Advertisement
SSL.com Root Certificate Rotation: Technical Guide and Impact Analysis
SSL.com is rotating its root certificate on May 5, 2026. Learn how this lifecycle event affects PKI trust and how to troubleshoot validation issues.
Cisco Acquires Astrix: Tackling Non-Human Identity Risks for AI & Machines
Cisco's acquisition of Astrix Security targets emerging non-human identity risks in AI and machine access, enhancing identity-centric security for cloud environments.
Identity-Based Fraud Tactics Targeting Credit Unions
Analysis of structured loan fraud targeting credit unions through stolen identities, KYC bypass techniques, and synthetic credential exploitation.
OpenAI Advanced Account Security: Mitigating AI Identity Risks
OpenAI releases Advanced Account Security features for ChatGPT, including FIDO2 support and session management to prevent unauthorized account access.
Managed Windows 11 Bloatware Removal: New IT Admin Policy Controls
Microsoft updates Windows 11 policy allowing IT admins to selectively uninstall pre-installed Store apps, reducing the attack surface in managed environments.
Oracle Red Bull Racing: Securing F1 IP via Identity Automation
Discover how Oracle Red Bull Racing leverages identity governance automation to protect intellectual property and streamline security in high-stakes F1 environments.
Roblox Account Hijacking: 610,000 Accounts Compromised and Sold
Ukrainian police arrested a group for hijacking 610,000 Roblox accounts and generating $225,000 in profits through illegal sales of user data.
Zero Trust Implementation Stalled by Secure Data Movement Bottlenecks
New Cyber360 research reveals why organizations fail to achieve Zero Trust by prioritizing network connectivity over granular data movement security.
Microsoft Entra ID Flaw: Agent ID Administrator Role Escalation
Microsoft patches a critical logic flaw in the Entra ID Agent ID Administrator role that allowed attackers to take over service principals and escalate privileges.
Microsoft Outlook.com Sign-In Failures: Analysis of Ongoing Outage
Microsoft confirms an Outlook.com outage causing intermittent sign-in failures and mailbox access issues. Learn about the impact on enterprise productivity.
Secure AI Agent Delegation: Bridging the Authority Gap
AI agents introduce a structural authority gap in enterprise security. Learn how continuous observability serves as a decision engine for delegation.
Multi-Signal Fraud Prevention for the Customer Journey
Protect digital platforms from account takeover and payment fraud. This guide covers how identity, device, and network signals improve security without friction.
Defending Against Identity-Based Attacks and Stolen Credentials
Identity-based attacks use stolen credentials to bypass security. Learn why these attacks are the primary entry point and how to mitigate the risk.
OAuth Token Hijacking in AI Tools: Vercel Breach Analysis
An investigation into how stolen OAuth tokens from a Vercel employee's AI tool session led to unauthorized internal access and the risks of AI integration.
DraftKings Hacker Sentenced: Lessons in Credential Stuffing Defense
Analysis of the sentencing of Kamerin Stokes following the 2022 DraftKings breach, detailing credential stuffing TTPs and account takeover prevention strategies.
DraftKings Credential Stuffing: Memphis Man Sentenced to 30 Months
Kamerin Stokes sentenced to 30 months for selling 60,000+ hacked DraftKings accounts. Technical analysis of the 2022 credential stuffing attack and mitigations.
Securing Non-Human Identities: Preventing Orphaned API Key Exploits
Unmanaged non-human identities caused 68% of 2024 cloud breaches. Learn technical strategies for managing orphaned service accounts and API tokens.
Identity-First Zero Trust Strategies to Prevent Credential Theft
Learn how Zero Trust architecture mitigates stolen credentials and lateral movement by enforcing device trust, least privilege, and continuous verification.
VIP Credential Monitoring: Defending High-Value Targets
Learn how VIP credential monitoring protects high-privilege users from account takeover by tracking exposures across personal and corporate email domains.
Detecting Credential-Based Attacks: Moving Beyond Signatures
Identity-based attacks leverage valid credentials to mimic legitimate activity, requiring a shift toward behavioral detection and identity-centric monitoring.
Chrome DBSC: Securing Session Cookies with Device Binding — Analysis
Google introduces Device Bound Session Credentials in Chrome to combat session hijacking by cryptographically linking authentication cookies to local hardware.
Google Chrome 146 DBSC Implementation Hardens Windows Against Session Hijacking
Google releases Device Bound Session Credentials (DBSC) in Chrome 146 for Windows to mitigate cookie theft and session hijacking via hardware-backed security.
Honeypot Data Analysis: Predictable Year and Season Password Patterns
SANS ISC research reveals how attackers exploit predictable password patterns, such as years and seasons, driven by outdated rotation policies.
Consumer GPUs vs Enterprise Hardware for Password Cracking
Analysis of research comparing the NVIDIA H100 and RTX 4090 for password cracking, highlighting why attackers favor consumer-grade hardware for brute-force.