This Week in Identity
Every week we round up the identity and security news that matters, link to the original sources, and add a line on why each one counts. We fold in new jobs, guides, and community work too. Free, independent, no sponsorship. Read the archive below or get it in your inbox.
New issues publish every Tuesday morning, Pacific time. 10 issues so far.
A CVSS 10.0 Entra ID flaw that Microsoft first marked exploited and then unmarked, a Keycloak reset that skips the email token entirely, and Mirage2FA reaching 4,500 organizations by stealing sessions instead of breaking MFA.
Active Directory had a bad week: KerberLoss twins an SPN with invisible Unicode and ResetNightmare resets a Domain Admin from a low-privilege account. Plus a SharePoint PoC that turned into exploitation in 48 hours.
Black Hat week. Three passkey attacks that leave the cryptography alone, two CVSS 10.0 flaws, a GitHub issue reaching CI secrets, and GhostSplice driving coding agents to exfiltrate by splitting the instruction.
Two AI agents used stolen credentials this week, one of them Anthropic's own during a botched security test. Plus OWAReaper surviving credential rotation, Okta buying Permiso, and device code phishing at 25 kits.
The busiest week of the summer: a phishing-as-a-service takedown with 1,800 customers, four authentication bypasses, Certighost forging Domain Controller certificates, and Cyera buying Oasis for a billion dollars.
Google puts FIDO2 keys into Windows login days after Entra makes passkeys default, ransomware affiliates adopt a patched PAN-OS bypass as a front door, and a two-finger gesture sent SMS from a locked Android phone.
Microsoft makes passkeys the Entra default and retires SMS in 2027, and in the same week attackers phish the passkey enrollment flow. Plus a SharePoint JWT bypass and six months of AWS GovCloud keys in a public repo.
OAuth consent phishing gets a name and a kit, SailPoint closes its Entro deal, and EMVCo drafts one credential standard so merchants stop building per-wallet integrations.
Digital identity goes national: the EU's wallet deadline closes in, India's data-protection rules set their clock, and we publish a directory of 86 national eID schemes across 51 countries.
World Passkey Day puts a number on adoption: an estimated 5 billion passkeys in active use. Plus RSA brings passwordless to Linux, and a FIDO and HID study finds enterprise confidence outruns operational reality.