Access Management & IAM Security
Articles on identity and access management (IAM), access control systems, approval workflows, passkey adoption, and how companies balance security with developer velocity
LastPass Warns of Fake DocuSign Phishing Campaign Targeting IAM & Access Teams
LastPass and Bitwarden users are being targeted by sophisticated phishing emails mimicking DocuSign to steal master passwords. Here’s what IAM and access management teams need to know—and why your training might be making things worse.
Why Microsoft 365's Built-In Data Protection Falls Short for Business
Microsoft 365 is often mistaken for a complete data protection solution, but its native features—version history, recycle bins, and retention policies—are not backups. Under the shared responsibility model, organizations bear full accountability for backup and recovery, leaving them exposed to ransomware, insider threats, compliance failures, and costly scaling challenges.
The DMCA Trap: How Fake Copyright Claims Remove Live Pages From Google
Analysis of how DMCA copyright complaints are exploited to remove legitimate pages from Google search results, the takedown process mechanics, and how site owners can detect and respond to false claims.
U.S. Eases AI Export Rules for Anthropic’s Mythos and Fable Models
The United States government has lifted the mandatory export license requirement for Anthropic's Mythos and Fable models, aiming to restore access and adjust to global AI competition.
RIPE NCC Pulls Back From Cloud Migration — Europe's Internet Registry Rebuilds On-Premises
RIPE NCC is reversing its cloud-first strategy after geopolitical jitters — particularly around reliance on US hyperscalers — prompted a reassessment of infrastructure risk. The regional internet registry will rebuild on-premises datacenter capacity with geographically redundant storage, greenfield deployment by 2028, and capex levels not seen since before 2020.
How a Silent Software Vulnerability Exposed 12 Million Users at Japan's KDDI and Partner ISPs
Logan Bastion breaks down the architecture failure behind the KDDI zero-day exploit, which exposed the email addresses and passwords of over 12 million users across five partner ISPs.
Questions Remain About Estonia's State ID System and AI Agent Exposure
Estonia's plan to issue state-backed digital identities to AI agents raises major security concerns. A security & compliance analyst breaks down the administrative, cryptographic, and operational risks.
Why Every Security & Compliance Analyst Must Think Like an Operational Engineer
A look at the imperative for aligning governance, risk, and compliance with hands-on security engineering, featuring insights from BNSF's Yelena Mujibur Sheikh.
Robinhood Made Security Invisible—Here’s How
How Robinhood’s appsec team built SERA, a passkey-driven approval platform that lets engineers grant access from any device—cutting delays in half while hardening identity verification.