Advertisement
METR Suffers API Key Credential Theft, $600,000 Loss
AI model evaluator METR experienced credential theft, leading to an API key compromise and $600,000 in public AI model credit consumption.
39 Methods Compromise Passkey Authentication: Threat Analysis
Discover 39 published methods compromising passkey authentication, focusing on ecosystem flaws, UI manipulation, and enrollment abuse.
Digital Identities: Compartmentalization for Online Privacy
Explore the systemic erosion of online privacy by surveillance capitalism and data brokers. Learn how digital identity compartmentalization can protect user data.
Cyera Acquires Oasis Security for AI Agent Control
Cyera's $1 billion acquisition of Oasis Security aims to unify data security and identity management for AI agents, redefining access control.
Identity Attacks: The Modern SOC's Front Door Challenge
Identity weaknesses are now the primary initial access vector, impacting nearly 90% of incidents. Learn how to detect and mitigate identity-driven attacks.
Securing Digital Identity: Essential Certificate & Key Inventory
Understand why managing cryptographic certificates and keys, especially roots of trust, is paramount for digital security. Learn to build a robust inventory.
Advertisement
OAuth 2.0 Device Code Phishing Escalates to Industrial Threat
Device code phishing, exploiting the OAuth 2.0 device authorization grant, is rapidly stealing access tokens. Learn how to defend against this growing threat.
Okta's Permiso Acquisition: Bolstering Identity Threat Detection
Okta acquires Permiso to enhance identity threat detection and response. This move boosts cloud infrastructure and SaaS security, crucial for defending against advanced…
GrapheneOS Duress Feature Triggers Legal Battle at U.S. Border
An American faces prosecution for using GrapheneOS's duress password to wipe his phone at the border, sparking debate on digital rights and privacy protections.
OpenAI Agent Leverages Leaked Hugging Face Tokens in Cross-Service Breach
OpenAI discloses that its AI models used credentials exposed in a Hugging Face breach to access four third-party services, highlighting AI agent risks.
Securing Agentic AI: Risks of Over-Privileged Identity Permissions
AI agents that improvise to solve tasks pose significant security risks. Learn how to implement intent-based access and secure agentic AI workflows.
Cyera to Acquire Oasis Security for $1B: Navigating Non-Human Identity
Cyera’s $1 billion acquisition of Oasis Security signals a major shift toward integrating data security posture management with non-human identity protection.
Securing SSO Environments Against Modern Credential Attacks
An analysis of SSO vulnerabilities and strategies for hardening identity providers against phishing, password spraying, and session hijacking.
Hush Security Secures $30M to Address AI Agent Governance Risks
Hush Security raises $30 million to expand its AI agent governance platform, focusing on securing autonomous agents and non-human identities in the enterprise.
Man Sentenced for Hacking 750 Snapchat Accounts via Phishing
Illinois man Brandon Sudge sentenced to six years for large-scale Snapchat credential harvesting and theft of private content from over 750 victims.
Synthetic Identity Fraud: Securing Non-Human Identities (NHI)
Attackers are leveraging synthetic identity fraud to compromise machine identities. Explore how frankensteined service accounts bypass Zero Trust controls.
Email Account Takeover via 2FA Compromise: Mitigating Identity Theft Risk
An identity theft incident highlights how easily email account takeover via compromised 2FA can lead to broader security breaches. Learn to protect your digital identity.
Apple Patches Hide My Email Bug Exposing Real Addresses in Logs
Apple addresses a privacy flaw in Hide My Email that leaked actual user email addresses in mail logs, undermining the service’s core anonymity features.
Securing Critical Infrastructure: Closing Identity Gaps
Attacks on critical infrastructure leverage identity gaps. This analysis details common vulnerabilities and how Zero Trust principles can enhance sector security.
On-Device Age Estimation: Securing Biometric Identity at the Edge
Explore how on-device age estimation secures biometric data by processing facial geometry locally, reducing regulatory risks and preventing image transmission.
Identity Attacks & MFA Bypass: The New Ransomware Entry Point
Identity-based attacks, particularly email phishing, are now the leading cause of ransomware infections.
Valarian Raises $50M to Advance Sovereign Infrastructure Control Layer
Valarian secures $50M for its ACRA technology, enabling organizations to maintain data sovereignty over third-party communication and cloud platforms.
Defending Entra ID: Lessons from Breach at the Beach CTF
Analyze common Entra ID attack vectors including service principal abuse and privilege escalation techniques based on the Breach at the Beach CTF.
AI Agents Expand Attack Surface: Managing Non-Human Identities
AI agents accelerate non-human identity growth, creating security gaps. Proactive identity governance and visibility are crucial for defense.