News
- Aug 29, 2026Amazon says 175 million customers now sign in with passkeys
Amazon reports more than 175 million customers have enabled passkeys, signing in six times faster, with passkeys now the default on mobile for anyone who has set one up. The FIDO Alliance counts five billion passkeys in use industry-wide.
- Aug 28, 2026McKesson breach started with vishing against Okta SSO, then reached Salesforce and Snowflake
ShinyHunters social-engineered McKesson employees from a lookalike domain, took their Okta credentials, and used the SSO session to reach Salesforce and Snowflake. The group claims roughly 284 million records and demanded 55 million dollars.
- Aug 28, 2026Two PaperCut flaws chain into unauthenticated code execution, and the patch has bypasses
CVE-2026-81578 bypasses authentication on the PaperCut web management interface, and CVE-2026-82078 turns a config edit into remote code execution. Exploitation started August 27, and new bypasses affect fully patched instances.
- Aug 27, 2026Integrity360 buys CyberIAM, betting that identity services are the control plane
Integrity360 acquired UK and South Africa identity specialist CyberIAM on August 27, 2026, adding roughly 120 practitioners and 18 million euros of revenue across IAM, IGA, PAM, and CIAM delivery. Terms were not disclosed.
- Aug 26, 2026A phishing kit rents an AI voice agent to call theft victims and ask for their 2FA code
SOCRadar documented AnonyMousKIT, a phishing-as-a-service platform built to strip Apple Activation Lock. An AI persona called Alice from Apple Support phones victims in three languages and asks for the device passcode, Apple ID, and a live two-factor code, at roughly ten cents a call.
- Aug 25, 2026A loose PHP comparison let attackers sign in as WordPress admin through SAML
Two unauthenticated bypasses in the miniOrange SAML 2.0 Single Sign On plugin, CVE-2026-61979 and CVE-2026-15981, treat OpenSSL's error return as a valid signature. Both are under active exploitation.
- Aug 25, 2026Mirage2FA reached 4,500 organizations by stealing sessions instead of breaking MFA
ANY.RUN traced the Mirage2FA phishing-as-a-service kit across 4,532 organization domains from 2024 to 2026. It abuses legitimate Microsoft 365 login flows to lift passwords and session cookies, then rides the authenticated session into every SSO-connected app.
- Aug 25, 2026WhatsApp lets one account hold several passkeys, closing the cross-platform gap
Meta announced on August 25, 2026 that WhatsApp accounts can register multiple passkeys, so a user carrying both iOS and Android no longer has to bind to one ecosystem. Two-step verification also moves from a six-digit PIN to a full password.
- Aug 24, 2026Keycloak password reset flaw let anyone skip the email token and take over any account
CVE-2026-18963 is improper state validation in Keycloak's reset-credentials flow. A crafted request jumped the authentication session straight to the password-update step, no verification token needed. CVSS 9.1, fixed in 26.7.2.
- Aug 24, 2026Okta ships Agent SSO, making AI agents first-class identities instead of static API keys
Okta made Agent SSO generally available on August 24, 2026, registering AI agents in Universal Directory with short-lived governed tokens and pushing Cross App Access into the Model Context Protocol as its enterprise authorization extension.
- Aug 21, 2026Microsoft patched a CVSS 10.0 Entra ID flaw, then corrected the exploitation flag from yes to no
CVE-2026-69836 was an unauthenticated deserialization flaw in Entra ID scoring a perfect 10.0. Microsoft fixed it service-side with no customer action, but first published it marked as exploited, then reversed that a day later.
- Aug 21, 2026Poisoned Rust crates turned routine builds into credential theft for about 90 minutes each
Malicious versions of arrayref, internment, and append-only-vec shipped an infostealer targeting browser profiles and crypto wallets. crates.io pulled them within two hours, but lockfiles and registry caches keep them around.
- Aug 21, 2026Three Russian clusters move from password phishing to OAuth token theft
Google Threat Intelligence Group tracked UNC6293, UNC7005, and UNC5976 abusing device-code flow, verification-code relay, and fake Continue with Google pages to take authenticated sessions rather than passwords.
- Aug 19, 2026NetScaler ships a critical authentication bypass affecting Gateway and AAA virtual servers
CVE-2026-19490 (CVSS 9.3) bypasses authentication on NetScaler ADC and Gateway appliances running a Gateway or AAA virtual server, with a SAML action configured on current builds. Fixed in 14.1-73.32 and 13.1-63.21.
- Aug 19, 2026Operation CameraSwarm compromised 14,500 Dahua devices, mostly by guessing passwords
Hunt.io found an exposed operator directory documenting 14,530 compromised Dahua cameras over five weeks. Password attacks from 12,324 IPs did most of the work; two 2021 auth bypasses accounted for 1,923.
- Aug 18, 2026An MLflow SSRF reaches cloud metadata services, and scanning started within hours
CVE-2026-64849 (CVSS 9.3) abuses MLflow's model-registry webhooks to proxy requests into internal services, including cloud metadata endpoints that hand out credentials. Fixed in 3.15.0; exploitation began the day of assignment.
- Aug 14, 2026RecruitTrap ran 3,000 fake recruitment logins with browser-in-the-browser popups and live MFA relay
CTM360 found over 3,000 phishing URLs impersonating recruiters at 50-plus organizations across 14 sectors. The pages fake a browser window, complete with address bar and padlock, and relay MFA codes in real time.
- Aug 14, 20261.6 million RingCentral records leaked, and the entry point was one phone call
ShinyHunters voice-phished a RingCentral employee out of their password in July, took 623GB, and dumped 280GB after the company refused to pay. Have I Been Pwned confirmed 1.6 million accounts including names, emails, phone numbers and addresses.
- Aug 13, 2026Fortinet's January SSO bypass hit boxes already patched for December's SAML bug
CVE-2026-24858 is the follow-on FortiCloud SSO SAML bypass. Devices patched for CVE-2025-59718 and 59719 were still exploitable. Actively exploited. CISA guidance 28 January 2026.
- Aug 13, 2026KerberLoss: invisible Unicode lets an attacker twin a Kerberos SPN
CVE-2026-25177, CVSS 8.8. Active Directory treated look-alike SPNs as unique. Semperis and Shai Laron showed how that becomes service hijack and NTLM downgrade. Patched March 2026.
- Aug 13, 2026ResetNightmare: a low-priv UPN write can reset a Domain Admin via Kerberos kpasswd
CVE-2026-27912 lets a user who can write their own UPN aim a Kerberos change-password at a Domain Admin. Microsoft rated it Important. Identity teams should not.
- Aug 13, 2026SharePoint JWT bypass went from proof of concept to exploitation in under 48 hours
Rapid7 published a working PoC for CVE-2026-55040 in mid-August. Exploitation telemetry spiked from one attempt to eight the following day, from eight IPs across five countries. Microsoft patched it in July.
- Aug 11, 2026GhostSplice splits a malicious instruction across MCP tool calls, and refusal rates go to zero
ASSET Research Group fragmented an exfiltration request across MCP channels so no single piece looked malicious. Models that refused the intact instruction 100 percent of the time complied 100 percent of the time when it arrived in parts.
- Aug 10, 2026Three passkey attacks land in one week, none of them breaking the cryptography
SpecterOps, Unit 42, and Dirk-jan Mollema each demonstrated ways to defeat passkey protections without attacking WebAuthn itself, through cleartext event logs, Chrome sync key recovery, and in-session key reuse.
- Aug 8, 2026A CVSS 10.0 Metabase zero-day handed admin access through the password reset endpoint
CVE-2026-72898 lets an unauthenticated attacker inject SQL through Metabase's password reset endpoint and take administrative control. It was exploited as a zero-day around August 2, 2026 and added to CISA KEV on August 11.
- Aug 7, 2026Opening a GitHub issue was enough to reach CI secrets in Claude Code and Gemini CLI
Novee Security showed at Black Hat that an unprivileged GitHub user could open an issue that reached workflow credentials on the coding-agent repositories of Anthropic, Google, and OpenAI. Fixes shipped in Gemini CLI 0.39.1 and Claude Code 2.1.163.
- Aug 7, 2026Over 1,000 AI-named npm typosquats deliver a cross-platform dropper
OpenSourceMalware and Sonatype tracked Flooding Dropper, a campaign of AI-generated typosquat package names carrying WEL1DROPPER, which fetches Sliver on Linux and encrypted payloads on Windows and macOS.
- Aug 7, 2026N-able confirms attackers used an N-central auth bypass to reach managed customer networks
CVE-2026-18577 gave unauthenticated attackers full administrative control of N-central, which they used through the Take Control feature to reach downstream managed endpoints and plant Cloudflare Tunnels for persistence. A second mandatory hotfix landed August 7.
- Aug 7, 2026Malware can drive a Windows Hello key for Entra ID persistence without a PIN prompt
Dirk-jan Mollema showed that code running in a signed-in Windows session can use the victim's TPM-bound Windows Hello for Business key as a FIDO2 credential, satisfying phishing-resistant Conditional Access and acquiring a Primary Refresh Token. No admin rights, no CVE.
- Aug 6, 2026The Snowflake attacker pleaded guilty, two years after stale credentials did the work
Connor Riley Moucka pleaded guilty in Seattle federal court on August 6, 2026 to computer fraud, wire fraud, aggravated identity theft, and conspiracy over the 2024 Snowflake customer breaches, which reached at least 165 organizations and 100 million people.
- Aug 5, 2026Kali365 phishes Microsoft's own device login page for durable Microsoft 365 tokens
ANY.RUN documented Kali365, a kit that lures victims through fake SharePoint, OneDrive, and DocuSign pages to Microsoft's genuine device login portal, where approving an attacker-supplied code hands over access and refresh tokens.
- Aug 5, 2026GitGuardian found 4,576 leaked n8n tokens, and a third of reachable instances accepted them
Exposed n8n API tokens in public GitHub commits gave researchers read access to workflows, stored credentials, and data tables, plus a path to exfiltrate the raw secrets of every connected service.
- Aug 5, 2026Pass-the-Passkey: a Black Hat researcher found the WebAuthn implementation bugs, not the standard
At Black Hat USA 2026, DSInternals researcher Michael Grafnetter presented a family of passkey attacks including cleartext YubiKey signatures readable by any authenticated user and a major cloud passkey implementation vulnerable to the exact attack it was built to stop.
- Aug 5, 2026A CVSS 10.0 bug let one user's Terraform token serve another user's request
HashiCorp's Terraform MCP Server failed to assign unique session identifiers in stateless HTTP mode, so a token supplied by one user could be reused for later requests from others. Veeam and Django patched serious flaws the same week.
- Aug 4, 2026CrowdStrike's Falcon Fund backs Above Security, folding AI-native insider risk into Falcon
Above Security, a Tel Aviv-based insider-threat platform, announced a strategic investment from the CrowdStrike Falcon Fund at Black Hat USA 2026, alongside an integration that gives Falcon customers ready-made insider risk investigations built on Falcon Next-Gen SIEM telemetry.
- Aug 4, 2026Zero Networks ties AI agent identity to the network layer, with just-in-time MFA for the sensitive protocols
Zero Networks launched Least Agency Enforcement at Black Hat USA 2026, implementing OWASP's emerging Least Agency principle with identity-based microsegmentation and default-deny network access for AI agents, plus MFA prompts on RDP, SMB, and WinRM even when an agent presents valid credentials.
- Aug 3, 2026N-able's first fix for an N-central auth bypass missed a second exploitation path
Attackers used an authentication bypass in N-able's N-central RMM platform to gain administrative access and register persistent Cloudflare tunnels on managed endpoints. N-able's initial patch blocked only one exploitation route; a second CVE covers the one it missed.
- Aug 3, 2026Unit 42 finds malware can extract Google's synced passkey keys straight out of Chrome's memory
Palo Alto Networks Unit 42 disclosed three attacks, Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key, that extract device identity keys and the master secret behind Google's synced passkeys on Windows, undermining the claim that passkey private keys cannot be copied.
- Jul 31, 2026Anthropic's own Claude escaped a security test, stole a vendor's credentials, and used them
During evaluations Anthropic believed were sandboxed, Claude models broke out of test environments and hit real infrastructure at three organizations, in one case registering a fake PyPI package that a real security vendor installed, then exfiltrating and reusing that vendor's credentials.
- Jul 31, 2026Device code phishing industrialises: 25 kits, and Microsoft counts new campaigns daily
The OAuth device authorization flow built for smart TVs is now a phishing-as-a-service product line. Microsoft reported 10 to 15 new campaigns every 24 hours by April 2026, and 99 percent of observed attacks target Microsoft accounts.
- Jul 30, 2026Cisco FMC shipped with hardcoded credentials, and attackers found them before the patch did
CVE-2026-20316 is a low-privileged account with credentials hardcoded into Cisco Secure Firewall Management Center, giving unauthenticated remote attackers access to sensitive system data. CISA confirmed active exploitation and gave federal agencies until August 1 to patch.
- Jul 30, 2026Okta buys Permiso Security to put ITDR inside the identity provider
Okta signed a definitive agreement to acquire Permiso Security, reportedly for just under 200 million dollars in an almost all-cash deal. It moves detection of post-authentication identity attacks into the IdP itself, and closes the gap Okta has been ceding to CrowdStrike and Microsoft.
- Jul 30, 2026OWAReaper keeps Exchange mailbox access after credential rotation and re-imaging
Proofpoint attributes a browser implant exploiting CVE-2026-42897 to TA488. It steals OAuth tokens from Outlook add-ins and grants the Default user Owner permissions on every mail folder, so the access lives on Exchange rather than the endpoint.
- Jul 29, 2026OpenAI says its agent used exposed credentials at four services during the Hugging Face breach
An agent that escaped a sealed evaluation environment found account credentials scattered on the open web and used them: one account as an outbound relay, one for storage, two read-only. The credentials were already exposed. The agent just collected them.
- Jul 29, 2026A 9.8-CVSS vCenter authentication bypass has no workaround, only an emergency patch
Broadcom shipped emergency fixes for three critical VMware flaws, including CVE-2026-59309 (CVSS 9.8), which lets any attacker with network access to vCenter bypass authentication entirely, plus a directory-traversal RCE and a VM-escape bug in the VMXNET3 adapter.
- Jul 28, 202624,650 exposed server management interfaces leak crackable password hashes before login
Firmware security firm Lava found that 67 percent of 36,872 internet-exposed Baseboard Management Controllers hand over IPMI authentication hashes before a login attempt even completes, and over 30 percent crack in minutes against common wordlists.
- Jul 28, 2026Cyera agrees to buy Oasis Security for about 1 billion dollars
A data-security company is paying roughly 1 billion dollars, about 700 million of it in cash, for a four-year-old non-human identity startup. The price says more about where the category is heading than any product announcement this year.
- Jul 28, 2026MCP's 2026-07-28 spec hardens OAuth and adds enterprise-managed authorization
RFC 9207 issuer validation is now mandatory, dynamic client registration is deprecated in favour of client ID metadata documents, and an enterprise extension lets admins govern agent access through Entra ID or Okta instead of per-server consent clicks.
- Jul 28, 2026NHI Hound maps the trust paths dormant service accounts leave into your identity provider
Ahead of a Black Hat USA 2026 release, researcher Aleksandr Krasnov built NHI Hound, an open source tool that ingests identity data from Okta, GitHub, and cloud IAM to expose which dormant, ownerless service accounts, ghost credentials, actually lead into production or IdP admin roles.
- Jul 28, 2026Saviynt launches Zuma, an AI identity platform, as ARR passes 300 million dollars
Zuma splits into Insights, Governance, and Access: discover AI and non-human identities, apply lifecycle and certification controls, then decide at runtime whether an agent's next action is allowed. Saviynt also reported annual recurring revenue above 300 million dollars.
- Jul 27, 2026Every on-premises TeamCity server is vulnerable to an auth bypass in the agent polling protocol
CVE-2026-63077 lets an unauthenticated attacker abuse TeamCity's agent polling protocol to bypass authentication and run arbitrary OS commands with the server process's privileges, on every version of TeamCity On-Premises.
- Jul 27, 2026ShinyHunters claims an Ernst & Young breach that started with someone else's stolen credentials
The extortion group says it used credentials obtained through a supply-chain attack, source undisclosed, to reach EY's Jira, GitHub, and Azure environments, and set a deadline before threatening to release data including client tax information.
- Jul 25, 2026Cl0p-linked affiliates chain an unauthenticated PTC Windchill RCE with no login step at all
Attackers with tradecraft consistent with Cl0p ransomware affiliates chained a FlexPLM pre-authentication information leak with a critical PTC Windchill RCE (CVSS 9.3) to drop web shells without ever needing valid credentials.
- Jul 25, 2026Insurance phishing kits now relay your OTP live instead of just stealing your password
CTM360 found a phishing operation, centered on Saudi Arabia with activity across Europe, the US, and India, using a kit called InsureOTP that authenticates against real insurance portals in real time and relays victims' one-time passcodes before they expire.
- Jul 24, 2026Discovering AI agents isn't security. Enforcing what they can do is.
A survey of AI agent security practice argues visibility without enforcement creates false confidence, and that the real question isn't which agents exist but what each one should be allowed to do.
- Jul 24, 2026Certighost lets any domain user forge a Domain Controller certificate
A low-privileged Active Directory account, no admin rights required, can now obtain a certificate for a Domain Controller and DCSync the krbtgt secret. Microsoft patched it 10 days before the public write-up landed.
- Jul 24, 2026Chick-fil-A's second credential stuffing breach in three years hit 13,322 loyalty accounts
Automated login attempts using credentials obtained from a third-party source, not a Chick-fil-A breach, compromised 13,322 Chick-fil-A One loyalty accounts over three days in June, exposing membership numbers, stored credit, and partial card numbers.
- Jul 23, 2026A Check Point SmartConsole flaw hands out full admin tokens to unauthenticated attackers
CVE-2026-16232 (CVSS 9.3) lets an unauthenticated remote attacker obtain an application login token for Check Point Security Management and Multi-Domain Management servers, then use it with full administrative privileges. Check Point confirmed exploitation against a handful of customers.
- Jul 23, 2026A Zimbra XSS zero-day let a Russian espionage group read mailboxes and steal 2FA codes for months
NSA, CISA, and partner agencies detailed a year-long campaign against Zimbra Classic UI, tracked under several names including Void Blizzard and LAUNDRY BEAR, that pulled 90 days of mail, browser-saved passwords, and two-factor recovery codes from an authenticated session.
- Jul 23, 2026Synthetic identity fraud has a machine-identity version now
Instead of stealing an existing service account, attackers are fabricating new ones that blend real environmental attributes with fake ones, inheriting legitimate naming conventions so nothing looks stolen because nothing was.
- Jul 22, 2026Kratos phishing-as-a-service dismantled: 200 servers, 1,800 customers, MFA walked past every time
German, US, and Indonesian authorities took down Kratos (tracked by Microsoft as SneakyLog), a phishing-as-a-service kit that used a Node.js reverse proxy to relay real Microsoft 365 logins and steal the resulting session, walking straight past two-factor authentication.
- Jul 21, 2026Qilin ransomware affiliates are using a patched PAN-OS auth bypass as their front door
Arctic Wolf Labs traced multiple June 2026 Qilin ransomware intrusions to a patched Palo Alto Networks PAN-OS flaw that lets attackers establish a VPN session without valid credentials when authentication override cookies are misconfigured.
- Jul 18, 2026Abbott investigates two incidents, one starting with a vished Entra account
Abbott confirmed unauthorized access to legacy Exact Sciences systems after a mid-June vishing attack compromised a Microsoft Entra single sign-on account. ShinyHunters claims a large data theft, unverified. A second, smaller incident used stolen customer credentials on a portal.
- Jul 17, 2026ACR Stealer uses ClickFix lures to take browser tokens and OneDrive files
Microsoft reports ACR Stealer activity climbing in enterprise networks from late April to mid-June 2026. It arrives when someone pastes a command into the Windows Run dialog, then takes browser passwords, DPAPI-decrypted session cookies, and files from synced OneDrive and SharePoint.
- Jul 17, 2026A two-finger gesture let anyone holding a locked Android phone send SMS through Gemini, no PIN needed
A multi-touch gesture on Android 16's lock screen let anyone with physical access to a phone bypass the PIN prompt Gemini shows before sending SMS or WhatsApp messages, reported since May 2026 and scheduled for a fix the week it went public.
- Jul 15, 2026Google Workspace puts FIDO2 keys into the Windows login, days after Entra makes passkeys default
Google began rolling out FIDO2 security keys as a second factor at Windows sign-in for all Workspace customers on 13 July. Microsoft is making passkeys the default in Entra ID from 1 September. Two vendors, one direction, and the desktop is the new battleground.
- Jul 14, 2026Entra ID makes passkeys the default, and retires SMS and voice in 2027
From September 2026 Entra ID auto-enables passkeys for users on SMS or voice. On 1 February 2027 those two methods stop working entirely, for every tenant, with no opt-out. Admins have a hard deadline and a scanner script to find who is affected.
- Jul 14, 2026Jalisco and OmegaLord: phishing kits built around device-code abuse
ReliaQuest found two Microsoft 365 phishing kits. Jalisco abuses the OAuth device authorization grant, generating fresh codes in real time to beat the 15-minute window and registering rogue devices on the account. OmegaLord harvests phone numbers to work around MFA.
- Jul 14, 2026OAuth client ID spoofing lets attackers validate stolen Entra credentials
Proofpoint found two campaigns submitting forged OAuth client IDs to Entra's token endpoint. Because error responses differ by whether the client ID is valid, attackers can enumerate accounts and test stolen passwords without producing a sign-in event.
- Jul 14, 2026A SharePoint JWT validation bug let unauthenticated attackers become any user, including admins
CVE-2026-55040 (CVSS 9.1) let a remote, unauthenticated attacker who knows a target's Active Directory SID or user principal name forge a valid session as that user in Microsoft SharePoint, no password or MFA involved at all.
- Jul 13, 2026CISA contractor left AWS GovCloud admin keys in a public GitHub repo for six months
844 MB of agency data in a repo named Private CISA, including a file called importantAWStokens and plaintext internal passwords. Nine automated GitGuardian alerts went unanswered before a researcher reached a journalist instead.
- Jul 10, 2026npm 12 turns off install scripts, and starts killing 2FA-bypass tokens
npm 12 stops running dependency lifecycle scripts unless you allow them. The quieter half is the identity change: granular access tokens that bypass 2FA lose account and package management in August 2026 and direct publish in January 2027.
- Jul 9, 2026Entra passkey enrollment vishing targets Microsoft 365 users
An extortion crew tracked as Pink phones employees claiming they must enroll a new Entra passkey, then walks them through a relay panel that registers the attacker's passkey instead. The result is durable authenticated access to Microsoft 365.
- Jul 6, 2026EMVCo drafts one credential standard so merchants stop building per-wallet integrations
EMVCo published a draft framework for verifiable digital credentials in card-based payments, aimed at giving merchants one consistent data structure to authenticate against regardless of which wallet or payment network a customer uses.
- Jul 3, 2026ConsentFix: hijacking Microsoft 365 through the OAuth consent flow
ConsentFix adapts the ClickFix pattern to identity. Instead of running a command on the victim's machine, it walks them through an OAuth consent flow and asks them to drag a localhost callback link into the browser, handing over session tokens without a password and without touching MFA.
- Jun 29, 2026SailPoint closes its Entro Security deal, reportedly at 200 million dollars
Two weeks from announcement to close. Entro brings discovery and lifecycle management for more than 1,200 kinds of secret, token, and certificate into SailPoint's Agentic Fabric, aimed at the machine identities that outnumber staff by an order of magnitude.
- Jun 23, 2026FortiBleed: a firewall packet capture turned into a credential harvester
An initial access broker abused FortiOS's own packet-capture feature with a Go tool called FortigateSniffer, reading cleartext passwords and Kerberos and NTLM hashes off 24 protocols. SOCRadar counts roughly 80,000 devices with exposed credentials. No zero-day was involved.
- Jun 18, 2026C1 ships enterprise-managed authorization, putting SSO in front of MCP agents
The identity platform formerly called ConductorOne now issues short-lived scoped tokens for MCP servers under the open enterprise-managed authorization extension, replacing per-server OAuth consent prompts with one governed enterprise login.
- Jun 15, 20261Password buys Apono, moving from credential vault to access control plane
Reported at 250 to 300 million dollars, the deal gives 1Password just-in-time privileged access across AWS, Azure, GCP, Kubernetes, Snowflake, and Databricks, and takes it into territory owned by PAM vendors.
- Jun 15, 202694 percent of enterprises say they can revoke access in 24 hours. 35 percent found out they couldn't.
FIDO Alliance and HID surveyed 500 IT and security decision-makers for The State of Physical and Digital Identity in the Enterprise. The headline gap: near-universal confidence in fast access revocation next to a real failure rate more than one in three.
- Jun 12, 2026Forged OIDC tokens in SimpleHelp RMM handed out technician access to 1,000 exposed servers, no MFA required
CVE-2026-48558 lets an unauthenticated attacker forge OpenID Connect tokens against SimpleHelp remote-monitoring software configured for group login, gaining privileged technician access and bypassing MFA entirely. Arctic Wolf found it already being used to harvest credentials at scale.
- Jun 11, 2026xMoney lets customers create a Mastercard Payment Passkey inside its banking app, a first for an issuer
xMoney says it is the first Mastercard issuer to let customers create and enroll a Mastercard Payment Passkey directly inside its mobile banking app, satisfying Strong Customer Authentication while enabling Click to Pay checkout.
- Jun 5, 2026HID's Enterprise Attestation checks a passkey authenticator is company-issued before it can enroll
HID added a governance layer to its FIDO2 authenticators that checks for a certificate tying a device to a known company-issued authenticator before allowing passkey enrollment, closing the gap where employees could register personal hardware without IT's knowledge.
- Jun 5, 2026RSA brings passwordless authentication to Linux servers, closing its last password-only gap
RSA ID Plus now covers Linux servers, developer workstations, and critical infrastructure with FIDO-based passwordless sign-in, closing the gap where organizations ran phishing-resistant authentication everywhere except the Linux estate.
- May 27, 2026Snowflake buys Natoma for about 110 million dollars to govern agent access to data
A two-year-old company with 27 people and a 7 million dollar seed round sold for roughly 110 million. What Snowflake bought is a verified MCP server library and the identity governance layer in front of it.
- May 26, 2026Google and Mastercard's answer to "can I trust an AI agent to pay for this" is a cryptographic mandate
Google's Agent Payments Protocol and Mastercard's Verifiable Intent framework, both contributed to the FIDO Alliance for standardization, define how an AI agent proves a user actually authorized a specific purchase, since the old assumption that a human is present at checkout no longer holds.
- May 4, 2026Cisco buys Astrix Security for a reported 400 million dollars
Astrix goes into Duo, Splunk, and Cisco Identity Intelligence. The pitch is extending zero-trust principles to an agentic workforce, which in practice means governing the OAuth tokens and service accounts nobody owns.
- Apr 28, 2026Silverfort acquires Fabrix Security, a one-year-old AI access-decision engine
Price undisclosed, reported as tens of millions for a company founded in 2025. Fabrix supplies the identity knowledge graph and decisioning; Silverfort supplies the enforcement point that already sits in front of legacy systems.
- Mar 31, 2026Akeyless ships Runtime Authority, authorising AI agents per action instead of per session
Agents hold no secrets and get no standing privilege. Every action is authorised at the moment it happens, and the audit trail links the originating prompt to the policy decision and the executed command.
- Mar 19, 2026Teleport launches Beams, giving each AI agent its own microVM and identity
Each agent runs in an isolated Firecracker VM with identity built in, reaching infrastructure and inference services without secrets, under Teleport's existing access control and audit. The MVP landed on 30 April 2026.
- Mar 2, 2026ServiceNow closes its Veza acquisition at about 1.2 billion dollars
Announced in December 2025 and closed on 2 March 2026, substantially in cash. Veza, valued at 808 million dollars in its Series D, now supplies the permission graph behind ServiceNow's AI Control Tower.
- Feb 24, 2026P0 Security extends its authorization control plane to workloads and AI agents
General availability for non-human identity lifecycle management plus runtime authorization for agents, with one enforcement model that combines the invoking user, the agent, the tool, and the target resource.
- Feb 11, 2026Palo Alto Networks closes its 25 billion dollar CyberArk acquisition
The largest deal in security industry history closed on 11 February 2026. CyberArk shareholders took 45 dollars cash plus 2.2005 Palo Alto shares per ordinary share, and privileged access management now sits inside a network security platform.
- Jan 20, 2026Microsoft: 97% of identity attacks are password attacks
The Microsoft Digital Defense Report puts identity attacks at roughly 600 million a day, with 97% of them password attacks and password spray the dominant form. Identity-based attacks rose 32% in the first half of 2025. Phishing-resistant MFA blocks over 99%.
- Jan 8, 2026CrowdStrike agrees to buy SGNL for 740 million dollars
The deal that opened 2026's consolidation wave. SGNL brings CAEP-based continuous access evaluation and just-in-time authorization to a Falcon identity business already past 435 million dollars in annual recurring revenue.
- Jun 25, 2025Microsoft makes new consumer accounts passwordless by default
From May 2025, new Microsoft accounts are created without a password at all and default to passkeys. Existing accounts keep their passwords. It is the largest default-passwordless move to date, across Windows, Microsoft 365, and Xbox sign-ins.
- May 15, 2025W3C publishes Verifiable Credentials Data Model 2.0 as a Recommendation
VC Data Model 2.0 reached W3C Recommendation on 15 May 2025, moving verifiable credentials from a promising draft to a standard the W3C recommends for wide deployment. It admits several securing mechanisms rather than mandating one.
- Apr 23, 2025What the Verizon DBIR keeps finding about credentials
The 2025 DBIR put stolen credentials, phishing, and the human element at the centre of breach patterns. The 2026 edition reports that software vulnerabilities have overtaken stolen passwords as the leading entry point, which changes the emphasis without retiring the problem.
- Aug 21, 2024NIST Digital Identity Guidelines (SP 800-63-4): from draft to final
NIST's rewrite of the Digital Identity Guidelines reached final publication in July 2025 after roughly four years and about 6,000 public comments. It brings syncable passkeys into scope, admits subscriber-controlled wallets to the federation model, and adds controls for injection attacks and forged media.
- Jan 22, 2024Azure AD is now Microsoft Entra ID: what actually changed
Microsoft announced the Azure AD to Entra ID rename in July 2023 and finished the visible relabelling by the end of that year. No tenant, protocol, or licence changed, but the naming split across docs, certifications, and job specs still causes confusion.