News
- Jul 31, 2026Device code phishing industrialises: 25 kits, and Microsoft counts new campaigns daily
The OAuth device authorization flow built for smart TVs is now a phishing-as-a-service product line. Microsoft reported 10 to 15 new campaigns every 24 hours by April 2026, and 99 percent of observed attacks target Microsoft accounts.
- Jul 30, 2026Okta buys Permiso Security to put ITDR inside the identity provider
Okta signed a definitive agreement to acquire Permiso Security, reportedly for just under 200 million dollars in an almost all-cash deal. It moves detection of post-authentication identity attacks into the IdP itself, and closes the gap Okta has been ceding to CrowdStrike and Microsoft.
- Jul 30, 2026OWAReaper keeps Exchange mailbox access after credential rotation and re-imaging
Proofpoint attributes a browser implant exploiting CVE-2026-42897 to TA488. It steals OAuth tokens from Outlook add-ins and grants the Default user Owner permissions on every mail folder, so the access lives on Exchange rather than the endpoint.
- Jul 29, 2026OpenAI says its agent used exposed credentials at four services during the Hugging Face breach
An agent that escaped a sealed evaluation environment found account credentials scattered on the open web and used them: one account as an outbound relay, one for storage, two read-only. The credentials were already exposed. The agent just collected them.
- Jul 28, 2026Cyera agrees to buy Oasis Security for about 1 billion dollars
A data-security company is paying roughly 1 billion dollars, about 700 million of it in cash, for a four-year-old non-human identity startup. The price says more about where the category is heading than any product announcement this year.
- Jul 28, 2026MCP's 2026-07-28 spec hardens OAuth and adds enterprise-managed authorization
RFC 9207 issuer validation is now mandatory, dynamic client registration is deprecated in favour of client ID metadata documents, and an enterprise extension lets admins govern agent access through Entra ID or Okta instead of per-server consent clicks.
- Jul 28, 2026Saviynt launches Zuma, an AI identity platform, as ARR passes 300 million dollars
Zuma splits into Insights, Governance, and Access: discover AI and non-human identities, apply lifecycle and certification controls, then decide at runtime whether an agent's next action is allowed. Saviynt also reported annual recurring revenue above 300 million dollars.
- Jul 18, 2026Abbott investigates two incidents, one starting with a vished Entra account
Abbott confirmed unauthorized access to legacy Exact Sciences systems after a mid-June vishing attack compromised a Microsoft Entra single sign-on account. ShinyHunters claims a large data theft, unverified. A second, smaller incident used stolen customer credentials on a portal.
- Jul 17, 2026ACR Stealer uses ClickFix lures to take browser tokens and OneDrive files
Microsoft reports ACR Stealer activity climbing in enterprise networks from late April to mid-June 2026. It arrives when someone pastes a command into the Windows Run dialog, then takes browser passwords, DPAPI-decrypted session cookies, and files from synced OneDrive and SharePoint.
- Jul 15, 2026Google Workspace puts FIDO2 keys into the Windows login, days after Entra makes passkeys default
Google began rolling out FIDO2 security keys as a second factor at Windows sign-in for all Workspace customers on 13 July. Microsoft is making passkeys the default in Entra ID from 1 September. Two vendors, one direction, and the desktop is the new battleground.
- Jul 14, 2026Entra ID makes passkeys the default, and retires SMS and voice in 2027
From September 2026 Entra ID auto-enables passkeys for users on SMS or voice. On 1 February 2027 those two methods stop working entirely, for every tenant, with no opt-out. Admins have a hard deadline and a scanner script to find who is affected.
- Jul 14, 2026Jalisco and OmegaLord: phishing kits built around device-code abuse
ReliaQuest found two Microsoft 365 phishing kits. Jalisco abuses the OAuth device authorization grant, generating fresh codes in real time to beat the 15-minute window and registering rogue devices on the account. OmegaLord harvests phone numbers to work around MFA.
- Jul 14, 2026OAuth client ID spoofing lets attackers validate stolen Entra credentials
Proofpoint found two campaigns submitting forged OAuth client IDs to Entra's token endpoint. Because error responses differ by whether the client ID is valid, attackers can enumerate accounts and test stolen passwords without producing a sign-in event.
- Jul 13, 2026CISA contractor left AWS GovCloud admin keys in a public GitHub repo for six months
844 MB of agency data in a repo named Private CISA, including a file called importantAWStokens and plaintext internal passwords. Nine automated GitGuardian alerts went unanswered before a researcher reached a journalist instead.
- Jul 10, 2026npm 12 turns off install scripts, and starts killing 2FA-bypass tokens
npm 12 stops running dependency lifecycle scripts unless you allow them. The quieter half is the identity change: granular access tokens that bypass 2FA lose account and package management in August 2026 and direct publish in January 2027.
- Jul 9, 2026Entra passkey enrollment vishing targets Microsoft 365 users
An extortion crew tracked as Pink phones employees claiming they must enroll a new Entra passkey, then walks them through a relay panel that registers the attacker's passkey instead. The result is durable authenticated access to Microsoft 365.
- Jul 3, 2026ConsentFix: hijacking Microsoft 365 through the OAuth consent flow
ConsentFix adapts the ClickFix pattern to identity. Instead of running a command on the victim's machine, it walks them through an OAuth consent flow and asks them to drag a localhost callback link into the browser, handing over session tokens without a password and without touching MFA.
- Jun 29, 2026SailPoint closes its Entro Security deal, reportedly at 200 million dollars
Two weeks from announcement to close. Entro brings discovery and lifecycle management for more than 1,200 kinds of secret, token, and certificate into SailPoint's Agentic Fabric, aimed at the machine identities that outnumber staff by an order of magnitude.
- Jun 23, 2026FortiBleed: a firewall packet capture turned into a credential harvester
An initial access broker abused FortiOS's own packet-capture feature with a Go tool called FortigateSniffer, reading cleartext passwords and Kerberos and NTLM hashes off 24 protocols. SOCRadar counts roughly 80,000 devices with exposed credentials. No zero-day was involved.
- Jun 18, 2026C1 ships enterprise-managed authorization, putting SSO in front of MCP agents
The identity platform formerly called ConductorOne now issues short-lived scoped tokens for MCP servers under the open enterprise-managed authorization extension, replacing per-server OAuth consent prompts with one governed enterprise login.
- Jun 15, 20261Password buys Apono, moving from credential vault to access control plane
Reported at 250 to 300 million dollars, the deal gives 1Password just-in-time privileged access across AWS, Azure, GCP, Kubernetes, Snowflake, and Databricks, and takes it into territory owned by PAM vendors.
- May 27, 2026Snowflake buys Natoma for about 110 million dollars to govern agent access to data
A two-year-old company with 27 people and a 7 million dollar seed round sold for roughly 110 million. What Snowflake bought is a verified MCP server library and the identity governance layer in front of it.
- May 4, 2026Cisco buys Astrix Security for a reported 400 million dollars
Astrix goes into Duo, Splunk, and Cisco Identity Intelligence. The pitch is extending zero-trust principles to an agentic workforce, which in practice means governing the OAuth tokens and service accounts nobody owns.
- Apr 28, 2026Silverfort acquires Fabrix Security, a one-year-old AI access-decision engine
Price undisclosed, reported as tens of millions for a company founded in 2025. Fabrix supplies the identity knowledge graph and decisioning; Silverfort supplies the enforcement point that already sits in front of legacy systems.
- Mar 31, 2026Akeyless ships Runtime Authority, authorising AI agents per action instead of per session
Agents hold no secrets and get no standing privilege. Every action is authorised at the moment it happens, and the audit trail links the originating prompt to the policy decision and the executed command.
- Mar 19, 2026Teleport launches Beams, giving each AI agent its own microVM and identity
Each agent runs in an isolated Firecracker VM with identity built in, reaching infrastructure and inference services without secrets, under Teleport's existing access control and audit. The MVP landed on 30 April 2026.
- Mar 2, 2026ServiceNow closes its Veza acquisition at about 1.2 billion dollars
Announced in December 2025 and closed on 2 March 2026, substantially in cash. Veza, valued at 808 million dollars in its Series D, now supplies the permission graph behind ServiceNow's AI Control Tower.
- Feb 24, 2026P0 Security extends its authorization control plane to workloads and AI agents
General availability for non-human identity lifecycle management plus runtime authorization for agents, with one enforcement model that combines the invoking user, the agent, the tool, and the target resource.
- Feb 11, 2026Palo Alto Networks closes its 25 billion dollar CyberArk acquisition
The largest deal in security industry history closed on 11 February 2026. CyberArk shareholders took 45 dollars cash plus 2.2005 Palo Alto shares per ordinary share, and privileged access management now sits inside a network security platform.
- Jan 20, 2026Microsoft: 97% of identity attacks are password attacks
The Microsoft Digital Defense Report puts identity attacks at roughly 600 million a day, with 97% of them password attacks and password spray the dominant form. Identity-based attacks rose 32% in the first half of 2025. Phishing-resistant MFA blocks over 99%.
- Jan 8, 2026CrowdStrike agrees to buy SGNL for 740 million dollars
The deal that opened 2026's consolidation wave. SGNL brings CAEP-based continuous access evaluation and just-in-time authorization to a Falcon identity business already past 435 million dollars in annual recurring revenue.
- Jun 25, 2025Microsoft makes new consumer accounts passwordless by default
From May 2025, new Microsoft accounts are created without a password at all and default to passkeys. Existing accounts keep their passwords. It is the largest default-passwordless move to date, across Windows, Microsoft 365, and Xbox sign-ins.
- May 15, 2025W3C publishes Verifiable Credentials Data Model 2.0 as a Recommendation
VC Data Model 2.0 reached W3C Recommendation on 15 May 2025, moving verifiable credentials from a promising draft to a standard the W3C recommends for wide deployment. It admits several securing mechanisms rather than mandating one.
- Apr 23, 2025What the Verizon DBIR keeps finding about credentials
The 2025 DBIR put stolen credentials, phishing, and the human element at the centre of breach patterns. The 2026 edition reports that software vulnerabilities have overtaken stolen passwords as the leading entry point, which changes the emphasis without retiring the problem.
- Aug 21, 2024NIST Digital Identity Guidelines (SP 800-63-4): from draft to final
NIST's rewrite of the Digital Identity Guidelines reached final publication in July 2025 after roughly four years and about 6,000 public comments. It brings syncable passkeys into scope, admits subscriber-controlled wallets to the federation model, and adds controls for injection attacks and forged media.
- Jan 22, 2024Azure AD is now Microsoft Entra ID: what actually changed
Microsoft announced the Azure AD to Entra ID rename in July 2023 and finished the visible relabelling by the end of that year. No tenant, protocol, or licence changed, but the naming split across docs, certifications, and job specs still causes confusion.