<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Identity Security</title><description>Cybersecurity articles tagged #Identity Security on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Securing Agentic AI: Risks of Over-Privileged Identity Permissions</title><link>https://runtimerebel.com/blog/securing-agentic-ai-risks-of-over-privileged-identity-permissions</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-agentic-ai-risks-of-over-privileged-identity-permissions</guid><description>AI agents that improvise to solve tasks pose significant security risks. Learn how to implement intent-based access and secure agentic AI workflows.</description><pubDate>Wed, 29 Jul 2026 14:13:24 GMT</pubDate><category>AI Security</category><category>Agentic AI</category><category>Identity Security</category><category>Least Privilege</category><category>Machine Identity</category></item><item><title>SolarWinds ARM RCE via CVE-2024-28995 — Technical Mitigation Guide</title><link>https://runtimerebel.com/blog/solarwinds-arm-rce-via-cve-2024-28995-technical-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/solarwinds-arm-rce-via-cve-2024-28995-technical-mitigation-guide</guid><description>Critical vulnerabilities in SolarWinds Access Rights Manager (ARM), including CVE-2024-28995, allow unauthenticated RCE. Update to version 2024.3 now.</description><pubDate>Fri, 24 Jul 2026 02:47:40 GMT</pubDate><category>SolarWinds</category><category>Access Rights Manager</category><category>CVE-2024-28995</category><category>RCE</category><category>Directory Traversal</category><category>Identity Security</category></item><item><title>Securing Critical Infrastructure: Closing Identity Gaps</title><link>https://runtimerebel.com/blog/securing-critical-infrastructure-closing-identity-gaps</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-critical-infrastructure-closing-identity-gaps</guid><description>Attacks on critical infrastructure leverage identity gaps. This analysis details common vulnerabilities and how Zero Trust principles can enhance sector security.</description><pubDate>Tue, 21 Jul 2026 17:24:12 GMT</pubDate><category>Critical Infrastructure</category><category>Identity Security</category><category>Zero Trust</category><category>Credential Theft</category><category>MFA Bypass</category><category>Supply Chain Attack</category><category>Phishing</category></item><item><title>Defending Entra ID: Lessons from Breach at the Beach CTF</title><link>https://runtimerebel.com/blog/defending-entra-id-lessons-from-breach-at-the-beach-ctf</link><guid isPermaLink="true">https://runtimerebel.com/blog/defending-entra-id-lessons-from-breach-at-the-beach-ctf</guid><description>Analyze common Entra ID attack vectors including service principal abuse and privilege escalation techniques based on the Breach at the Beach CTF.</description><pubDate>Mon, 13 Jul 2026 14:42:13 GMT</pubDate><category>Entra ID</category><category>Azure AD</category><category>Cloud Security</category><category>Varonis</category><category>Identity Security</category></item><item><title>AI Agents Expand Attack Surface: Managing Non-Human Identities</title><link>https://runtimerebel.com/blog/ai-agents-expand-attack-surface-managing-non-human-identities</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agents-expand-attack-surface-managing-non-human-identities</guid><description>AI agents accelerate non-human identity growth, creating security gaps. Proactive identity governance and visibility are crucial for defense.</description><pubDate>Fri, 10 Jul 2026 14:31:05 GMT</pubDate><category>AI Agents</category><category>Non Human Identities</category><category>Identity Security</category><category>Attack Surface Management</category><category>Netwrix</category><category>Identity Governance</category></item><item><title>Digital Identity Security: Investment Reflects Evolving Threat Landscape</title><link>https://runtimerebel.com/blog/digital-identity-security-investment-reflects-evolving-threat-landscape</link><guid isPermaLink="true">https://runtimerebel.com/blog/digital-identity-security-investment-reflects-evolving-threat-landscape</guid><description>Investment in digital identity security platforms highlights ongoing critical need for robust defense against modern cyber threats and data breaches.</description><pubDate>Thu, 09 Jul 2026 07:45:03 GMT</pubDate><category>Identity Security</category><category>Digital Identity</category><category>Cybersecurity Funding</category><category>Access Management</category></item><item><title>Cisco Secures Non-Human Identity with Astrix and WideField</title><link>https://runtimerebel.com/blog/cisco-secures-non-human-identity-with-astrix-and-widefield</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-secures-non-human-identity-with-astrix-and-widefield</guid><description>Cisco&apos;s acquisition of Astrix and WideField signals a strategic shift toward Non-Human Identity (NHI) as a critical control plane for securing cloud access.</description><pubDate>Sat, 27 Jun 2026 09:01:11 GMT</pubDate><category>Cisco</category><category>Astrix Security</category><category>WideField</category><category>Non Human Identity</category><category>NHI</category><category>Identity Security</category><category>Cloud Security</category></item><item><title>Cisco Acquires WideField Security to Advance Splunk Agentic SOC</title><link>https://runtimerebel.com/blog/cisco-acquires-widefield-security-to-advance-splunk-agentic-soc</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-acquires-widefield-security-to-advance-splunk-agentic-soc</guid><description>Cisco expands its security portfolio by acquiring WideField Security to integrate identity and session context into Splunk’s AI-driven Agentic SOC platform.</description><pubDate>Fri, 19 Jun 2026 09:45:25 GMT</pubDate><category>Cisco</category><category>Splunk</category><category>WideField Security</category><category>Agentic SOC</category><category>Identity Security</category></item><item><title>Shrinking IAM Attack Surface via Identity Visibility Platforms (IVIP)</title><link>https://runtimerebel.com/blog/shrinking-iam-attack-surface-via-identity-visibility-platforms-ivip</link><guid isPermaLink="true">https://runtimerebel.com/blog/shrinking-iam-attack-surface-via-identity-visibility-platforms-ivip</guid><description>Enterprise security teams must tackle Identity Dark Matter using IVIP to eliminate blind spots in fragmented identity and access management environments.</description><pubDate>Wed, 03 Jun 2026 13:47:34 GMT</pubDate><category>IAM</category><category>IVIP</category><category>Identity Security</category><category>Access Management</category><category>Identity Dark Matter</category></item><item><title>AI Agent Identity Security: Budget Dynamics &amp; Governance Priorities</title><link>https://runtimerebel.com/blog/ai-agent-identity-security-budget-dynamics-governance-priorities</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agent-identity-security-budget-dynamics-governance-priorities</guid><description>New Omdia research reveals AI agent proliferation is fundamentally altering enterprise identity security budget dynamics, demanding distinct governance and management…</description><pubDate>Thu, 21 May 2026 20:41:56 GMT</pubDate><category>AI Agents</category><category>Identity Security</category><category>IAM</category><category>Governance</category><category>Budget Dynamics</category><category>Omdia</category></item><item><title>Securing Identity Attack Paths: Protecting Cached AWS Credentials</title><link>https://runtimerebel.com/blog/securing-identity-attack-paths-protecting-cached-aws-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-identity-attack-paths-protecting-cached-aws-credentials</guid><description>Attackers exploit cached AWS access keys to achieve lateral movement. Learn how identity-based attack paths expose 98% of cloud entities and how to defend.</description><pubDate>Thu, 21 May 2026 13:17:05 GMT</pubDate><category>AWS</category><category>Identity Security</category><category>Cloud Security</category><category>Lateral Movement</category><category>IAM</category></item><item><title>Reducing Phishing Exposure: Strategies for Rapid Evidence Recovery</title><link>https://runtimerebel.com/blog/reducing-phishing-exposure-strategies-for-rapid-evidence-recovery</link><guid isPermaLink="true">https://runtimerebel.com/blog/reducing-phishing-exposure-strategies-for-rapid-evidence-recovery</guid><description>Learn how SOC teams can close the visibility gap in phishing detection and use evidence-based analysis to prevent business disruption after a click.</description><pubDate>Mon, 18 May 2026 17:03:33 GMT</pubDate><category>Phishing Prevention</category><category>SOC Operations</category><category>Incident Response</category><category>Identity Security</category></item><item><title>Bypassing AI-Based Age Verification via Facial Obfuscations</title><link>https://runtimerebel.com/blog/bypassing-ai-based-age-verification-via-facial-obfuscations</link><guid isPermaLink="true">https://runtimerebel.com/blog/bypassing-ai-based-age-verification-via-facial-obfuscations</guid><description>Research reveals that AI-driven age estimation systems can be bypassed using physical facial alterations, highlighting flaws in biometric verification models.</description><pubDate>Fri, 15 May 2026 12:49:02 GMT</pubDate><category>Age Verification</category><category>Biometrics</category><category>AI Vulnerabilities</category><category>Facial Recognition</category><category>Identity Security</category></item><item><title>Microsoft Entra ID Flaw: Agent ID Administrator Role Escalation</title><link>https://runtimerebel.com/blog/microsoft-entra-id-flaw-agent-id-administrator-role-escalation</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-entra-id-flaw-agent-id-administrator-role-escalation</guid><description>Microsoft patches a critical logic flaw in the Entra ID Agent ID Administrator role that allowed attackers to take over service principals and escalate privileges.</description><pubDate>Tue, 28 Apr 2026 08:56:27 GMT</pubDate><category>Microsoft Entra ID</category><category>Silverfort</category><category>Identity Security</category><category>Service Principals</category><category>AI Agent Security</category></item><item><title>Robinhood Sign-Up Flaw Used for Phishing Injection - Analysis</title><link>https://runtimerebel.com/blog/robinhood-sign-up-flaw-used-for-phishing-injection-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/robinhood-sign-up-flaw-used-for-phishing-injection-analysis</guid><description>Exploit of Robinhood&apos;s account creation process allowed attackers to inject phishing content into official emails, bypassing standard security filters.</description><pubDate>Tue, 28 Apr 2026 00:49:44 GMT</pubDate><category>Robinhood</category><category>Phishing</category><category>Input Validation</category><category>Email Spoofing</category><category>Identity Security</category></item><item><title>Rituals Cosmetics Breach: My Rituals Database PII Exposure</title><link>https://runtimerebel.com/blog/rituals-cosmetics-breach-my-rituals-database-pii-exposure</link><guid isPermaLink="true">https://runtimerebel.com/blog/rituals-cosmetics-breach-my-rituals-database-pii-exposure</guid><description>Rituals Cosmetics discloses a data breach affecting its My Rituals membership database. Learn about the PII exposure, risk of credential stuffing, and mitigation.</description><pubDate>Thu, 23 Apr 2026 16:41:37 GMT</pubDate><category>Rituals</category><category>PII Theft</category><category>Credential Stuffing</category><category>Identity Security</category><category>Retail Cybersecurity</category></item><item><title>Defensive Strategies for Routine Workflow Weaponization</title><link>https://runtimerebel.com/blog/defensive-strategies-for-routine-workflow-weaponization</link><guid isPermaLink="true">https://runtimerebel.com/blog/defensive-strategies-for-routine-workflow-weaponization</guid><description>Attackers are pivoting from technical exploits to weaponizing trusted workflows. Learn how to detect and mitigate these behavioral identity-based threats.</description><pubDate>Thu, 23 Apr 2026 12:30:57 GMT</pubDate><category>Social Engineering</category><category>Business Email Compromise</category><category>Identity Security</category><category>Behavioral Analytics</category><category>Insider Threat</category></item><item><title>Identity-First Zero Trust Strategies to Prevent Credential Theft</title><link>https://runtimerebel.com/blog/identity-first-zero-trust-strategies-to-prevent-credential-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/identity-first-zero-trust-strategies-to-prevent-credential-theft</guid><description>Learn how Zero Trust architecture mitigates stolen credentials and lateral movement by enforcing device trust, least privilege, and continuous verification.</description><pubDate>Tue, 14 Apr 2026 16:32:08 GMT</pubDate><category>Zero Trust</category><category>Identity Security</category><category>Credential Theft</category><category>Least Privilege</category><category>MFA</category></item><item><title>Detecting Credential-Based Attacks: Moving Beyond Signatures</title><link>https://runtimerebel.com/blog/detecting-credential-based-attacks-moving-beyond-signatures</link><guid isPermaLink="true">https://runtimerebel.com/blog/detecting-credential-based-attacks-moving-beyond-signatures</guid><description>Identity-based attacks leverage valid credentials to mimic legitimate activity, requiring a shift toward behavioral detection and identity-centric monitoring.</description><pubDate>Fri, 10 Apr 2026 20:14:30 GMT</pubDate><category>Identity Security</category><category>Credential Theft</category><category>Behavioral Analytics</category><category>MFA Bypass</category><category>ITDR</category></item><item><title>Managing Recurring Credential Incident Risks in Enterprise Environments</title><link>https://runtimerebel.com/blog/managing-recurring-credential-incident-risks-in-enterprise-environments</link><guid isPermaLink="true">https://runtimerebel.com/blog/managing-recurring-credential-incident-risks-in-enterprise-environments</guid><description>Analyze the financial and operational impact of recurring credential incidents, beyond the $4.4 million average breach cost cited in recent industry reports.</description><pubDate>Tue, 07 Apr 2026 12:27:43 GMT</pubDate><category>Credential Stuffing</category><category>Identity Security</category><category>Breach Prevention</category><category>Access Management</category></item><item><title>Linx Security Boosts Identity Governance Solutions with $50M Funding</title><link>https://runtimerebel.com/blog/linx-security-boosts-identity-governance-solutions-with-50m-funding</link><guid isPermaLink="true">https://runtimerebel.com/blog/linx-security-boosts-identity-governance-solutions-with-50m-funding</guid><description>Linx Security secures $50M funding, accelerating product development and global reach for its identity security and governance platform, underscoring identity…</description><pubDate>Thu, 02 Apr 2026 04:49:49 GMT</pubDate><category>Identity Security</category><category>Identity Governance</category><category>Cybersecurity Investment</category><category>Access Management</category><category>Funding</category></item><item><title>Beyond MFA: Bridging the Zero Trust Gap in Session Security</title><link>https://runtimerebel.com/blog/beyond-mfa-bridging-the-zero-trust-gap-in-session-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/beyond-mfa-bridging-the-zero-trust-gap-in-session-security</guid><description>Authentication alone does not equate to trust. Discover how session token hijacking bypasses MFA and why device health is critical for Zero Trust.</description><pubDate>Tue, 24 Mar 2026 16:29:03 GMT</pubDate><category>Zero Trust</category><category>MFA Bypass</category><category>Session Hijacking</category><category>Identity Security</category><category>Device Trust</category></item><item><title>RSAC 2026: Analyzing Pre-Event Cybersecurity Vendor Announcements</title><link>https://runtimerebel.com/blog/rsac-2026-analyzing-pre-event-cybersecurity-vendor-announcements</link><guid isPermaLink="true">https://runtimerebel.com/blog/rsac-2026-analyzing-pre-event-cybersecurity-vendor-announcements</guid><description>Analysis of pre-event announcements for RSAC 2026, detailing the shift toward AI-driven security operations and unified identity-centric defense strategies.</description><pubDate>Mon, 23 Mar 2026 16:25:48 GMT</pubDate><category>RSAC 2026</category><category>Security Automation</category><category>Identity Security</category><category>Cloud Defense</category></item><item><title>Credential Theft Surge: Understanding Infostealer &amp; AI Social Engineering</title><link>https://runtimerebel.com/blog/credential-theft-surge-understanding-infostealer-ai-social-engineering</link><guid isPermaLink="true">https://runtimerebel.com/blog/credential-theft-surge-understanding-infostealer-ai-social-engineering</guid><description>Credential theft surged in late 2025, driven by sophisticated infostealer malware and AI-enhanced social engineering.</description><pubDate>Wed, 18 Mar 2026 00:37:14 GMT</pubDate><category>Credential Theft</category><category>Infostealer</category><category>AI Social Engineering</category><category>Identity Security</category><category>Account Takeover</category><category>Social Engineering</category></item><item><title>Remote Device Wiping Attack Hits Stryker via Microsoft Environment</title><link>https://runtimerebel.com/blog/remote-device-wiping-attack-hits-stryker-via-microsoft-environment</link><guid isPermaLink="true">https://runtimerebel.com/blog/remote-device-wiping-attack-hits-stryker-via-microsoft-environment</guid><description>An attack on medical technology firm Stryker resulted in the remote wiping of tens of thousands of devices by leveraging internal management tools and identity.</description><pubDate>Mon, 16 Mar 2026 20:15:55 GMT</pubDate><category>Stryker Breach</category><category>Microsoft Intune</category><category>Remote Wipe</category><category>Malwareless Attack</category><category>Identity Security</category></item><item><title>Identity Prioritization: Shifting from Backlogs to Risk Math</title><link>https://runtimerebel.com/blog/identity-prioritization-shifting-from-backlogs-to-risk-math</link><guid isPermaLink="true">https://runtimerebel.com/blog/identity-prioritization-shifting-from-backlogs-to-risk-math</guid><description>Enterprise identity programs must evolve from ticket-based prioritization to dynamic risk math models to manage the surge of human and non-human identities.</description><pubDate>Tue, 24 Feb 2026 12:20:29 GMT</pubDate><category>IAM</category><category>Identity Security</category><category>Risk Management</category><category>Non Human Identities</category><category>Identity Threat Detection and Response</category></item></channel></rss>