Advertisement
Entra Passkeys: Phishing-Resistant Windows Sign-In Deployment
Microsoft introduces phishing-resistant passkey support for Entra ID on Windows, leveraging Windows Hello to secure the sign-in process against credential theft.
Microsoft Teams Third-Party Bot Tagging Enhances Meeting Security
Microsoft Teams updates meeting lobbies to identify third-party bots, helping administrators prevent unauthorized data collection and social engineering.
Rethinking Password Audits: Protecting Breached & Service Accounts
Traditional password audits often miss critical attack vectors. Learn how compromised credentials, orphaned, and service accounts pose significant threats and how to
Credential Abuse Risks: Solving Microsoft Entra ID MFA Coverage Gaps
Examine how coverage gaps in Microsoft Entra ID and Okta MFA implementations allow attackers to exploit valid credentials within Windows network environments.
Bitwarden Passkey Login for Windows 11: Implementation Guide
Bitwarden introduces passkey login support for Windows 11, providing phishing-resistant authentication using FIDO2 standards for enhanced account security.
Chrome to Adopt Merkle Tree Certificates for Post-Quantum HTTPS
Google introduces Merkle Tree Certificates in Chrome to enable quantum-resistant HTTPS, addressing scalability issues found in traditional X.509 PQC signatures.
Deepfake and Digital Injection Attacks Target Identity Verification
Attackers use deepfakes and digital injection to bypass biometric security. Learn how to secure identity verification sessions against synthetic fraud.
Google’s Path to Quantum-Safe Chrome HTTPS via Merkle Tree Certificates
Google is developing Merkle Tree Certificates (MTCs) for Chrome to transition the web toward post-quantum cryptography and enhance HTTPS certificate security.
CrowdStrike Falcon ID: Phishing-Resistant MFA via FIDO2 Standards
CrowdStrike Falcon ID integrates FIDO2-based MFA into the Falcon platform to combat AiTM attacks and identity-based threats across hybrid environments.
Gambit Security Raises $61M to Converge Physical and Cyber Security
Gambit Security exits stealth with $61M in funding to integrate physical access control and video surveillance into modern enterprise IT security stacks.
Entropy Deficiencies in LLM-Generated Passwords
Research indicates that Large Language Models produce predictable passwords with biased character distributions, increasing vulnerability to targeted attacks.
Mitigating Identity Risks in Autonomous AI Agent Workflows
Enterprise security must evolve to manage AI agents as non-human identities (NHIs) by implementing intent-based controls and solving over-scoped privilege risks.
Identity Prioritization: Shifting from Backlogs to Risk Math
Enterprise identity programs must evolve from ticket-based prioritization to dynamic risk math models to manage the surge of human and non-human identities.
Sentenced: Ukrainian National Facilitated DPRK IT Worker Infrastructure
Oleksandr Didenko sentenced to five years for orchestrating an identity laundering scheme that enabled North Korean operatives to infiltrate Western corporate networks.
Token Theft and Session Hijacking: Mitigating Device Trust Failures
An analysis of post-authentication attack vectors involving token theft and the technical requirement for continuous device posture verification within Zero Trust frameworks.
Cryptographic Flaws in Password Manager Zero-Knowledge Architectures
Technical analysis of Bitwarden, Dashlane, and LastPass reveals server-side attack vectors that bypass zero-knowledge encryption through account recovery and group sharing mechanisms.