#identity-news
- Analysis · Jun 12, 2026Identiverse 2026 recap: agentic identity grows up, and passkeys get real
Our takeaways from Identiverse 2026 in Las Vegas: AI agent identity moved from theory to roadmap, passkeys turned operational, deepfakes pressured identity verification, and session security took center stage.
- News · Apr 15, 2026Post-quantum migration starts to reach identity and PKI
As NIST post-quantum standards mature, certificate and PKI vendors began planning crypto-agile migrations for machine identity.
- News · Mar 2, 2026OAuth 2.1 consolidation draft continues through the IETF
Work continued on OAuth 2.1, which folds widely adopted security practices into a single specification and removes legacy grants.
- News · Feb 11, 2026Agentic AI identity emerges as a distinct security category
Vendors and standards bodies began addressing identity for AI agents, focusing on scoped, delegated, and revocable credentials and MCP authorization.
- News · Jan 20, 2026Microsoft reports identity attacks dominated by password attacks
Microsoft research found the overwhelming majority of identity attacks target passwords, and that phishing-resistant MFA blocks over 99% of them.
- News · Dec 1, 2025Reusable verifiable-credential pilots expand for KYC
Banks and governments piloted reusable, wallet-based credentials to cut repeat KYC, aligned with eIDAS 2.0 and W3C standards.
- News · Nov 10, 2025IBM reports global average data breach cost eased to $4.44M
IBM Cost of a Data Breach research showed a modest decline in average breach cost, driven by faster identification and containment.
- News · Oct 15, 2025FIDO Alliance reports over 15 billion accounts can use passkeys
The FIDO Alliance said more than 15 billion online accounts now support passkey sign-in, roughly doubling availability year over year.
- News · Sep 30, 2025Analysts name identity-first security a top enterprise priority
Industry analysts continued to position identity as the primary security control plane, driving investment in ITDR, ISPM, and governance.
- News · Sep 15, 2025Palo Alto Networks to acquire CyberArk in roughly $25B deal
Palo Alto Networks agreed to acquire privileged access leader CyberArk in a deal valued around $25 billion, its largest acquisition and a major bet that identity security is core to platform consolidation.
- News · Sep 9, 2025Non-human identity security startups raise significant funding
Investor interest in non-human identity governance grew, with multiple startups raising rounds to discover and secure service accounts, tokens, and agents.
- News · Aug 19, 2025Non-human identity governance becomes a defined market
Analysts and vendors formalized non-human identity governance as its own category, covering discovery, posture, and lifecycle for machine identities.
- News · Aug 5, 2025Ping Identity acquires just-in-time PAM startup Procyon
Ping Identity acquired Procyon and relaunched it as PingOne Privilege, adding cloud just-in-time privileged access to its platform.
- News · Aug 1, 2025OpenID Foundation finalizes OpenID4VC High Assurance Interoperability Profile
The OpenID Foundation advanced OpenID for Verifiable Credentials profiles, improving interoperability for issuing and presenting digital credentials.
- News · Jul 22, 2025Identity providers adopt the Shared Signals Framework for continuous access
Adoption of the Shared Signals Framework and CAEP grew, letting providers share security events and revoke sessions in near real time.
- News · Jul 8, 2025Infostealer-driven session and token theft surges
Threat researchers reported a sharp rise in infostealer malware harvesting credentials and live session cookies, enabling attackers to bypass MFA.
- News · Jun 25, 2025Microsoft moves new consumer accounts to passwordless by default
Microsoft began defaulting new consumer accounts to passwordless sign-in with passkeys, citing the scale of password-based attacks.
- News · Jun 19, 2025Report describes a 16 billion credential compilation circulating online
Researchers described one of the largest aggregations of stolen credentials to date, largely sourced from infostealer logs and prior breaches.
- News · May 20, 2025CyberArk reports machine identities outnumber humans by more than 80 to 1
CyberArk research found non-human identities vastly outnumber human ones, driven by cloud and AI, and that most organizations lack controls for them.
- News · May 15, 2025W3C publishes Verifiable Credentials Data Model 2.0 as a Recommendation
The W3C finalized the Verifiable Credentials Data Model 2.0 family as Recommendations, a milestone for decentralized identity and the EU Digital Identity Wallet.
- News · May 6, 2025World Passkey Day spotlights passwordless adoption
The FIDO Alliance marked World Passkey Day with new adoption data and a pledge program to accelerate the shift away from passwords.
- News · Apr 23, 2025Verizon DBIR finds credentials and the human element central to breaches
The annual Data Breach Investigations Report again highlighted stolen credentials, phishing, and the human element as dominant breach factors.
- News · Apr 2, 2025SailPoint returns to public markets
Identity governance leader SailPoint listed on Nasdaq again under ticker SAIL, while remaining majority-owned by Thoma Bravo.
- News · Mar 25, 2025Claims of Oracle Cloud credential exposure prompt scrutiny
Reports of exposed cloud credentials drew attention to single-sign-on and federation hygiene, though details and scope were disputed.
- News · Mar 18, 2025GitGuardian reports millions of new secrets leaked on public GitHub
GitGuardian found tens of millions of new hardcoded secrets exposed in public commits, with a large share still valid long after leaking.
- News · Feb 25, 2025Major CIAM vendors add support for authenticating AI agents
Developer identity vendors began shipping features to issue and verify identities for AI agents and bots, an early sign of agentic identity going mainstream.
- News · Feb 13, 2025CyberArk acquires Zilla Security for modern IGA
CyberArk acquired cloud-native identity governance vendor Zilla Security to add lightweight access reviews and provisioning to its platform.
- News · Feb 4, 2025Vendors warn of surge in deepfake-driven identity verification fraud
Verification vendors reported rapid growth in deepfake and injection attacks against remote identity proofing, raising the bar for liveness detection.
- News · Jan 21, 2025IETF publishes OAuth 2.0 Security Best Current Practice as RFC 9700
The OAuth 2.0 Security BCP became RFC 9700, consolidating hardening guidance such as PKCE everywhere and sender-constrained tokens.
- News · Jan 17, 2025DORA takes effect for EU financial entities
The Digital Operational Resilience Act began to apply, raising the bar for access controls, identity governance, and third-party risk in EU finance.
- News · Jan 16, 2025US executive order mandates phishing-resistant authentication for agencies
A US cybersecurity executive order directed federal agencies toward phishing-resistant authentication such as passkeys and PIV, reinforcing the move off passwords.
- News · Dec 10, 2024FIDO Alliance advances passkey portability and credential exchange
The FIDO Alliance published specifications to let users securely move passkeys between providers, addressing a key adoption blocker.
- News · Dec 3, 2024CISA urges organizations to adopt phishing-resistant MFA
CISA reiterated guidance to move from SMS and push-based MFA to phishing-resistant methods like FIDO2 and passkeys.
- News · Nov 19, 2024Amazon, eBay, and more expand consumer passkey support
Major consumer brands continued rolling out passkeys, with the FIDO Alliance reporting steady growth in passkey-enabled accounts.
- News · Nov 12, 2024Scattered Spider help-desk social engineering drives identity attacks
Authorities warned that the Scattered Spider group continued to bypass MFA through help-desk social engineering and SIM swapping, hitting major enterprises.
- News · Oct 29, 2024Yubico expands enterprise passkey delivery as a service
Yubico grew its YubiEnterprise subscription for distributing hardware security keys, easing phishing-resistant rollouts at scale.
- News · Oct 23, 2024Microsoft Authenticator adds passkey support
Microsoft enabled passkeys in its Authenticator app, expanding phishing-resistant sign-in options for consumer and work accounts.
- News · Oct 17, 2024NIS2 transposition deadline raises identity and access requirements
The NIS2 directive deadline pushed many EU organizations to strengthen MFA, access control, and identity governance as baseline obligations.
- News · Oct 1, 2024CyberArk acquires machine-identity leader Venafi
CyberArk completed its acquisition of Venafi, combining human and machine identity security as certificate and workload identities proliferate.
- News · Sep 26, 2024Okta expands secure identity commitment after support breach
Okta detailed hardening and a secure-identity initiative following its 2023 support-system breach, including session and admin protections.
- News · Sep 12, 2024Apple ships dedicated Passwords app with passkey sync
Apple introduced a standalone Passwords app across its platforms, making passkeys and credential sync more visible to consumers.
- News · Aug 21, 2024NIST releases updated Digital Identity Guidelines (SP 800-63-4) draft
NIST advanced SP 800-63-4, emphasizing phishing-resistant authentication, syncable passkeys, and revised identity proofing guidance.
- News · Aug 13, 2024Fine-grained authorization gains traction with OpenFGA and Cerbos
Developer-led authorization engines saw rising adoption as teams externalized access decisions from application code.
- News · Jul 16, 2024Okta launches identity threat protection with continuous evaluation
Okta introduced Identity Threat Protection, using shared signals to detect risk and revoke sessions in real time across the session lifecycle.
- News · Jul 4, 2024RockYou2024 compilation exposes billions of leaked passwords
Researchers reported a massive aggregation of previously leaked passwords, a reminder that credential reuse keeps fueling account-takeover attacks.
- News · Jun 25, 2024Snowflake moves to enforce mandatory MFA after attack wave
Following customer breaches, Snowflake began letting admins enforce MFA and moved toward mandatory multifactor authentication for accounts.
- News · Jun 18, 2024WorkOS acquires fine-grained authorization startup Warrant
WorkOS acquired Warrant to add fine-grained, relationship-based authorization to its enterprise-readiness toolkit for B2B SaaS.
- News · Jun 10, 2024Snowflake customer breaches tied to stolen credentials and missing MFA
A wave of breaches at Snowflake customers was attributed to stolen credentials and accounts without multifactor authentication, fueling major data theft.
- News · May 29, 2024Ticketmaster breach tied to stolen Snowflake credentials
Live Nation confirmed a breach of Ticketmaster data hosted in Snowflake, part of a campaign exploiting accounts without multifactor authentication.
- News · May 20, 2024EU adopts eIDAS 2.0, mandating the European Digital Identity Wallet
The EU adopted eIDAS 2.0, requiring member states to offer digital identity wallets and accelerating verifiable-credential adoption across Europe.
- News · May 2, 2024Google makes passkeys the default sign-in for personal accounts
Google began prompting users to create and use passkeys by default, accelerating mainstream passwordless adoption.
- News · Apr 18, 2024Cisco discloses Duo telephony supplier breach exposing MFA SMS logs
Cisco Duo notified customers that a breach at a telephony provider exposed SMS multifactor message logs, underscoring the weakness of SMS-based MFA.
- News · Apr 15, 2024SailPoint acquires Imprivata IGA business and Osirium
SailPoint expanded through acquisitions including Imprivata governance assets and UK-based PAM vendor Osirium, broadening its identity security platform.
- News · Apr 8, 2024Entrust completes acquisition of Onfido
Entrust acquired identity verification specialist Onfido, adding AI-based document and biometric verification to its IAM and PKI portfolio.
- News · Mar 12, 20241Password acquires passkey startup Passage
Password manager 1Password acquired Passage to accelerate passkey adoption across consumer and business products.
- News · Mar 6, 2024HashiCorp launches Vault Radar to find leaked secrets
HashiCorp introduced Vault Radar to scan code and systems for unmanaged and leaked secrets, extending its secrets-management footprint.
- News · Feb 26, 2024IBM to acquire HashiCorp for $6.4B
IBM agreed to acquire HashiCorp, bringing Vault secrets management and Boundary access into its hybrid-cloud portfolio. The deal closed in 2025.
- News · Feb 21, 2024Change Healthcare ransomware attack began with credentials and no MFA
The Change Healthcare ransomware attack, one of the most disruptive in US healthcare, started with compromised credentials on a server lacking MFA.
- News · Jan 22, 2024Microsoft completes rebrand of Azure AD to Microsoft Entra ID
Microsoft finished renaming Azure Active Directory to Microsoft Entra ID and expanded the Entra family with Internet Access and Private Access.
- News · Jan 19, 2024Microsoft says Midnight Blizzard breached corporate email via a test account
Microsoft reported the Russia-linked Midnight Blizzard group accessed executive email after password-spraying a legacy test account without MFA.
- News · Jan 9, 202423andMe confirms credential-stuffing breach affecting millions
23andMe attributed a large data exposure to credential stuffing against accounts that reused passwords and lacked MFA, later leading to settlements.
- News · Oct 20, 2023Okta discloses breach of its customer support case management system
Okta disclosed that attackers accessed its support system using a stolen credential, exposing session tokens and prompting customers to harden configurations.
- News · Oct 9, 2023Tenable acquires CIEM vendor Ermetic
Tenable acquired Ermetic, folding cloud infrastructure entitlement management into its exposure-management platform.
- News · Sep 14, 2023MGM Resorts disrupted by ransomware after help-desk social engineering
Attackers reportedly reset an employee credential via the help desk to breach MGM Resorts, a high-profile example of social engineering defeating identity controls.
- News · Aug 23, 2023Thoma Bravo completes ForgeRock acquisition, merges it into Ping Identity
Thoma Bravo closed its ForgeRock purchase and combined it with Ping Identity, consolidating two enterprise access-management leaders under one owner.
- News · Jul 11, 2023Microsoft says Storm-0558 forged tokens to access Outlook accounts
Microsoft disclosed that a China-linked group, Storm-0558, forged authentication tokens using a stolen signing key to access email, intensifying scrutiny of token security.