Start with Identity
This Week in Identity · Issue 8 · 2026-08-11 · Covers 2026-08-05 to 2026-08-11

This Week in Identity, Issue 8

Issue 8 of This Week in Identity. Black Hat delivered, and the theme was implementations rather than standards.

In brief

  • Three passkey attacks landed in one week and none of them broke WebAuthn. They broke implementations, storage, and enrollment.
  • Two CVSS 10.0 flaws shipped: a Terraform MCP server serving one user's token to another user's request, and a Metabase zero-day giving admin through password reset.
  • Opening a GitHub issue was enough to reach CI secrets in Claude Code and Gemini CLI, and GhostSplice showed that splitting a malicious instruction takes agent refusal rates to zero.

The big story

Three passkey attacks in one week, none of them touching the cryptography. Pass-the-Passkey found WebAuthn implementation bugs. Unit 42 extracted Google's synced passkey keys from Chrome's memory. Malware drove a Windows Hello key for Entra persistence with no PIN prompt.

Why it matters: the standard is holding, and that is worth saying clearly before the "passkeys are broken" headlines. What is not holding is everything around it. Key storage in a browser process, enrollment flows that accept an attacker's registration, recovery paths that fall back to a password, and platform authenticators that can be driven by malware already on the device. Our analysis is three passkey attacks target everything except the cryptography. The practical read for a rollout: the credential is strong, so attack effort moves to enrollment and recovery, and that is where your controls need to be.

Patch this week

  • Terraform MCP server, CVSS 10.0: one user's token served another user's request. This is cross-tenant token confusion. Post.
  • Metabase, CVSS 10.0 zero-day: admin access through the password reset endpoint, the same class as the Keycloak flaw two weeks later. Post.
  • N-able N-central: confirmed use against managed customer networks after the incomplete first fix. Post.

The pattern

Four of this week's stories are about agents and their credentials: the Terraform MCP token mix-up, GitHub issues reaching CI secrets, 4,576 leaked n8n tokens with a third of instances accepting them, and GhostSplice. The common failure is scope. An agent or automation platform holds a credential broad enough to be worth stealing and reachable through an input channel nobody classified as untrusted. Static API key abuse and agent instruction injection are the two halves.

What else happened

  • GhostSplice fragments a malicious instruction across MCP channels so no single piece looks harmful, taking several models from 100 percent refusal to 100 percent compliance. Post.
  • GitGuardian found 4,576 leaked n8n tokens, and a third of reachable instances accepted them. Post.
  • Kali365 phishes Microsoft's own device login page for durable Microsoft 365 tokens. Post.
  • Over 1,000 AI-named npm typosquats delivered a cross-platform dropper. Post.
  • The Snowflake attacker pleaded guilty, two years after stale credentials did the work. Our teardown: Snowflake 2024. Post.

New from Start with Identity

  • Black Hat USA 2026 identity coverage, pulling the week's research into one thread.
  • 26 curated news posts verified against primary sources, clearing the queue backlog.
  • Three vendor profiles and a four-piece B2B SaaS content set.

From the community

Corrections are welcome and credited. The contact form reaches an editor.

That's Issue 8. Subscribe for the next one.

Free to read and share. Independent and community-driven, no sponsorship. Subscribe to get the next issue.