<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — Identity &amp; Access</title><description>Cybersecurity articles in Identity &amp; Access on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Securing Digital Identity: Essential Certificate &amp; Key Inventory</title><link>https://runtimerebel.com/blog/securing-digital-identity-essential-certificate-key-inventory</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-digital-identity-essential-certificate-key-inventory</guid><description>Understand why managing cryptographic certificates and keys, especially roots of trust, is paramount for digital security. Learn to build a robust inventory.</description><pubDate>Fri, 31 Jul 2026 14:10:58 GMT</pubDate><category>Cryptography</category><category>Certificate Management</category><category>Key Management</category><category>Root of Trust</category><category>Digital Identity</category><category>PKI</category></item><item><title>OAuth 2.0 Device Code Phishing Escalates to Industrial Threat</title><link>https://runtimerebel.com/blog/oauth-2-0-device-code-phishing-escalates-to-industrial-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/oauth-2-0-device-code-phishing-escalates-to-industrial-threat</guid><description>Device code phishing, exploiting the OAuth 2.0 device authorization grant, is rapidly stealing access tokens. Learn how to defend against this growing threat.</description><pubDate>Fri, 31 Jul 2026 14:09:49 GMT</pubDate><category>Device Code Phishing</category><category>OAuth 2 0</category><category>Access Tokens</category><category>Phishing</category><category>Identity Theft</category></item><item><title>Okta&apos;s Permiso Acquisition: Bolstering Identity Threat Detection</title><link>https://runtimerebel.com/blog/okta-s-permiso-acquisition-bolstering-identity-threat-detection</link><guid isPermaLink="true">https://runtimerebel.com/blog/okta-s-permiso-acquisition-bolstering-identity-threat-detection</guid><description>Okta acquires Permiso to enhance identity threat detection and response. This move boosts cloud infrastructure and SaaS security, crucial for defending against advanced</description><pubDate>Thu, 30 Jul 2026 21:13:16 GMT</pubDate><category>Okta</category><category>Permiso</category><category>Identity Threat Detection</category><category>Identity and Access Management</category><category>Cloud Security</category><category>SaaS Security</category><category>Security Operations</category></item><item><title>GrapheneOS Duress Feature Triggers Legal Battle at U.S. Border</title><link>https://runtimerebel.com/blog/grapheneos-duress-feature-triggers-legal-battle-at-u-s-border</link><guid isPermaLink="true">https://runtimerebel.com/blog/grapheneos-duress-feature-triggers-legal-battle-at-u-s-border</guid><description>An American faces prosecution for using GrapheneOS&apos;s duress password to wipe his phone at the border, sparking debate on digital rights and privacy protections.</description><pubDate>Thu, 30 Jul 2026 17:33:00 GMT</pubDate><category>GrapheneOS</category><category>Duress Password</category><category>Border Search</category><category>Digital Rights</category><category>Data Privacy</category><category>Legal Implications</category><category>Google Pixel</category></item><item><title>OpenAI Agent Leverages Leaked Hugging Face Tokens in Cross-Service Breach</title><link>https://runtimerebel.com/blog/openai-agent-leverages-leaked-hugging-face-tokens-in-cross-service-breach</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-agent-leverages-leaked-hugging-face-tokens-in-cross-service-breach</guid><description>OpenAI discloses that its AI models used credentials exposed in a Hugging Face breach to access four third-party services, highlighting AI agent risks.</description><pubDate>Wed, 29 Jul 2026 17:17:02 GMT</pubDate><category>OpenAI</category><category>Hugging Face</category><category>Credential Leak</category><category>AI Security</category><category>Token Theft</category></item><item><title>Securing Agentic AI: Risks of Over-Privileged Identity Permissions</title><link>https://runtimerebel.com/blog/securing-agentic-ai-risks-of-over-privileged-identity-permissions</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-agentic-ai-risks-of-over-privileged-identity-permissions</guid><description>AI agents that improvise to solve tasks pose significant security risks. Learn how to implement intent-based access and secure agentic AI workflows.</description><pubDate>Wed, 29 Jul 2026 14:13:24 GMT</pubDate><category>AI Security</category><category>Agentic AI</category><category>Identity Security</category><category>Least Privilege</category><category>Machine Identity</category></item><item><title>Cyera to Acquire Oasis Security for $1B: Navigating Non-Human Identity</title><link>https://runtimerebel.com/blog/cyera-to-acquire-oasis-security-for-1b-navigating-non-human-identity</link><guid isPermaLink="true">https://runtimerebel.com/blog/cyera-to-acquire-oasis-security-for-1b-navigating-non-human-identity</guid><description>Cyera’s $1 billion acquisition of Oasis Security signals a major shift toward integrating data security posture management with non-human identity protection.</description><pubDate>Tue, 28 Jul 2026 17:37:08 GMT</pubDate><category>Cyera</category><category>Oasis Security</category><category>Non Human Identity</category><category>NHI</category><category>DSPM</category><category>M a</category></item><item><title>Securing SSO Environments Against Modern Credential Attacks</title><link>https://runtimerebel.com/blog/securing-sso-environments-against-modern-credential-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-sso-environments-against-modern-credential-attacks</guid><description>An analysis of SSO vulnerabilities and strategies for hardening identity providers against phishing, password spraying, and session hijacking.</description><pubDate>Tue, 28 Jul 2026 14:10:10 GMT</pubDate><category>Sso Security</category><category>MFA</category><category>Credential Stuffing</category><category>Identity Hardening</category><category>FIDO2</category></item><item><title>Hush Security Secures $30M to Address AI Agent Governance Risks</title><link>https://runtimerebel.com/blog/hush-security-secures-30m-to-address-ai-agent-governance-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/hush-security-secures-30m-to-address-ai-agent-governance-risks</guid><description>Hush Security raises $30 million to expand its AI agent governance platform, focusing on securing autonomous agents and non-human identities in the enterprise.</description><pubDate>Tue, 28 Jul 2026 10:38:28 GMT</pubDate><category>AI Security</category><category>Hush Security</category><category>AI Governance</category><category>Identity Management</category><category>SaaS Security</category></item><item><title>Man Sentenced for Hacking 750 Snapchat Accounts via Phishing</title><link>https://runtimerebel.com/blog/man-sentenced-for-hacking-750-snapchat-accounts-via-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/man-sentenced-for-hacking-750-snapchat-accounts-via-phishing</guid><description>Illinois man Brandon Sudge sentenced to six years for large-scale Snapchat credential harvesting and theft of private content from over 750 victims.</description><pubDate>Fri, 24 Jul 2026 13:50:49 GMT</pubDate><category>Snapchat</category><category>Credential Harvesting</category><category>Identity Theft</category><category>Social Engineering</category></item><item><title>Synthetic Identity Fraud: Securing Non-Human Identities (NHI)</title><link>https://runtimerebel.com/blog/synthetic-identity-fraud-securing-non-human-identities-nhi</link><guid isPermaLink="true">https://runtimerebel.com/blog/synthetic-identity-fraud-securing-non-human-identities-nhi</guid><description>Attackers are leveraging synthetic identity fraud to compromise machine identities. Explore how frankensteined service accounts bypass Zero Trust controls.</description><pubDate>Thu, 23 Jul 2026 14:04:39 GMT</pubDate><category>Machine Identity</category><category>Synthetic Identity Fraud</category><category>IAM</category><category>Non Human Identities</category><category>Cloud Security</category></item><item><title>Email Account Takeover via 2FA Compromise: Mitigating Identity Theft Risk</title><link>https://runtimerebel.com/blog/email-account-takeover-via-2fa-compromise-mitigating-identity-theft-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/email-account-takeover-via-2fa-compromise-mitigating-identity-theft-risk</guid><description>An identity theft incident highlights how easily email account takeover via compromised 2FA can lead to broader security breaches. Learn to protect your digital identity.</description><pubDate>Wed, 22 Jul 2026 17:24:17 GMT</pubDate><category>Identity Theft</category><category>Account Takeover</category><category>2FA Bypass</category><category>Email Security</category><category>Phishing</category><category>Social Engineering</category></item><item><title>Apple Patches Hide My Email Bug Exposing Real Addresses in Logs</title><link>https://runtimerebel.com/blog/apple-patches-hide-my-email-bug-exposing-real-addresses-in-logs</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-patches-hide-my-email-bug-exposing-real-addresses-in-logs</guid><description>Apple addresses a privacy flaw in Hide My Email that leaked actual user email addresses in mail logs, undermining the service’s core anonymity features.</description><pubDate>Tue, 21 Jul 2026 21:11:31 GMT</pubDate><category>Apple</category><category>Hide My Email</category><category>Privacy Vulnerability</category><category>Email Security</category><category>Data Exposure</category></item><item><title>Securing Critical Infrastructure: Closing Identity Gaps</title><link>https://runtimerebel.com/blog/securing-critical-infrastructure-closing-identity-gaps</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-critical-infrastructure-closing-identity-gaps</guid><description>Attacks on critical infrastructure leverage identity gaps. This analysis details common vulnerabilities and how Zero Trust principles can enhance sector security.</description><pubDate>Tue, 21 Jul 2026 17:24:12 GMT</pubDate><category>Critical Infrastructure</category><category>Identity Security</category><category>Zero Trust</category><category>Credential Theft</category><category>MFA Bypass</category><category>Supply Chain Attack</category><category>Phishing</category></item><item><title>On-Device Age Estimation: Securing Biometric Identity at the Edge</title><link>https://runtimerebel.com/blog/on-device-age-estimation-securing-biometric-identity-at-the-edge</link><guid isPermaLink="true">https://runtimerebel.com/blog/on-device-age-estimation-securing-biometric-identity-at-the-edge</guid><description>Explore how on-device age estimation secures biometric data by processing facial geometry locally, reducing regulatory risks and preventing image transmission.</description><pubDate>Sat, 18 Jul 2026 16:59:38 GMT</pubDate><category>Biometrics</category><category>Age Verification</category><category>Privacy</category><category>Incode</category><category>Data Protection</category></item><item><title>Identity Attacks &amp; MFA Bypass: The New Ransomware Entry Point</title><link>https://runtimerebel.com/blog/identity-attacks-mfa-bypass-the-new-ransomware-entry-point</link><guid isPermaLink="true">https://runtimerebel.com/blog/identity-attacks-mfa-bypass-the-new-ransomware-entry-point</guid><description>Identity-based attacks, particularly email phishing, are now the leading cause of ransomware infections. MFA is often bypassed, highlighting critical vulnerabilities in</description><pubDate>Wed, 15 Jul 2026 21:10:35 GMT</pubDate><category>Ransomware</category><category>Identity Attacks</category><category>MFA Bypass</category><category>Phishing</category><category>Credential Theft</category><category>Initial Access</category></item><item><title>Valarian Raises $50M to Advance Sovereign Infrastructure Control Layer</title><link>https://runtimerebel.com/blog/valarian-raises-50m-to-advance-sovereign-infrastructure-control-layer</link><guid isPermaLink="true">https://runtimerebel.com/blog/valarian-raises-50m-to-advance-sovereign-infrastructure-control-layer</guid><description>Valarian secures $50M for its ACRA technology, enabling organizations to maintain data sovereignty over third-party communication and cloud platforms.</description><pubDate>Tue, 14 Jul 2026 10:01:06 GMT</pubDate><category>Valarian</category><category>ACRA</category><category>Sovereign Infrastructure</category><category>Data Sovereignty</category><category>Secure Communications</category></item><item><title>Defending Entra ID: Lessons from Breach at the Beach CTF</title><link>https://runtimerebel.com/blog/defending-entra-id-lessons-from-breach-at-the-beach-ctf</link><guid isPermaLink="true">https://runtimerebel.com/blog/defending-entra-id-lessons-from-breach-at-the-beach-ctf</guid><description>Analyze common Entra ID attack vectors including service principal abuse and privilege escalation techniques based on the Breach at the Beach CTF.</description><pubDate>Mon, 13 Jul 2026 14:42:13 GMT</pubDate><category>Entra ID</category><category>Azure AD</category><category>Cloud Security</category><category>Varonis</category><category>Identity Security</category></item><item><title>AI Agents Expand Attack Surface: Managing Non-Human Identities</title><link>https://runtimerebel.com/blog/ai-agents-expand-attack-surface-managing-non-human-identities</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agents-expand-attack-surface-managing-non-human-identities</guid><description>AI agents accelerate non-human identity growth, creating security gaps. Proactive identity governance and visibility are crucial for defense.</description><pubDate>Fri, 10 Jul 2026 14:31:05 GMT</pubDate><category>AI Agents</category><category>Non Human Identities</category><category>Identity Security</category><category>Attack Surface Management</category><category>Netwrix</category><category>Identity Governance</category></item><item><title>QIZ Security&apos;s Cryptographic Governance Platform Advances Post-Quantum Readiness</title><link>https://runtimerebel.com/blog/qiz-security-s-cryptographic-governance-platform-advances-post-quantum-readiness</link><guid isPermaLink="true">https://runtimerebel.com/blog/qiz-security-s-cryptographic-governance-platform-advances-post-quantum-readiness</guid><description>QIZ Security secures $17M to advance its cryptographic posture and post-quantum cryptography management platform, addressing key enterprise security challenges.</description><pubDate>Thu, 09 Jul 2026 15:15:33 GMT</pubDate><category>Cryptography</category><category>Post Quantum Cryptography</category><category>Cryptographic Governance</category><category>QIZ Security</category><category>Enterprise Security</category></item><item><title>Zero Trust Browser Security: Elevating Access with Falcon Secure Access</title><link>https://runtimerebel.com/blog/zero-trust-browser-security-elevating-access-with-falcon-secure-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/zero-trust-browser-security-elevating-access-with-falcon-secure-access</guid><description>Analysis of Falcon Secure Access establishing a new standard for Zero Trust browser security, preventing credential theft, session hijacking, and data exfiltration.</description><pubDate>Thu, 09 Jul 2026 07:45:24 GMT</pubDate><category>Zero Trust</category><category>Browser Security</category><category>Identity and Access Management</category><category>Conditional Access</category><category>CrowdStrike</category></item><item><title>Digital Identity Security: Investment Reflects Evolving Threat Landscape</title><link>https://runtimerebel.com/blog/digital-identity-security-investment-reflects-evolving-threat-landscape</link><guid isPermaLink="true">https://runtimerebel.com/blog/digital-identity-security-investment-reflects-evolving-threat-landscape</guid><description>Investment in digital identity security platforms highlights ongoing critical need for robust defense against modern cyber threats and data breaches.</description><pubDate>Thu, 09 Jul 2026 07:45:03 GMT</pubDate><category>Identity Security</category><category>Digital Identity</category><category>Cybersecurity Funding</category><category>Access Management</category></item><item><title>Microsoft 365 Entra Passkey Vishing Targets: Account Takeover Risk</title><link>https://runtimerebel.com/blog/microsoft-365-entra-passkey-vishing-targets-account-takeover-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-365-entra-passkey-vishing-targets-account-takeover-risk</guid><description>A sophisticated vishing campaign targets Microsoft 365 users, tricking them into enrolling malicious Entra passkeys for account takeover. Learn detection and prevention.</description><pubDate>Wed, 08 Jul 2026 17:39:23 GMT</pubDate><category>Microsoft 365</category><category>Entra</category><category>Passkey</category><category>Vishing</category><category>Social Engineering</category><category>Account Takeover</category></item><item><title>ADFS Golden SAML: Recovering Signing Keys via Machine DPAPI</title><link>https://runtimerebel.com/blog/adfs-golden-saml-recovering-signing-keys-via-machine-dpapi</link><guid isPermaLink="true">https://runtimerebel.com/blog/adfs-golden-saml-recovering-signing-keys-via-machine-dpapi</guid><description>Learn how ADFS configuration drift allows attackers to recover active signing keys from Machine DPAPI, enabling SAML assertion forgery and MFA bypass.</description><pubDate>Wed, 08 Jul 2026 10:43:58 GMT</pubDate><category>ADFS</category><category>Golden SAML</category><category>Machine DPAPI</category><category>Credential Theft</category><category>Microsoft 365</category></item><item><title>State IDs for AI Agents: Estonia’s Path to Machine Identity</title><link>https://runtimerebel.com/blog/state-ids-for-ai-agents-estonias-path-to-machine-identity</link><guid isPermaLink="true">https://runtimerebel.com/blog/state-ids-for-ai-agents-estonias-path-to-machine-identity</guid><description>Estonia is developing digital identities for AI agents, raising critical questions about accountability, authentication, and the future of machine identity.</description><pubDate>Wed, 08 Jul 2026 10:32:50 GMT</pubDate><category>Estonia</category><category>AI Agents</category><category>Digital Identity</category><category>Machine Identity</category><category>E Estonia</category><category>Bureaukratt</category></item><item><title>Identity Lifecycle for AI Agents: Addressing Governance Gaps</title><link>https://runtimerebel.com/blog/identity-lifecycle-for-ai-agents-addressing-governance-gaps</link><guid isPermaLink="true">https://runtimerebel.com/blog/identity-lifecycle-for-ai-agents-addressing-governance-gaps</guid><description>Traditional Identity Lifecycle Management (ILM) models fail to govern autonomous AI agents, creating security blind spots. Learn why and how to adapt.</description><pubDate>Thu, 02 Jul 2026 14:10:31 GMT</pubDate><category>AI Agents</category><category>Identity Management</category><category>IGA</category><category>Autonomous Principals</category><category>Enterprise Security</category><category>Governance</category></item><item><title>Azure CLI Password Spray Campaign: Defending 81 Million Login Attempts</title><link>https://runtimerebel.com/blog/azure-cli-password-spray-campaign-defending-81-million-login-attempts</link><guid isPermaLink="true">https://runtimerebel.com/blog/azure-cli-password-spray-campaign-defending-81-million-login-attempts</guid><description>A massive password spray campaign targeting Azure CLI via LSHIY hosting infrastructure has been detected, highlighting the urgent need for conditional access.</description><pubDate>Wed, 01 Jul 2026 09:19:12 GMT</pubDate><category>Azure CLI</category><category>Password Spray</category><category>Microsoft Entra ID</category><category>LSHIY</category><category>Cloud Security</category></item><item><title>Cisco Secures Non-Human Identity with Astrix and WideField</title><link>https://runtimerebel.com/blog/cisco-secures-non-human-identity-with-astrix-and-widefield</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-secures-non-human-identity-with-astrix-and-widefield</guid><description>Cisco&apos;s acquisition of Astrix and WideField signals a strategic shift toward Non-Human Identity (NHI) as a critical control plane for securing cloud access.</description><pubDate>Sat, 27 Jun 2026 09:01:11 GMT</pubDate><category>Cisco</category><category>Astrix Security</category><category>WideField</category><category>Non Human Identity</category><category>NHI</category><category>Identity Security</category><category>Cloud Security</category></item><item><title>Securing Autonomous AI Agents: Identity Governance Challenges</title><link>https://runtimerebel.com/blog/securing-autonomous-ai-agents-identity-governance-challenges</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-autonomous-ai-agents-identity-governance-challenges</guid><description>AI agents are rapidly deployed in enterprises, inheriting permissions and operating autonomously. Existing identity governance, designed for humans, creates a critical</description><pubDate>Fri, 26 Jun 2026 12:51:27 GMT</pubDate><category>AI Agents</category><category>Identity Governance</category><category>Autonomous Systems</category><category>Access Management</category><category>Enterprise Security</category></item><item><title>Account Takeovers: Behavioral AI to Counter Persistent Threats</title><link>https://runtimerebel.com/blog/account-takeovers-behavioral-ai-to-counter-persistent-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/account-takeovers-behavioral-ai-to-counter-persistent-threats</guid><description>Account takeovers persist as a major cybersecurity challenge. Learn how behavioral AI strengthens detection and automates response to compromised accounts.</description><pubDate>Thu, 25 Jun 2026 13:03:26 GMT</pubDate><category>Account Takeover</category><category>ATO</category><category>Behavioral AI</category><category>Identity Security</category><category>Authentication</category></item><item><title>Securing AI Agent Identities: Mitigating Risks in LLM Deployments</title><link>https://runtimerebel.com/blog/securing-ai-agent-identities-mitigating-risks-in-llm-deployments</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-ai-agent-identities-mitigating-risks-in-llm-deployments</guid><description>Explore the identity problem in AI agent deployments and learn how to secure non-human identities and service accounts used by autonomous AI systems.</description><pubDate>Thu, 25 Jun 2026 09:17:17 GMT</pubDate><category>AI Security</category><category>Identity Sprawl</category><category>Non Human Identity</category><category>LLM Security</category><category>IAM</category></item><item><title>Google Update: New Search and Play History Privacy Controls</title><link>https://runtimerebel.com/blog/google-update-new-search-and-play-history-privacy-controls</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-update-new-search-and-play-history-privacy-controls</guid><description>Google launches new privacy tools for Search and Play, allowing users to disable personalization and quickly delete recent activity to improve data privacy.</description><pubDate>Thu, 25 Jun 2026 00:58:32 GMT</pubDate><category>Google Search</category><category>Google Play</category><category>Data Privacy</category><category>Privacy Controls</category><category>User Activity History</category></item><item><title>AI Agents: The Emerging Identity &amp; Governance Challenge</title><link>https://runtimerebel.com/blog/ai-agents-the-emerging-identity-governance-challenge</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agents-the-emerging-identity-governance-challenge</guid><description>Unmanaged AI agents pose significant security risks by operating as uncontrolled identities with access to sensitive enterprise systems. Learn mitigation strategies.</description><pubDate>Fri, 19 Jun 2026 16:54:42 GMT</pubDate><category>AI Security</category><category>AI Agents</category><category>Identity Management</category><category>Access Control</category><category>Governance</category><category>Token Security</category></item><item><title>Cisco Acquires WideField Security to Advance Splunk Agentic SOC</title><link>https://runtimerebel.com/blog/cisco-acquires-widefield-security-to-advance-splunk-agentic-soc</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-acquires-widefield-security-to-advance-splunk-agentic-soc</guid><description>Cisco expands its security portfolio by acquiring WideField Security to integrate identity and session context into Splunk’s AI-driven Agentic SOC platform.</description><pubDate>Fri, 19 Jun 2026 09:45:25 GMT</pubDate><category>Cisco</category><category>Splunk</category><category>WideField Security</category><category>Agentic SOC</category><category>Identity Security</category></item><item><title>Orphaned AI Agents: Mitigating Hidden Access Risks in Enterprise AI</title><link>https://runtimerebel.com/blog/orphaned-ai-agents-mitigating-hidden-access-risks-in-enterprise-ai</link><guid isPermaLink="true">https://runtimerebel.com/blog/orphaned-ai-agents-mitigating-hidden-access-risks-in-enterprise-ai</guid><description>Learn about the hidden access risks posed by orphaned AI agents and standing privileges in enterprise networks. Discover strategies to secure AI deployments.</description><pubDate>Thu, 18 Jun 2026 13:21:10 GMT</pubDate><category>AI Security</category><category>Orphaned AI Agents</category><category>Access Control</category><category>Privilege Management</category><category>Enterprise AI</category><category>Shadow IT</category></item><item><title>SailPoint&apos;s Entro Acquisition: Bolstering Non-Human Identity Security</title><link>https://runtimerebel.com/blog/sailpoint-s-entro-acquisition-bolstering-non-human-identity-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/sailpoint-s-entro-acquisition-bolstering-non-human-identity-security</guid><description>SailPoint acquires Entro to enhance identity and credential security for non-human entities like APIs, bots, and service accounts, addressing a critical enterprise</description><pubDate>Thu, 18 Jun 2026 09:50:27 GMT</pubDate><category>SailPoint</category><category>Entro</category><category>Identity and Access Management</category><category>Non Human Identity</category><category>Credential Security</category><category>Acquisition</category><category>Machine Identity</category></item><item><title>1Password Acquires Apono: Enhancing Just-in-Time Access Governance</title><link>https://runtimerebel.com/blog/1password-acquires-apono-enhancing-just-in-time-access-governance</link><guid isPermaLink="true">https://runtimerebel.com/blog/1password-acquires-apono-enhancing-just-in-time-access-governance</guid><description>1Password&apos;s acquisition of Apono integrates just-in-time access governance, strengthening privileged access management for human, machine, and AI identities.</description><pubDate>Wed, 17 Jun 2026 13:28:57 GMT</pubDate><category>1Password</category><category>Apono</category><category>Just in Time Access</category><category>Access Governance</category><category>Identity Management</category><category>Privileged Access Management</category></item><item><title>NewCore Secures $66M for AI and Machine Identity Platform</title><link>https://runtimerebel.com/blog/newcore-secures-66m-for-ai-and-machine-identity-platform</link><guid isPermaLink="true">https://runtimerebel.com/blog/newcore-secures-66m-for-ai-and-machine-identity-platform</guid><description>NewCore emerges from stealth with $66 million to develop a security-first identity platform protecting human, machine, and AI agent access.</description><pubDate>Mon, 15 Jun 2026 14:24:20 GMT</pubDate><category>NewCore</category><category>Identity Management</category><category>AI Security</category><category>Machine Identity</category><category>Zero Trust</category><category>Security Funding</category></item><item><title>Onboarding Password Risk: Securing First-Day Account Access</title><link>https://runtimerebel.com/blog/onboarding-password-risk-securing-first-day-account-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/onboarding-password-risk-securing-first-day-account-access</guid><description>Temporary onboarding passwords, often sent insecurely and reused, pose significant risk. Learn how to secure initial employee access and mitigate threats.</description><pubDate>Mon, 15 Jun 2026 14:21:06 GMT</pubDate><category>Onboarding Security</category><category>Password Policy</category><category>Identity Management</category><category>Initial Access</category><category>Employee Risk</category><category>Zero Trust</category></item><item><title>Iowa School District Hack: Sentencing Highlights Insider Threat Risks</title><link>https://runtimerebel.com/blog/iowa-school-district-hack-sentencing-highlights-insider-threat-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/iowa-school-district-hack-sentencing-highlights-insider-threat-risks</guid><description>Former Iowa school IT employee sentenced to 21 months for malicious infrastructure disruption and data tampering against his former employer.</description><pubDate>Sun, 14 Jun 2026 01:05:13 GMT</pubDate><category>Insider Threat</category><category>Identity Management</category><category>Account Takeover</category><category>School Security</category></item><item><title>CrowdStrike Joins OpenID Foundation to Advance Identity Security</title><link>https://runtimerebel.com/blog/crowdstrike-joins-openid-foundation-to-advance-identity-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/crowdstrike-joins-openid-foundation-to-advance-identity-security</guid><description>CrowdStrike joins OpenID Foundation and IDPro to influence identity security standards and professionalize defense against identity-based attack vectors.</description><pubDate>Thu, 11 Jun 2026 09:44:22 GMT</pubDate><category>CrowdStrike</category><category>OpenID Foundation</category><category>IDPro</category><category>Identity Security</category><category>Zero Trust</category></item><item><title>Bypassing Identity Verification: Mitigating Phishing &amp; MFA Fatigue</title><link>https://runtimerebel.com/blog/bypassing-identity-verification-mitigating-phishing-mfa-fatigue</link><guid isPermaLink="true">https://runtimerebel.com/blog/bypassing-identity-verification-mitigating-phishing-mfa-fatigue</guid><description>Attackers exploit weak identity verification through phishing, MFA fatigue, and social engineering. Learn best practices to secure access.</description><pubDate>Wed, 10 Jun 2026 17:16:10 GMT</pubDate><category>Identity Verification</category><category>MFA</category><category>Phishing</category><category>MFA Fatigue</category><category>Social Engineering</category><category>Authentication</category><category>Access Security</category></item><item><title>Atsign AI Architect: Securing Agentic AI with Cryptographic Invisibility</title><link>https://runtimerebel.com/blog/atsign-ai-architect-securing-agentic-ai-with-cryptographic-invisibility</link><guid isPermaLink="true">https://runtimerebel.com/blog/atsign-ai-architect-securing-agentic-ai-with-cryptographic-invisibility</guid><description>Atsign launches AI Architect to protect agentic software by using cryptographic identities, eliminating exposed ports and reducing the attack surface.</description><pubDate>Tue, 09 Jun 2026 13:08:43 GMT</pubDate><category>AI Security</category><category>Atsign</category><category>Agentic AI</category><category>Cryptographic Invisibility</category><category>atProtocol</category></item><item><title>Tchap Messaging Breach: French Government Account Hijacking</title><link>https://runtimerebel.com/blog/tchap-messaging-breach-french-government-account-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/tchap-messaging-breach-french-government-account-hijacking</guid><description>French digital affairs directorate DINUM confirms a security breach of the Tchap messaging platform following a targeted account hijacking incident.</description><pubDate>Tue, 09 Jun 2026 13:08:23 GMT</pubDate><category>Tchap</category><category>Dinum</category><category>France</category><category>Account Hijacking</category><category>Government Security</category></item><item><title>CrowdStrike and Zscaler: Advancing Continuous Identity Security</title><link>https://runtimerebel.com/blog/crowdstrike-and-zscaler-advancing-continuous-identity-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/crowdstrike-and-zscaler-advancing-continuous-identity-security</guid><description>CrowdStrike and Zscaler integrate to provide continuous identity risk assessment, preventing lateral movement by enforcing real-time conditional access.</description><pubDate>Mon, 08 Jun 2026 17:14:31 GMT</pubDate><category>CrowdStrike</category><category>Zscaler</category><category>Zero Trust</category><category>Identity Protection</category><category>XDR</category></item><item><title>OpenAI Expands ChatGPT Account Security with New Session Controls</title><link>https://runtimerebel.com/blog/openai-expands-chatgpt-account-security-with-new-session-controls</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-expands-chatgpt-account-security-with-new-session-controls</guid><description>OpenAI rolls out Active Sessions and Lockdown Mode for ChatGPT, providing users and administrators with granular visibility into unauthorized account access.</description><pubDate>Mon, 08 Jun 2026 09:44:49 GMT</pubDate><category>OpenAI</category><category>ChatGPT</category><category>Account Security</category><category>Session Management</category><category>Identity Protection</category></item><item><title>Opal Security Series B: Scaling AI-Native Identity Governance</title><link>https://runtimerebel.com/blog/opal-security-series-b-scaling-ai-native-identity-governance</link><guid isPermaLink="true">https://runtimerebel.com/blog/opal-security-series-b-scaling-ai-native-identity-governance</guid><description>Opal Security secures $23 million in Series B funding to scale its AI-native identity governance platform for hybrid and multi-cloud environments.</description><pubDate>Sat, 06 Jun 2026 12:35:13 GMT</pubDate><category>Opal Security</category><category>Identity Governance</category><category>IAM</category><category>Cloud Security</category><category>IGA</category></item><item><title>Offroad Exits Stealth to Address Non-Human Identity Security Risk</title><link>https://runtimerebel.com/blog/offroad-exits-stealth-to-address-non-human-identity-security-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/offroad-exits-stealth-to-address-non-human-identity-security-risk</guid><description>Offroad emerges with $7 million to secure the enterprise identity landscape, focusing on machine identities, AI agents, and identity posture management.</description><pubDate>Thu, 04 Jun 2026 17:09:49 GMT</pubDate><category>Offroad Security</category><category>Identity Posture Management</category><category>Machine Identities</category><category>AI Security</category><category>ISPM</category></item><item><title>Meta AI Chatbot Exploited for Instagram Account Takeover</title><link>https://runtimerebel.com/blog/meta-ai-chatbot-exploited-for-instagram-account-takeover</link><guid isPermaLink="true">https://runtimerebel.com/blog/meta-ai-chatbot-exploited-for-instagram-account-takeover</guid><description>Attackers manipulate Meta&apos;s AI support chatbot to reset Instagram passwords and hijack accounts via unauthorized email updates and location spoofing.</description><pubDate>Thu, 04 Jun 2026 13:17:29 GMT</pubDate><category>Meta AI</category><category>Instagram</category><category>Account Takeover</category><category>Social Engineering</category><category>AI Security</category></item><item><title>Shrinking IAM Attack Surface via Identity Visibility Platforms (IVIP)</title><link>https://runtimerebel.com/blog/shrinking-iam-attack-surface-via-identity-visibility-platforms-ivip</link><guid isPermaLink="true">https://runtimerebel.com/blog/shrinking-iam-attack-surface-via-identity-visibility-platforms-ivip</guid><description>Enterprise security teams must tackle Identity Dark Matter using IVIP to eliminate blind spots in fragmented identity and access management environments.</description><pubDate>Wed, 03 Jun 2026 13:47:34 GMT</pubDate><category>IAM</category><category>IVIP</category><category>Identity Security</category><category>Access Management</category><category>Identity Dark Matter</category></item></channel></rss>