This Week in Identity, Issue 3
Issue 3 of This Week in Identity, the digest from the Start with Identity community. We read the week's identity news, link the primary sources, and add the line on why it matters.
In brief
- Consent phishing needs no password and survives every credential reset, because the attacker holds a grant rather than a secret.
- Non-human identity consolidated again: SailPoint closed Entro at a reported 200 million dollars, the second NHI acquisition of the year.
- EMVCo is drafting a single verifiable payment credential standard, which would end the per-wallet integration tax merchants pay today.
The big story
ConsentFix turned OAuth consent into a three-step account takeover. The kit walks a Microsoft 365 user through a genuine Microsoft consent screen for an attacker-registered application, and the user approves it because the screen is real. No password is captured and no MFA prompt is bypassed, because neither is involved.
Why it matters: a consent grant is a durable authorization, not a credential. Resetting the password does nothing. Revoking sessions does nothing. The grant persists until someone revokes the grant specifically, and most organizations have no process that ever does. This is the technique we now catalog as OAuth consent phishing, and the control that works is restricting user consent to verified publishers, then reviewing the grants you already have. Source: our writeup, ConsentFix and ClickFix.
The pattern
Two of this week's three stories are about authorization rather than authentication. The industry spent a decade hardening the login and comparatively little on what happens after it: which grants exist, which tokens are still live, and who can approve a scope on the organization's behalf. Attackers noticed first.
What else happened
- SailPoint closed its Entro Security acquisition, reportedly around 200 million dollars, folding secrets and machine-identity discovery into an IGA platform. Track the wave on our identity M&A hub. Post.
- EMVCo drafted a single standard for verifiable payment credentials, so a merchant integrates once rather than per wallet. It is the same consolidation logic that made OpenID Connect win over bespoke federation. Post.
New from Start with Identity
- A non-human identity pillar, covering machine identity and NHI fundamentals, plus an AI agent security guide and an enterprise ranking.
- The decentralized identity build-out landed: fundamentals, glossary terms, standards pages, guides, vendor profiles, and rankings. Start at what is decentralized identity.
- The vendor directory grew to 288 profiles, and rankings gained segment cuts (startups, enterprise, high-scale, compliance) across ten categories.
From the community
New to identity, or planning a move? Start with the guided learning path. We are recruiting volunteers: news curators, country ambassadors, and jobs scouts.
That's Issue 3. Subscribe for the next one, and send corrections through the contact form.