Start with Identity
This Week in Identity · Issue 11 · 2026-09-01 · Covers 2026-08-26 to 2026-09-01

This Week in Identity, Issue 11

Issue 11 of This Week in Identity, the digest from the Start with Identity community. We read the week's identity news, link the primary sources, and add the line on why it matters.

In brief

  • WebAuthn Level 3 is a W3C Recommendation, which turns conditional create, the Signals API, and Related Origin Requests from working drafts into something you can write a policy against.
  • Infostealers are draining paid Claude subscriptions using stolen session cookies. No password, no MFA prompt, and signing the user out does not remove the malware.
  • A cybercrime service sold lookups against 153 million driver's licences that its operators say they exfiltrated from an identity verification vendor over more than a year.

The big story

WebAuthn Level 3 reached Recommendation status on August 25, 2026. Nothing your browser does changes this week. What changes is that an enterprise writing a passkey standard no longer has to cite a moving working draft, which was a poor foundation for an authentication policy and an actively bad one for an auditor.

Two items matter more than the rest. The Signals API is the first standard answer to the revocation problem every passkey rollout hits: when an account closes or a credential is removed server-side, the passkey previously sat in the user's credential manager forever, offering to sign them into something that no longer existed. And conditional create is the migration lever, because it turns passkey adoption from a task the user must choose into a by-product of a login they were already doing. Given that enrollment is where the attacks moved once the cryptography held, a standardised enrollment path with defined semantics is worth more than the feature list suggests. Source: WebAuthn Level 3 is a W3C Recommendation.

Patch this week

  • CVE-2026-82329, JFrog Artifactory (CVSS 9.8). Instances with no explicit join key got a predictable "phantom" one, letting an unauthenticated attacker mint administrator tokens. Fixed in 7.161.20, exploited from September 1. Post.

The pattern

Three of this week's stories end at a credential that cannot be rotated. A stolen session cookie is valid wherever it is presented. A driver's licence number is good for years and is the knowledge base behind help desk verification. Only the Artifactory token can actually be revoked. Identity controls are built around the assumption that a compromised secret can be replaced, and a growing share of what attackers now collect breaks that assumption outright. See session cookie theft and help desk social engineering.

What else happened

  • Infostealers are hijacking Claude sessions. Anthropic's own caveat is the one to steal for your runbook: revoking the session stops the theft, the infected machine re-harvests the next one. Endpoint cleanup is a precondition for rotation, not a follow-up. Post.
  • A service sold 153 million driver's licences scraped from IDScan.net, which processes over 21 million verifications a month. The FBI opened an investigation and the vendor confirmed unauthorized access. Every large document dump makes knowledge-based caller verification permanently worse. Post.
  • McKesson disclosed a breach that began with vishing against Okta SSO, then reached Salesforce and Snowflake. Post.
  • AnonyMousKIT rents an AI voice agent that calls theft victims in three languages and asks for their passcode and live 2FA code, at roughly ten cents a call. Post.
  • Amazon reported 175 million customers using passkeys, six times faster than passwords, with passkeys default on mobile for anyone who already made one. Post.
  • Integrity360 bought CyberIAM, adding roughly 120 practitioners and 18 million euros of identity services revenue. Post, M&A hub.

New from Start with Identity

  • The identity attack technique library launched: 25 briefs organized by the identity control that fails, cross-linked to 31 CVE briefs and the breach teardowns. It is the layer between /cves (the instance) and /breaches (the incident): the class.

From the community

Corrections are welcome and credited. The contact form reaches an editor.

That's Issue 11. Subscribe for the next one.

Free to read and share. Independent and community-driven, no sponsorship. Subscribe to get the next issue.