector…
-
Critical Red Hat Keycloak Password Reset Flaw Enables Unauthenticated Account Takeover
Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that allows an unauthenticated remote attacker to bypass a key safeguard in the password reset process and seize control of arbitrary user accounts. Tracked as CVE-2026-18963, the flaw affects the keycloak-services component, the core identity and access management engine behind the…
-
KI-Agenten absichern: Warum Identity zum Erfolgsfaktor wird KI braucht Identity Governance
KI-Agenten versprechen Unternehmen mehr Tempo und Automatisierung, schaffen aber zugleich neue Sicherheitsrisiken. Entscheidend ist deshalb, nicht nur ihre Funktionen, sondern vor allem ihre Identitäten, Berechtigungen und Zugriffe konsequent zu steuern. Wer Identity Governance früh verankert, kann Innovation ermöglichen, ohne Kontrolle und Compliance aus der Hand zu geben. First seen on ap-verlag.de Jump to article: ap-verlag.de/ki-agenten-absichern-warum-identity-zum-erfolgsfaktor-wird-ki-braucht-identity-governance/107027/
-
Gateways, Registries, Policy Engines und Visibility-Plattformen Identity Security als Schlüssel für sichere AI-Agenten
Warum AI nur dann sicher skaliert, wenn jede maschinelle Identität, vom Agenten bis zur MCP-Verbindung, von Anfang an verwaltet wird. First seen on ap-verlag.de Jump to article: ap-verlag.de/gateways-registries-policy-engines-und-visibility-plattformen-identity-security-als-schluessel-fuer-sichere-ai-agenten/106990/
-
Does AI Create New Cybersecurity Risks? What Actually Changes
<div cla AI does not create new attack vectors. It accelerates the ones that already dominate most risk registers. Code exploitation, injection, credential and identity abuse, phishing, and misconfiguration are the same vectors security teams tracked before generative AI reached the enterprise. What changed is how quickly they can be found and exploited, and the…
-
Does AI Create New Cybersecurity Risks? What Actually Changes
<div cla AI does not create new attack vectors. It accelerates the ones that already dominate most risk registers. Code exploitation, injection, credential and identity abuse, phishing, and misconfiguration are the same vectors security teams tracked before generative AI reached the enterprise. What changed is how quickly they can be found and exploited, and the…
-
Interview mit Nexis Warum Identity heute nicht mehr isoliert betrachtet werden kann
Identity & Access-Management (IAM) steht vor einem grundlegenden Wandel. Im Remote-Interview mit Dr. Heiko Klarl, CEO bei Nexis, geht es um die Frage, warum Unternehmen mehr brauchen als klassische IGA-Tools. Nexis verfolgt dabei einen Ansatz, der bestehende Lösungen wie SailPoint, Saviynt oder One Identity nicht einfach ersetzen, sondern erweitern und intelligenter verknüpfen soll. Ein zentraler…
-
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset.The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system…
-
The Visibility Paradox: Why “We Can See Our Identity Risk” Is the Most Dangerous Sentence in Security
Identity visibility means little if security teams cannot quickly map the blast radius of a compromised account, prioritize its business impact and shut down dangerous access paths. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-visibility-paradox-why-we-can-see-our-identity-risk-is-the-most-dangerous-sentence-in-security/
-
The Network Access Debt AI Is Making Harder to Ignore
Tags: access, ai, cloud, cybersecurity, detection, endpoint, identity, network, threat, vulnerability, vulnerability-managementFor the last decade, cybersecurity has responded to an evolving threat landscape by adding new layers of defense. Organizations invested in endpoint security, identity, cloud security, vulnerability management, detection and… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-network-access-debt-ai-is-making-harder-to-ignore/
-
What Happens to Your Digital Life When You Die?
Scott Wright joins Shared Security to discuss his Digital Legacy Tree framework and upcoming book, The Digital Legacy Tree. We talk about what happens to your accounts, passwords, devices, files, money, cloud storage, crypto, and online identity if you die, become incapacitated, or are suddenly unavailable, and how to plan for trusted access without… First…
-
Secure AI agent identity in private cloud and hybrid environments
First seen on scworld.com Jump to article: www.scworld.com/native/secure-ai-agent-identity-in-private-cloud-and-hybrid-environments
-
Microsoft patches flaw in Entra ID identity software
First seen on scworld.com Jump to article: www.scworld.com/news/microsoft-patches-flaw-in-entra-id-identity-software
-
Google Tightens Android Sideloading: Unverified Apps Now Face a 24-Hour Wait
Google’s new Android verification flow adds a 24-hour wait for apps from unverified developers as broader identity checks approach. The post Google Tightens Android Sideloading: Unverified Apps Now Face a 24-Hour Wait appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-android-sideloading-24-hour-wait/
-
Microsoft patches max severity code execution, privilege escalation flaws
Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-max-severity-entra-id-flaw-exploited-in-attacks/
-
Machine Identity for the AI Era: Building Doppel API V2 With OAuth 2.0
How we introduced organization-bound machine authentication while preserving the API contract customers already know. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/machine-identity-for-the-ai-era-building-doppel-api-v2-with-oauth-2-0/
-
Don’t Lose Sight of the Fundamentals of Privileged Access Management
There’s a lot of discussion in privileged access management (PAM) and identity security right now about AI agents, non-human identities and machine identities. And there should be. These identities are growing exponentially; they’re going to have significant levels of access, and we need to think differently about how we control and monitor that access. But we need to be careful not to get too……
-
Is Online Privacy Possible? How Digital Identities Can Help
Using the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to profile your activity. Anonyome Labs explains how separate digital personas can reduce correlation and limit the impact of breaches, spam, and identity theft. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/is-online-privacy-possible-how-digital-identities-can-help/
-
Microsoft warns of max severity Entra ID flaw exploited in attacks
Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-max-severity-entra-id-flaw-exploited-in-attacks/
-
Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution
Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required.The vulnerability, tracked as CVE-2026-69836 (CVSS score: 10.0), is a case of remote code execution impacting the tech giant’s cloud-based identity and access management service. It was…
-
The Elephants in the Technology Room – Part 5
Why Enterprise’s Fastest-Growing Risk Has No Owner, No Identity and No Audit Trail As autonomous AI agents move into production, organizations face a new insider threat they were never built to govern. Shared credentials, weak oversight and limited audit trails leave agents without clear identities or accountability, creating security blind spots that can quickly become…

