Advertisement
Insider Threat: Former Engineer Locks 254 Windows Servers in Extortion
A former infrastructure engineer pleaded guilty to a $750,000 extortion plot after locking administrators out of 254 Windows servers and deleting backups.
Linx Security Boosts Identity Governance Solutions with $50M Funding
Linx Security secures $50M funding, accelerating product development and global reach for its identity security and governance platform, underscoring identity…
Google Gmail Address Migration: Security and Identity Implications
Google introduces Gmail address changes in the U.S., presenting new challenges for identity verification, account recovery, and phishing defense.
Android Developer Identity Verification: New Google Play Mandates
Google mandates identity verification for all Android developers to reduce malicious app distribution and improve Play Store transparency starting September.
OpenAI Codex Vulnerability Exposed GitHub Tokens via OAuth Flaw
Researchers discovered a critical OpenAI Codex vulnerability allowing GitHub token theft via OAuth flaws, risking unauthorized access to private repositories.
Password Management Deficiencies: Manufacturing & Healthcare Risk
Analysis of critical password management weaknesses in manufacturing and healthcare sectors. Explores insider views, attacker exploitation, and mitigation strategies.
Advertisement
GitGuardian 2026 Report: Analyzing the 34% Surge in Secrets Sprawl
GitGuardian's 2026 report reveals 29 million leaked secrets on GitHub in 2025. Learn how AI and hardcoded credentials impact enterprise security posture.
Beyond MFA: Bridging the Zero Trust Gap in Session Security
Authentication alone does not equate to trust. Discover how session token hijacking bypasses MFA and why device health is critical for Zero Trust.
Gartner Market Guide for Guardian Agents: Securing AI and NHIs
Analysis of the inaugural Gartner Market Guide for Guardian Agents, focusing on securing non-human identities and AI agents in complex cloud environments.
KB5085516 Emergency Update: Fix for Microsoft Account Sign-in Failures
Microsoft releases emergency KB5085516 update to resolve widespread authentication failures affecting OneDrive, Teams, and other cloud-integrated services.
Proton Mail Metadata Disclosure: Understanding Legal Data Requests
Analysis of Proton Mail's metadata disclosure to Swiss authorities and the FBI, highlighting the risks of de-anonymization via payment information.
Agentic Access Management & AI: Emerging Security Focus
Oasis Security's $120M funding highlights agentic access management & AI framework security. This analysis explores implications for cyber defense.
Securing Claude Code: Managing AI Agent Risk with Ceros Visibility
Discover how Claude Code creates new security challenges for engineering teams and how Ceros provides the visibility needed to govern autonomous AI agents.
Credential Theft Surge: Understanding Infostealer & AI Social Engineering
Credential theft surged in late 2025, driven by sophisticated infostealer malware and AI-enhanced social engineering.
Securing Autonomous AI Agents: Identity and Access Management
Enterprises must address the security risks of autonomous AI agents by treating them as non-human identities with granular access controls and monitoring.
2025 Identity Threat Report: Analyzing the Infostealer Economy
Recorded Future's 2025 Identity Threat Landscape Report examines how infostealer malware and session cookie theft drive the modern credential threat economy.
Betterleaks: A New Open-Source Tool for Detecting Secrets in Git
Betterleaks is a new open-source secrets scanner designed to identify hardcoded credentials and sensitive data across directories and Git repositories.
WhatsApp Introduces Parent-Managed Accounts for Pre-Teens
WhatsApp rolls out new parent-managed accounts, enabling guardians to control contact lists and group access for pre-teen users, enhancing digital safety.
Entra Passkeys: Phishing-Resistant Windows Sign-In Deployment
Microsoft introduces phishing-resistant passkey support for Entra ID on Windows, leveraging Windows Hello to secure the sign-in process against credential theft.
Microsoft Teams Third-Party Bot Tagging Enhances Meeting Security
Microsoft Teams updates meeting lobbies to identify third-party bots, helping administrators prevent unauthorized data collection and social engineering.
Rethinking Password Audits: Protecting Breached & Service Accounts
Traditional password audits often miss critical attack vectors. Learn how compromised credentials, orphaned, and service accounts pose significant threats and how to…
Credential Abuse Risks: Solving Microsoft Entra ID MFA Coverage Gaps
Examine how coverage gaps in Microsoft Entra ID and Okta MFA implementations allow attackers to exploit valid credentials within Windows network environments.
Bitwarden Passkey Login for Windows 11: Implementation Guide
Bitwarden introduces passkey login support for Windows 11, providing phishing-resistant authentication using FIDO2 standards for enhanced account security.
Chrome to Adopt Merkle Tree Certificates for Post-Quantum HTTPS
Google introduces Merkle Tree Certificates in Chrome to enable quantum-resistant HTTPS, addressing scalability issues found in traditional X.509 PQC signatures.