# This Week in Identity, Issue 14

Source: https://startwithidentity.com/newsletter/2026-09-22-this-week-in-identity-14/
Last updated: 2026-09-22
License: content by Start with Identity. Cite the source URL.

---

Issue 14 of This Week in Identity. Most of this week's damage ran on access that was still valid long after anyone needed it.

## In brief

- From February 1, 2027, Microsoft stops delivering SMS and voice authentication codes in Entra ID. Users with no other method must register a passkey to keep signing in, while Global Administrators and external users have until July 1.
- CrowdSec lost about 170 private GitHub repositories through the account of an engineer who had left, whose access it deliberately kept open so he could finish some work. Malware had stolen his token eleven days earlier.
- Cisco ISE flaw CVE-2026-76460 (CVSS 10.0) lets an unauthenticated attacker run commands as root on the engine that decides who gets on the network, and it was exploited before a fix existed.

## The big story

**Entra ID sets the date SMS codes stop, and the most privileged accounts go last.** [Microsoft Entra ID](https://startwithidentity.com/vendors/iam/microsoft-entra/) made passkeys the default on September 1 and has now fixed the end date for the SMS and voice codes it delivers itself. From February 1, 2027, Microsoft-provided SMS and voice authentication ends for everyone except Global Administrators and external users, who follow on July 1. After each cutoff, anyone whose only MFA method is SMS or voice gets a blocking prompt to register a passkey, with no opt-out. Organizations that still need SMS can buy it from a telephony provider through Microsoft Security Store, starting with Soprano and Telesign from October 30, and pay the telecom costs themselves.

Read the dates in reverse. Global Administrators get five more months on SMS than anyone else, which hands the most privileged accounts the longest runway on the weakest factor. There are defensible reasons, since nobody wants the break-glass path to fail first, but the right plan is to move administrators first and deliberately, onto hardware keys, rather than last by default. And a blocking passkey prompt at sign-in is exactly the moment a vishing caller wants; attackers have been [phoning staff about passkey enrollment](https://startwithidentity.com/blog/2026-07-09-entra-passkey-enrollment-vishing-targets-microsoft-365-users/) since the summer. Tell users now how IT will and will not contact them.
Source: [Entra ID stops delivering SMS and voice codes on February 1](https://startwithidentity.com/blog/2026-09-21-entra-id-stops-delivering-sms-and-voice-codes-february-1-and-global-admins-go-last/).

## Patch this week

- **CVE-2026-76460**, Cisco Identity Services Engine and ISE-PIC (CVSS 10.0). Unauthenticated bypass of the management interface through an API endpoint, leading to root command execution, exploited in the wild. Fixed in 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4; no workaround. CISA's KEV deadline was September 19. After patching, rotate the RADIUS secrets and directory accounts the box held. [Post](https://startwithidentity.com/blog/2026-09-17-cisco-ise-cvss-10-auth-bypass-exploited-as-a-zero-day/).

## The pattern

Three stories this week turn on access that outlived its purpose. CrowdSec kept a departed engineer's GitHub access open with no end date, and his stolen token did the rest. Gyazo's breach exposed login session IDs and X integration tokens, which stay usable after a password reset unless the service revokes them. And the [hijacked AI coding session](https://startwithidentity.com/blog/2026-09-16-hijacked-ai-coding-assistant-session-spread-shai-hulud-to-100-repos/) reached about 100 repositories because the developer's machine held GitHub OAuth tokens broad enough to publish into the company's own package namespace. None of these needed a new exploit against an identity system; they needed a credential nobody had retired. See [orphaned account abuse](https://startwithidentity.com/techniques/orphaned-account-abuse/) and [session cookie theft](https://startwithidentity.com/techniques/session-cookie-theft/).

## What else happened

- **CrowdSec lost 170 private repositories through a leaver account it kept open on purpose.** The engineer's laptop was infected by the TanStack npm malware on May 11, the repositories were copied with his token on May 22, and access was revoked on May 25. The exposed secrets were rotated in September, after the code surfaced publicly. A known infection is the trigger for rotation, not a public leak four months later. [Post](https://startwithidentity.com/blog/2026-09-19-crowdsec-kept-a-departing-engineers-github-access-open-and-lost-170-repos/).
- **A hijacked AI coding assistant session spread Shai-Hulud to about 100 repositories**, according to Mandiant. The assistant recommended a poisoned package, the developer accepted, and an infostealer took the developer's GitHub OAuth tokens. Treat a dependency the assistant suggests exactly like one a stranger suggests. [Post](https://startwithidentity.com/blog/2026-09-16-hijacked-ai-coding-assistant-session-spread-shai-hulud-to-100-repos/).
- **Gyazo exposed 23.62 million accounts**, including password hashes with an undisclosed algorithm, login session IDs and X integration tokens. Affected users should sign out everywhere and revoke Gyazo from X's connected apps rather than rely on a password change. [Post](https://startwithidentity.com/blog/2026-09-17-gyazo-breach-exposes-23-million-accounts-with-session-ids-and-x-tokens/).

## New from Start with Identity

- **The [Experts directory](https://startwithidentity.com/experts/) was rebuilt** around the people behind the practice: protocol authors, founders, researchers, policy and standards contributors, 96 profiles across nine categories, with a [nomination and correction form](https://startwithidentity.com/experts/#nominate).
- **Eight alternatives guides**, including [Okta alternatives](https://startwithidentity.com/articles/okta-alternatives/) and [CyberArk alternatives](https://startwithidentity.com/articles/cyberark-alternatives/), each scored against the same rubric as our vendor profiles.
- **Every editorial page now has a plain-markdown version** for AI assistants, at the same URL ending in `.md`, plus [llms-full.txt](https://startwithidentity.com/llms-full.txt) with the full text of our guides, standards and glossary.

## From the community

We are recruiting [volunteers](https://startwithidentity.com/community/#volunteer): news curators, country ambassadors, and jobs scouts. A few hours a week, credited by name.

That's Issue 14. [Subscribe](https://startwithidentity.com/subscribe/) for the next one.
