Identity & Access
Authentication, credentials, IAM and zero-trust access control.
The EU Mandates Open Data Access for Google’s Search Competitors
Research and analysis on the new EU mandate under the DMA requiring Google to share anonymized search data and open Android to rival AI assistants. (twentyTaskId: )
Travelers Beware: Your Hotel Wi-Fi Just Might Be an Attack Vector
Security professionals must warn traveling employees: hotel and conference Wi-Fi networks are being hijacked to systematically compromise Microsoft 365 accounts. Discover the technical mechanics and essential defense strategies.
Chick-fil-A Breach Exposes Customer Data in Credential Stuffing Attack
Chick-fil-A discloses a data breach from credential stuffing attacks between June 17-19, 2026, exposing customer names, emails, membership data, and partial card information. Analysis of the attack vector, AI-powered threat landscape, and steps customers should take.
Microsoft is working to resolve an ongoing Exchange Online issue that has been mistakenly quarantining customers' mailboxes
Microsoft is racing to undo a cascading Exchange Online failure that began July 19, 2026, when a routine infrastructure change caused runaway memory consumption and incorrectly quarantined customer mailboxes, blocking email delivery and calendar access. Cleanup of excess indexing data reached 72% by Wednesday evening with no full-resolution timeline yet announced.
Why Stolen Credentials Keep Breaking Into Critical Infrastructure — and What Device-Bound Identity Can Do About It
From Colonial Pipeline's dormant VPN account to Volt Typhoon's years-long persistence inside U.S. critical infrastructure, identity-based attacks follow a familiar but devastating playbook. This article examines why credentials alone can't anchor zero trust, how state-backed threat actors exploit the gaps, and why binding identities to specific verified devices is emerging as a practical first step for utilities, energy, and transportation operators.
Your Gaze Is a Fingerprint—And AI Is Already Reading It
A new Dartmouth study reveals that AI can identify individuals by analyzing the abstract thematic patterns in their eye movements — not the objects they look at — using LLMs to decode subconscious conceptual priorities encoded in gaze.
AI Cybersecurity Threats: How ClickLock Uses Coercive UI Loops to Steal macOS Credentials
A new macOS malware named ClickLock terminates system processes and traps users in fake password dialogs to steal login credentials, browser data, and cryptocurrency wallets — a chilling example of how AI-driven social engineering bypasses traditional defenses.
AI Cybersecurity Threats: How UAT-11795 Weaponizes Legitimate Apps to Steal Credentials with Starland RAT
A financially motivated Russian threat actor tracked as UAT-11795 is using trojanized installers of legitimate software like WebEx and Zoom to deploy the Starland remote access trojan, stealing browser data, cryptocurrency wallets, and Active Directory credentials.
Identity-First Extortion: How the Helix Gang Uses Vishing and Device-Code Phishing to Steal SharePoint Data
A new data-extortion group called Helix is leveraging identity-focused attack techniques — voice phishing, device-code authentication abuse, and MFA hijacking — to compromise Microsoft 365 tenants and exfiltrate SharePoint data for ransom.
Agents as Identities: The IAM Gap Every Enterprise Is Ignoring
AI agents are quietly becoming privileged insiders in enterprise systems — yet most security teams have no inventory, governance model, or least-privilege controls for them. An opinion piece by Todd Thiemann (principal analyst, Omdia) on TechTarget provides one of the clearest frameworks for understanding identity security for AI agents, while a 2026 survey finds 82% of organizations have discovered AI agents created without security's knowledge, and 54% have already suffered agent-related security incidents. The identity layer that IAM teams spent a decade building was designed for humans and service accounts, not autonomous agents that create, use, and rotate credentials at machine speed.
Passkeys Will Become the Default Authentication Method for Entra ID — Here's What Changes
Microsoft announces that passkeys will become the default authentication method for Entra ID enterprise identity starting September 2026, with SMS and voice authentication fully retired by February 2027. What security teams need to know about the migration timeline, admin tooling, and why AI-driven phishing makes this urgent.
Who Governs the Autopilot? Mitigating Non-Human Identity Sprawl and Image-Based Prompt Injections in Agentic AI
An analysis of security vulnerabilities in autonomous AI agents, highlighting non-human identity governance risks and the multimodal GhostCommit prompt injection exploit.