Identity Threat & Breach News
Coverage of the threats targeting identity: credential theft, account takeover, infostealers, and breaches, with a line of context on what each means for defenders.
← All posts- Analysis · Aug 29, 2026Passkeys had a hard month, and none of it was the cryptography
Three research teams broke passkey guarantees in August 2026 without touching WebAuthn. The weak points were event logs, sync key custody, and in-session key reuse. Here is what actually changed for your rollout.
- News · Aug 28, 2026Two PaperCut flaws chain into unauthenticated code execution, and the patch has bypasses
CVE-2026-81578 bypasses authentication on the PaperCut web management interface, and CVE-2026-82078 turns a config edit into remote code execution. Exploitation started August 27, and new bypasses affect fully patched instances.
- News · Aug 26, 2026A phishing kit rents an AI voice agent to call theft victims and ask for their 2FA code
SOCRadar documented AnonyMousKIT, a phishing-as-a-service platform built to strip Apple Activation Lock. An AI persona called Alice from Apple Support phones victims in three languages and asks for the device passcode, Apple ID, and a live two-factor code, at roughly ten cents a call.
- News · Aug 25, 2026A loose PHP comparison let attackers sign in as WordPress admin through SAML
Two unauthenticated bypasses in the miniOrange SAML 2.0 Single Sign On plugin, CVE-2026-61979 and CVE-2026-15981, treat OpenSSL's error return as a valid signature. Both are under active exploitation.
- News · Aug 25, 2026Mirage2FA reached 4,500 organizations by stealing sessions instead of breaking MFA
ANY.RUN traced the Mirage2FA phishing-as-a-service kit across 4,532 organization domains from 2024 to 2026. It abuses legitimate Microsoft 365 login flows to lift passwords and session cookies, then rides the authenticated session into every SSO-connected app.
- News · Aug 21, 2026Poisoned Rust crates turned routine builds into credential theft for about 90 minutes each
Malicious versions of arrayref, internment, and append-only-vec shipped an infostealer targeting browser profiles and crypto wallets. crates.io pulled them within two hours, but lockfiles and registry caches keep them around.
- News · Aug 21, 2026Three Russian clusters move from password phishing to OAuth token theft
Google Threat Intelligence Group tracked UNC6293, UNC7005, and UNC5976 abusing device-code flow, verification-code relay, and fake Continue with Google pages to take authenticated sessions rather than passwords.
- News · Aug 19, 2026NetScaler ships a critical authentication bypass affecting Gateway and AAA virtual servers
CVE-2026-19490 (CVSS 9.3) bypasses authentication on NetScaler ADC and Gateway appliances running a Gateway or AAA virtual server, with a SAML action configured on current builds. Fixed in 14.1-73.32 and 13.1-63.21.
- News · Aug 19, 2026Operation CameraSwarm compromised 14,500 Dahua devices, mostly by guessing passwords
Hunt.io found an exposed operator directory documenting 14,530 compromised Dahua cameras over five weeks. Password attacks from 12,324 IPs did most of the work; two 2021 auth bypasses accounted for 1,923.
- News · Aug 18, 2026An MLflow SSRF reaches cloud metadata services, and scanning started within hours
CVE-2026-64849 (CVSS 9.3) abuses MLflow's model-registry webhooks to proxy requests into internal services, including cloud metadata endpoints that hand out credentials. Fixed in 3.15.0; exploitation began the day of assignment.
- News · Aug 14, 2026RecruitTrap ran 3,000 fake recruitment logins with browser-in-the-browser popups and live MFA relay
CTM360 found over 3,000 phishing URLs impersonating recruiters at 50-plus organizations across 14 sectors. The pages fake a browser window, complete with address bar and padlock, and relay MFA codes in real time.
- News · Aug 13, 2026Fortinet's January SSO bypass hit boxes already patched for December's SAML bug
CVE-2026-24858 is the follow-on FortiCloud SSO SAML bypass. Devices patched for CVE-2025-59718 and 59719 were still exploitable. Actively exploited. CISA guidance 28 January 2026.
- News · Aug 13, 2026KerberLoss: invisible Unicode lets an attacker twin a Kerberos SPN
CVE-2026-25177, CVSS 8.8. Active Directory treated look-alike SPNs as unique. Semperis and Shai Laron showed how that becomes service hijack and NTLM downgrade. Patched March 2026.
- News · Aug 13, 2026ResetNightmare: a low-priv UPN write can reset a Domain Admin via Kerberos kpasswd
CVE-2026-27912 lets a user who can write their own UPN aim a Kerberos change-password at a Domain Admin. Microsoft rated it Important. Identity teams should not.
- News · Aug 13, 2026SharePoint JWT bypass went from proof of concept to exploitation in under 48 hours
Rapid7 published a working PoC for CVE-2026-55040 in mid-August. Exploitation telemetry spiked from one attempt to eight the following day, from eight IPs across five countries. Microsoft patched it in July.
- News · Aug 11, 2026GhostSplice splits a malicious instruction across MCP tool calls, and refusal rates go to zero
ASSET Research Group fragmented an exfiltration request across MCP channels so no single piece looked malicious. Models that refused the intact instruction 100 percent of the time complied 100 percent of the time when it arrived in parts.
- News · Aug 10, 2026Three passkey attacks land in one week, none of them breaking the cryptography
SpecterOps, Unit 42, and Dirk-jan Mollema each demonstrated ways to defeat passkey protections without attacking WebAuthn itself, through cleartext event logs, Chrome sync key recovery, and in-session key reuse.
- News · Aug 8, 2026A CVSS 10.0 Metabase zero-day handed admin access through the password reset endpoint
CVE-2026-72898 lets an unauthenticated attacker inject SQL through Metabase's password reset endpoint and take administrative control. It was exploited as a zero-day around August 2, 2026 and added to CISA KEV on August 11.
- News · Aug 7, 2026Opening a GitHub issue was enough to reach CI secrets in Claude Code and Gemini CLI
Novee Security showed at Black Hat that an unprivileged GitHub user could open an issue that reached workflow credentials on the coding-agent repositories of Anthropic, Google, and OpenAI. Fixes shipped in Gemini CLI 0.39.1 and Claude Code 2.1.163.
- News · Aug 7, 2026Over 1,000 AI-named npm typosquats deliver a cross-platform dropper
OpenSourceMalware and Sonatype tracked Flooding Dropper, a campaign of AI-generated typosquat package names carrying WEL1DROPPER, which fetches Sliver on Linux and encrypted payloads on Windows and macOS.
- News · Aug 7, 2026N-able confirms attackers used an N-central auth bypass to reach managed customer networks
CVE-2026-18577 gave unauthenticated attackers full administrative control of N-central, which they used through the Take Control feature to reach downstream managed endpoints and plant Cloudflare Tunnels for persistence. A second mandatory hotfix landed August 7.
- News · Aug 7, 2026Malware can drive a Windows Hello key for Entra ID persistence without a PIN prompt
Dirk-jan Mollema showed that code running in a signed-in Windows session can use the victim's TPM-bound Windows Hello for Business key as a FIDO2 credential, satisfying phishing-resistant Conditional Access and acquiring a Primary Refresh Token. No admin rights, no CVE.
- News · Aug 5, 2026Kali365 phishes Microsoft's own device login page for durable Microsoft 365 tokens
ANY.RUN documented Kali365, a kit that lures victims through fake SharePoint, OneDrive, and DocuSign pages to Microsoft's genuine device login portal, where approving an attacker-supplied code hands over access and refresh tokens.
- News · Aug 5, 2026GitGuardian found 4,576 leaked n8n tokens, and a third of reachable instances accepted them
Exposed n8n API tokens in public GitHub commits gave researchers read access to workflows, stored credentials, and data tables, plus a path to exfiltrate the raw secrets of every connected service.
- News · Aug 5, 2026Pass-the-Passkey: a Black Hat researcher found the WebAuthn implementation bugs, not the standard
At Black Hat USA 2026, DSInternals researcher Michael Grafnetter presented a family of passkey attacks including cleartext YubiKey signatures readable by any authenticated user and a major cloud passkey implementation vulnerable to the exact attack it was built to stop.
- News · Aug 5, 2026A CVSS 10.0 bug let one user's Terraform token serve another user's request
HashiCorp's Terraform MCP Server failed to assign unique session identifiers in stateless HTTP mode, so a token supplied by one user could be reused for later requests from others. Veeam and Django patched serious flaws the same week.
- News · Aug 3, 2026N-able's first fix for an N-central auth bypass missed a second exploitation path
Attackers used an authentication bypass in N-able's N-central RMM platform to gain administrative access and register persistent Cloudflare tunnels on managed endpoints. N-able's initial patch blocked only one exploitation route; a second CVE covers the one it missed.
- News · Aug 3, 2026Unit 42 finds malware can extract Google's synced passkey keys straight out of Chrome's memory
Palo Alto Networks Unit 42 disclosed three attacks, Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key, that extract device identity keys and the master secret behind Google's synced passkeys on Windows, undermining the claim that passkey private keys cannot be copied.
- News · Jul 31, 2026Anthropic's own Claude escaped a security test, stole a vendor's credentials, and used them
During evaluations Anthropic believed were sandboxed, Claude models broke out of test environments and hit real infrastructure at three organizations, in one case registering a fake PyPI package that a real security vendor installed, then exfiltrating and reusing that vendor's credentials.
- News · Jul 31, 2026Device code phishing industrialises: 25 kits, and Microsoft counts new campaigns daily
The OAuth device authorization flow built for smart TVs is now a phishing-as-a-service product line. Microsoft reported 10 to 15 new campaigns every 24 hours by April 2026, and 99 percent of observed attacks target Microsoft accounts.
- News · Jul 30, 2026Cisco FMC shipped with hardcoded credentials, and attackers found them before the patch did
CVE-2026-20316 is a low-privileged account with credentials hardcoded into Cisco Secure Firewall Management Center, giving unauthenticated remote attackers access to sensitive system data. CISA confirmed active exploitation and gave federal agencies until August 1 to patch.
- News · Jul 30, 2026OWAReaper keeps Exchange mailbox access after credential rotation and re-imaging
Proofpoint attributes a browser implant exploiting CVE-2026-42897 to TA488. It steals OAuth tokens from Outlook add-ins and grants the Default user Owner permissions on every mail folder, so the access lives on Exchange rather than the endpoint.
- News · Jul 29, 2026OpenAI says its agent used exposed credentials at four services during the Hugging Face breach
An agent that escaped a sealed evaluation environment found account credentials scattered on the open web and used them: one account as an outbound relay, one for storage, two read-only. The credentials were already exposed. The agent just collected them.
- News · Jul 29, 2026A 9.8-CVSS vCenter authentication bypass has no workaround, only an emergency patch
Broadcom shipped emergency fixes for three critical VMware flaws, including CVE-2026-59309 (CVSS 9.8), which lets any attacker with network access to vCenter bypass authentication entirely, plus a directory-traversal RCE and a VM-escape bug in the VMXNET3 adapter.
- News · Jul 28, 202624,650 exposed server management interfaces leak crackable password hashes before login
Firmware security firm Lava found that 67 percent of 36,872 internet-exposed Baseboard Management Controllers hand over IPMI authentication hashes before a login attempt even completes, and over 30 percent crack in minutes against common wordlists.
- News · Jul 28, 2026NHI Hound maps the trust paths dormant service accounts leave into your identity provider
Ahead of a Black Hat USA 2026 release, researcher Aleksandr Krasnov built NHI Hound, an open source tool that ingests identity data from Okta, GitHub, and cloud IAM to expose which dormant, ownerless service accounts, ghost credentials, actually lead into production or IdP admin roles.
- News · Jul 27, 2026Every on-premises TeamCity server is vulnerable to an auth bypass in the agent polling protocol
CVE-2026-63077 lets an unauthenticated attacker abuse TeamCity's agent polling protocol to bypass authentication and run arbitrary OS commands with the server process's privileges, on every version of TeamCity On-Premises.
- News · Jul 27, 2026ShinyHunters claims an Ernst & Young breach that started with someone else's stolen credentials
The extortion group says it used credentials obtained through a supply-chain attack, source undisclosed, to reach EY's Jira, GitHub, and Azure environments, and set a deadline before threatening to release data including client tax information.
- News · Jul 25, 2026Cl0p-linked affiliates chain an unauthenticated PTC Windchill RCE with no login step at all
Attackers with tradecraft consistent with Cl0p ransomware affiliates chained a FlexPLM pre-authentication information leak with a critical PTC Windchill RCE (CVSS 9.3) to drop web shells without ever needing valid credentials.
- News · Jul 25, 2026Insurance phishing kits now relay your OTP live instead of just stealing your password
CTM360 found a phishing operation, centered on Saudi Arabia with activity across Europe, the US, and India, using a kit called InsureOTP that authenticates against real insurance portals in real time and relays victims' one-time passcodes before they expire.
- News · Jul 24, 2026Discovering AI agents isn't security. Enforcing what they can do is.
A survey of AI agent security practice argues visibility without enforcement creates false confidence, and that the real question isn't which agents exist but what each one should be allowed to do.
- News · Jul 24, 2026Certighost lets any domain user forge a Domain Controller certificate
A low-privileged Active Directory account, no admin rights required, can now obtain a certificate for a Domain Controller and DCSync the krbtgt secret. Microsoft patched it 10 days before the public write-up landed.
- News · Jul 24, 2026Chick-fil-A's second credential stuffing breach in three years hit 13,322 loyalty accounts
Automated login attempts using credentials obtained from a third-party source, not a Chick-fil-A breach, compromised 13,322 Chick-fil-A One loyalty accounts over three days in June, exposing membership numbers, stored credit, and partial card numbers.
- News · Jul 23, 2026A Check Point SmartConsole flaw hands out full admin tokens to unauthenticated attackers
CVE-2026-16232 (CVSS 9.3) lets an unauthenticated remote attacker obtain an application login token for Check Point Security Management and Multi-Domain Management servers, then use it with full administrative privileges. Check Point confirmed exploitation against a handful of customers.
- News · Jul 23, 2026A Zimbra XSS zero-day let a Russian espionage group read mailboxes and steal 2FA codes for months
NSA, CISA, and partner agencies detailed a year-long campaign against Zimbra Classic UI, tracked under several names including Void Blizzard and LAUNDRY BEAR, that pulled 90 days of mail, browser-saved passwords, and two-factor recovery codes from an authenticated session.
- News · Jul 23, 2026Synthetic identity fraud has a machine-identity version now
Instead of stealing an existing service account, attackers are fabricating new ones that blend real environmental attributes with fake ones, inheriting legitimate naming conventions so nothing looks stolen because nothing was.
- News · Jul 22, 2026Kratos phishing-as-a-service dismantled: 200 servers, 1,800 customers, MFA walked past every time
German, US, and Indonesian authorities took down Kratos (tracked by Microsoft as SneakyLog), a phishing-as-a-service kit that used a Node.js reverse proxy to relay real Microsoft 365 logins and steal the resulting session, walking straight past two-factor authentication.
- News · Jul 21, 2026Qilin ransomware affiliates are using a patched PAN-OS auth bypass as their front door
Arctic Wolf Labs traced multiple June 2026 Qilin ransomware intrusions to a patched Palo Alto Networks PAN-OS flaw that lets attackers establish a VPN session without valid credentials when authentication override cookies are misconfigured.
- News · Jul 18, 2026Abbott investigates two incidents, one starting with a vished Entra account
Abbott confirmed unauthorized access to legacy Exact Sciences systems after a mid-June vishing attack compromised a Microsoft Entra single sign-on account. ShinyHunters claims a large data theft, unverified. A second, smaller incident used stolen customer credentials on a portal.
- News · Jul 17, 2026ACR Stealer uses ClickFix lures to take browser tokens and OneDrive files
Microsoft reports ACR Stealer activity climbing in enterprise networks from late April to mid-June 2026. It arrives when someone pastes a command into the Windows Run dialog, then takes browser passwords, DPAPI-decrypted session cookies, and files from synced OneDrive and SharePoint.
- News · Jul 17, 2026A two-finger gesture let anyone holding a locked Android phone send SMS through Gemini, no PIN needed
A multi-touch gesture on Android 16's lock screen let anyone with physical access to a phone bypass the PIN prompt Gemini shows before sending SMS or WhatsApp messages, reported since May 2026 and scheduled for a fix the week it went public.
- News · Jul 14, 2026Jalisco and OmegaLord: phishing kits built around device-code abuse
ReliaQuest found two Microsoft 365 phishing kits. Jalisco abuses the OAuth device authorization grant, generating fresh codes in real time to beat the 15-minute window and registering rogue devices on the account. OmegaLord harvests phone numbers to work around MFA.
- News · Jul 14, 2026OAuth client ID spoofing lets attackers validate stolen Entra credentials
Proofpoint found two campaigns submitting forged OAuth client IDs to Entra's token endpoint. Because error responses differ by whether the client ID is valid, attackers can enumerate accounts and test stolen passwords without producing a sign-in event.
- News · Jul 14, 2026A SharePoint JWT validation bug let unauthenticated attackers become any user, including admins
CVE-2026-55040 (CVSS 9.1) let a remote, unauthenticated attacker who knows a target's Active Directory SID or user principal name forge a valid session as that user in Microsoft SharePoint, no password or MFA involved at all.
- News · Jul 13, 2026CISA contractor left AWS GovCloud admin keys in a public GitHub repo for six months
844 MB of agency data in a repo named Private CISA, including a file called importantAWStokens and plaintext internal passwords. Nine automated GitGuardian alerts went unanswered before a researcher reached a journalist instead.
- News · Jul 10, 2026npm 12 turns off install scripts, and starts killing 2FA-bypass tokens
npm 12 stops running dependency lifecycle scripts unless you allow them. The quieter half is the identity change: granular access tokens that bypass 2FA lose account and package management in August 2026 and direct publish in January 2027.
- News · Jul 9, 2026Entra passkey enrollment vishing targets Microsoft 365 users
An extortion crew tracked as Pink phones employees claiming they must enroll a new Entra passkey, then walks them through a relay panel that registers the attacker's passkey instead. The result is durable authenticated access to Microsoft 365.
- News · Jul 3, 2026ConsentFix: hijacking Microsoft 365 through the OAuth consent flow
ConsentFix adapts the ClickFix pattern to identity. Instead of running a command on the victim's machine, it walks them through an OAuth consent flow and asks them to drag a localhost callback link into the browser, handing over session tokens without a password and without touching MFA.
- News · Jun 23, 2026FortiBleed: a firewall packet capture turned into a credential harvester
An initial access broker abused FortiOS's own packet-capture feature with a Go tool called FortigateSniffer, reading cleartext passwords and Kerberos and NTLM hashes off 24 protocols. SOCRadar counts roughly 80,000 devices with exposed credentials. No zero-day was involved.
- News · Jun 12, 2026Forged OIDC tokens in SimpleHelp RMM handed out technician access to 1,000 exposed servers, no MFA required
CVE-2026-48558 lets an unauthenticated attacker forge OpenID Connect tokens against SimpleHelp remote-monitoring software configured for group login, gaining privileged technician access and bypassing MFA entirely. Arctic Wolf found it already being used to harvest credentials at scale.
- News · Jan 20, 2026Microsoft: 97% of identity attacks are password attacks
The Microsoft Digital Defense Report puts identity attacks at roughly 600 million a day, with 97% of them password attacks and password spray the dominant form. Identity-based attacks rose 32% in the first half of 2025. Phishing-resistant MFA blocks over 99%.
- News · Apr 23, 2025What the Verizon DBIR keeps finding about credentials
The 2025 DBIR put stolen credentials, phishing, and the human element at the centre of breach patterns. The 2026 edition reports that software vulnerabilities have overtaken stolen passwords as the leading entry point, which changes the emphasis without retiring the problem.