Start with Identity
This Week in Identity · Issue 5 · 2026-07-21 · Covers 2026-07-15 to 2026-07-21

This Week in Identity, Issue 5

Issue 5 of This Week in Identity. The passwordless push continues, and so does the reminder that patched is not the same as remediated.

In brief

  • Google Workspace now supports FIDO2 security keys for Windows login, days after Entra made passkeys the default. Both major workforce platforms now treat phishing-resistant credentials as the default path.
  • Qilin affiliates are using a patched PAN-OS authentication bypass as their primary front door, which tells you how many appliances stay unpatched.
  • A gesture on a locked Android phone let Gemini send SMS with no PIN, quietly turning the assistant into an authenticated actor on the lock screen.

The big story

Qilin ransomware affiliates adopted a patched PAN-OS authentication bypass as their standard initial access. The fix existed. The exploitation did not slow.

Why it matters: an authentication bypass on a network edge appliance has a long tail that patch metrics do not capture. Two things keep it exploitable after the patch ships. First, the appliance was never inventoried by the team that owns patching, because it belongs to networking. Second, and more often missed, patching does not evict a session or invalidate a credential the attacker already took. Every identity appliance CVE needs the same three-step close-out: patch, terminate all sessions, rotate the directory bind accounts and signing keys the box holds. Skip the second and third steps and you have a patched appliance with an attacker still inside it. Source: Qilin exploits PAN-OS auth bypass.

The pattern

This week's incidents share a shape: the attacker is not defeating a control, they are arriving somewhere the control does not run. Past the appliance's authentication check. Inside a browser session where the token already exists. On a lock screen where the assistant is trusted. Controls that evaluate a login are blind to all three. Session cookie theft is the canonical version.

What else happened

  • Google Workspace put FIDO2 keys into the Windows login, closing the gap where the desktop was the weak link in an otherwise phishing-resistant estate. Post.
  • ACR Stealer used ClickFix lures to take browser tokens and OneDrive files. An infostealer that takes session cookies skips authentication entirely. Post.
  • A two-finger gesture let anyone holding a locked Android phone send SMS through Gemini, no PIN. If SMS is still a recovery factor anywhere in your estate, a lock screen is now part of that factor's threat model. Post.
  • Abbott investigated two incidents, one beginning with a vished Entra account. Help desk and employee social engineering remains the most productive initial access route in the enterprise. Post.

New from Start with Identity

  • A Microsoft Entra External ID profile and a new Top B2B SaaS identity platforms article.
  • Outbound links now carry rel="nofollow" sitewide, per Google's qualify-outbound-links guidance, with our founder's authored site kept dofollow.

From the community

We publish our methodology for capability scores. If a score looks wrong, tell us and we will show our work.

That's Issue 5. Subscribe for the next one.

Free to read and share. Independent and community-driven, no sponsorship. Subscribe to get the next issue.