Access Management & IAM Security
Articles on identity and access management (IAM), access control systems, approval workflows, passkey adoption, and how companies balance security with developer velocity
Pass-ta-key: Three Malware Attacks Hijacking Google Synced Passkeys on Windows
Security researchers from Palo Alto Networks' Unit 42 discovered three attacks allowing malware on compromised Windows devices to hijack Google Password Manager's synced passkeys, enabling attackers to take over accounts and bypass user verification.

Kelly Jackson Higgins: Security & Compliance Analyst Editorial Leadership at Dark Reading and Informa TechTarget
An in-depth analysis of Kelly Jackson Higgins' editorial impact at Dark Reading and Informa TechTarget, examining how her leadership shapes cybersecurity coverage for security & compliance analysts navigating identity management, cloud security, and regulatory demands.
Chick-fil-A Breach: What the Security & Compliance Analyst Needs to Know
Chick-fil-A disclosed a fresh credential stuffing breach hitting customer accounts. Here is what every security & compliance analyst needs to evaluate.
Hotel Gateway DNS Poisoning Targets Microsoft 365: What Every Security & Compliance Analyst Must Know
Attackers are altering hotel Wi-Fi router DNS settings to trick remote workers into fake Microsoft 365 logins and OAuth device code prompts. Here is how a security & compliance analyst can harden endpoints.
Chick-fil-A Account Attack: What Every Security & Compliance Analyst Must Know
An analysis of the June 2026 Chick-fil-A credential stuffing breach affecting 13,000+ customer accounts, detailing exposed data, IAM risks, and enterprise identity controls.
How a Security & Compliance Analyst Can Master the 8 CISSP Domains on a Budget
An in-depth guide for security & compliance analysts evaluating CISSP preparation, comparing (ISC)² official pathways with the $19.99 CISSP Security & Risk Management Training Bundle.
OnTrac Corporate Network Breach: A Security & Compliance Analyst Breakdown of Last-Mile Intrusions
An in-depth security analysis of the March 2026 OnTrac corporate network breach, highlighting last-mile supply chain risks, data redaction tactics, and identity access lessons.
Beyond the Patch: Architectural Lessons for the Security & Compliance Analyst
A deep dive into the critical Azure Cosmos DB vulnerability, analyzing the systemic architectural risks for cloud infrastructure and what security teams must learn from it.
Why Every Security & Compliance Analyst Needs to Watch Exchange Online's Quarantine Recurrence
Analysis of the July 2026 Exchange Online mailbox quarantine incident (EX1436407) caused by indexing memory spikes, its connection to Azure maintenance outage MO1437424, and PowerShell diagnostics for security and compliance analysts.
California DROP Rollout: What the Security & Compliance Analyst Needs to Know
California's Delete Request and Opt-out Platform (DROP) goes live with mandatory broker compliance starting August 1. Here is what security & compliance analysts need to know about SB 362, identity verification risks, and enterprise data governance.
Software Supply Chain Resilience: A Security & Compliance Analyst Guide to SBOM Verification and AI Secrets Remediation
An in-depth security & compliance analyst report on CISA's 2025 SBOM minimum elements, supply chain risks, and AI agent secrets sprawl in Git history.
Automated Maintenance Gone Awry: Resilience Lessons for AI Cloud Infrastructure Companies in India
Detailed analysis of the July 2026 Azure outage, incorporating resilience lessons for AI cloud infrastructure in India and definitions of emerging AI agent concepts.