<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Identity Access</title><description>Cybersecurity articles tagged #Identity Access on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>FreeIPA Critical Chain: Anonymous Admin via CVE-2026-76578</title><link>https://runtimerebel.com/blog/freeipa-critical-chain-anonymous-admin-via-cve-2026-76578</link><guid isPermaLink="true">https://runtimerebel.com/blog/freeipa-critical-chain-anonymous-admin-via-cve-2026-76578</guid><description>Critical FreeIPA flaw chain (CVE-2026-76578, CVE-2026-76560) enables anonymous clients to forge admin credentials on default installations. Patch now.</description><pubDate>Tue, 08 Sep 2026 12:24:28 GMT</pubDate><category>Identity Access</category><category>Kerberos</category><category>FreeIPA</category><category>389 Directory Server</category><category>CVE-2026-76578</category></item><item><title>IDScan Sued Over Alleged Breach Impacting 153 Million Drivers</title><link>https://runtimerebel.com/blog/idscan-sued-over-alleged-breach-impacting-153-million-drivers</link><guid isPermaLink="true">https://runtimerebel.com/blog/idscan-sued-over-alleged-breach-impacting-153-million-drivers</guid><description>IDScan faces lawsuits after a dark-web service allegedly offered to sell 153 million driver&apos;s licenses and millions of other identity documents.</description><pubDate>Fri, 04 Sep 2026 18:44:31 GMT</pubDate><category>Data Breach</category><category>Identity Access</category><category>Class Action</category><category>Dark Web</category><category>Driver Licenses</category></item><item><title>Entra Log Analysis: Detecting Password Spray Attacks with PowerShell</title><link>https://runtimerebel.com/blog/entra-log-analysis-detecting-password-spray-attacks-with-powershell</link><guid isPermaLink="true">https://runtimerebel.com/blog/entra-log-analysis-detecting-password-spray-attacks-with-powershell</guid><description>Learn to analyze Microsoft Entra sign-in logs using PowerShell to detect password spray attacks and anomalous successful logins from unexpected geographic locations.</description><pubDate>Fri, 21 Aug 2026 08:33:19 GMT</pubDate><category>Entra ID</category><category>Azure AD</category><category>PowerShell</category><category>Threat Detection</category><category>Identity Access</category></item><item><title>Auditing Entra ID MFA Gaps with PowerShell and Microsoft Graph</title><link>https://runtimerebel.com/blog/auditing-entra-id-mfa-gaps-with-powershell-and-microsoft-graph</link><guid isPermaLink="true">https://runtimerebel.com/blog/auditing-entra-id-mfa-gaps-with-powershell-and-microsoft-graph</guid><description>A new PowerShell script helps security teams identify Microsoft Entra ID users not registered for MFA or using weaker authentication methods.</description><pubDate>Fri, 21 Aug 2026 08:32:39 GMT</pubDate><category>Microsoft Entra ID</category><category>MFA</category><category>PowerShell</category><category>Identity Access</category><category>Microsoft Graph</category></item><item><title>Securing Model Context Protocol (MCP) Traffic with Cloudflare</title><link>https://runtimerebel.com/blog/securing-model-context-protocol-mcp-traffic-with-cloudflare</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-model-context-protocol-mcp-traffic-with-cloudflare</guid><description>Learn how Cloudflare One identifies inspected Model Context Protocol traffic and controls AI agent tool calls to secure enterprise environments.</description><pubDate>Fri, 14 Aug 2026 16:44:20 GMT</pubDate><category>Cloud Security</category><category>Zero-Day</category><category>API Security</category><category>Identity Access</category></item><item><title>Cybersecurity M&amp;A Trends: Key Acquisitions in July 2026</title><link>https://runtimerebel.com/blog/cybersecurity-m-a-trends-key-acquisitions-in-july-2026</link><guid isPermaLink="true">https://runtimerebel.com/blog/cybersecurity-m-a-trends-key-acquisitions-in-july-2026</guid><description>July 2026 saw 21 cybersecurity M&amp;A deals, including major acquisitions by CrowdStrike, Okta, and Palo Alto Networks enhancing platform capabilities.</description><pubDate>Thu, 13 Aug 2026 16:46:17 GMT</pubDate><category>Cybersecurity M a</category><category>Industry Trends</category><category>CrowdStrike</category><category>Identity Access</category><category>Acquisitions</category></item><item><title>Device Code Phishing Surges 1,500% as Vishing Doubles</title><link>https://runtimerebel.com/blog/device-code-phishing-surges-1500-as-vishing-doubles</link><guid isPermaLink="true">https://runtimerebel.com/blog/device-code-phishing-surges-1500-as-vishing-doubles</guid><description>Device code phishing attacks surged 1,500% while vishing doubled, exploiting modern authentication flows to bypass traditional security controls.</description><pubDate>Tue, 04 Aug 2026 11:23:35 GMT</pubDate><category>Phishing</category><category>Social Engineering</category><category>Credential Theft</category><category>Identity Access</category><category>Multi Factor Authentication</category></item><item><title>Microsoft Teams Abused in Helpdesk Impersonation Attacks: TTPs &amp; Mitigations</title><link>https://runtimerebel.com/blog/microsoft-teams-abused-in-helpdesk-impersonation-attacks-ttps-mitigations</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-teams-abused-in-helpdesk-impersonation-attacks-ttps-mitigations</guid><description>Microsoft warns of helpdesk impersonation attacks via Teams external collaboration.</description><pubDate>Mon, 20 Apr 2026 16:32:32 GMT</pubDate><category>Microsoft Teams</category><category>Impersonation</category><category>Social Engineering</category><category>Helpdesk</category><category>Phishing</category><category>Identity Access</category><category>Microsoft 365</category><category>External Collaboration</category></item></channel></rss>