Start with Identity
This Week in Identity · Issue 15 · 2026-09-29 · Covers 2026-09-23 to 2026-09-29

This Week in Identity, Issue 15

Issue 15 of This Week in Identity. A new federal front door made the right first identity decision, and the rest of the week showed what happens to credentials nobody owns.

In brief

  • America.gov launched on September 29 as an AI front door to federal services, and the executive order behind it names Login.gov as its authentication service under an existing single sign-on mandate, 6 U.S.C. 1523(b)(1)(D).
  • A password-spraying campaign against more than 5,700 Microsoft 365 accounts compromised seven, and every one was an unmanaged functional or service account on a default or unrotated password with no MFA.
  • The private email address GitLab issues for filing issues by email works as a non-expiring token that can commit code and start CI jobs as the user, bypassing MFA. GitLab considers it intended behavior.

The big story

America.gov launched, and the line that matters is the one about Login.gov. The General Services Administration and the White House National Design Studio launched America.gov, a conversational entry point that answers questions about federal services and routes people to the right agency across more than 29,000 federal websites. The executive order signed the same day directs GSA to use Login.gov as America.gov's authentication service and tells agencies to complete their own Login.gov integration. It also commits to data minimization, "auditable authorization", and no centralized federal system of records. Transactions such as Medicare enrollment and passport applications are planned for 2027, and OMB owes agencies implementation guidance by December 28.

Why it matters: the chatbot got the coverage, but the identity choices decide whether transactions can safely sit behind it. The statute the order cites already required agencies to implement the single sign-on platform GSA develops for any public website that needs authentication, so this turns an existing requirement into a deadline. What to watch is what the OMB memo requires: phishing-resistant sign-in by default for a single front door that will be impersonated from day one, identity proofing matched to each transaction under NIST SP 800-63, authorization requested per agency at the moment of use, and a hard line between what the AI may suggest and what only the authenticated person can approve. Our founder Deepak Gupta's walkthrough of America.gov covers what the service does today and how other governments approached the same problem. Source: America.gov explained: why the identity layer matters more than the chatbot.

Patch this week

  • CVE-2026-35273, Oracle PeopleSoft. Unauthenticated remote code execution, patched by Oracle on June 11 and being exploited by ShinyHunters with a URL-encoding trick (/%50SEMHUB/ for /PSEMHUB/) that slips past WAF rules matching the literal path. If a WAF rule was your mitigation, patch now and search WebLogic logs for /PSEMHUB/ and its encoded variants. Post.
  • GitLab incoming email tokens. No patch is coming, because GitLab treats the behavior as intended. Reset the token for any account whose incoming email address has appeared in a README, ticket or wiki. Post.

The pattern

Four stories this week ran on credentials no person was responsible for. The spraying campaign succeeded only against functional accounts nobody owned. JadePuffer entered through a service principal secret posted in a public GitHub issue. The GitLab address is a bearer token that looks like an email address, so it never makes it into a token inventory. And more than 16,000 Supabase databases trusted a public key because row-level security was never switched on. Inventories built from the HR system see people; the entry points this week were the identities with no person attached. We wrote up what to change in The credentials nobody owns. See password spraying, static API key abuse and secrets in repositories and CI.

What else happened

  • A TeamFiltration spraying campaign found its way in through seven service accounts. Proofpoint tracked it across 28 Microsoft 365 tenants from 1,487 AWS addresses. Within two minutes of access the attacker was requesting Microsoft Graph tokens. List accounts that can sign in interactively but have no named owner, and block interactive sign-in for those that do not need it. Post.
  • GitLab's incoming email token can commit to main and run CI as you, according to Aikido Security. It does not expire and covers every project the account can open. Branch protection limits where a mailed patch lands, but not the CI jobs, which is where the secrets are. Post.
  • JadePuffer wiped Azure resources in seven minutes using two compromised service principals and an AI-driven toolchain, according to Microsoft, pulling storage keys and deleting recovery locks along the way. A principal that can read secrets and delete locks is standing destructive privilege. Managed identities remove the secret that leaked. Post.
  • Bitget lost $388 million without losing a private key. The attacker reached an internal management system through a zero-day in a third-party security product and issued withdrawals as an administrator. Independent approval for high-value actions, through a channel the admin session cannot reach, is the control that was missing. Post.
  • More than 16,000 Supabase databases were readable by anyone, per UpGuard, because row-level security was missing and the public key read every row. Authentication worked; authorization did not exist. Many of the apps appear to have been built with AI coding agents. Post.
  • Dutch police arrested a suspect in the ShinyHunters investigation on September 15. The group denies any link and its attacks have not slowed; its method remains a phone call to someone who can enter or reset credentials. Post.

New from Start with Identity

From the community

We are recruiting volunteers: news curators, country ambassadors, and jobs scouts. A few hours a week, credited by name.

That's Issue 15. Subscribe for the next one.

Free to read and share. Independent and community-driven, no sponsorship. Subscribe to get the next issue.