Identity & Access
Authentication, credentials, IAM and zero-trust access control.
Stolen Credentials Unmask Suno's Scraping Infrastructure: Decades of Audio Ingested from YouTube, Stock Libraries, and Podcasts
A security breach at AI music platform Suno has exposed internal source code detailing the company's extensive audio-scraping pipelines, bypassing YouTube's terms via proxy services and harvesting customer information.
Jailbroken Google Gemini Automated 90% of Russian Cybercriminal's Credential and Crypto-Stealing Operation
A TrendAI investigation reveals how a solo Russian-speaking attacker, known as "bandcampro," used a jailbroken Google Gemini to autonomously conduct credential theft and cryptocurrency fraud — including spinning up a new command-and-control server in six minutes and executing 59 unprompted behaviors during infrastructure migration.
Security & Compliance Analyst: How AssuranceAmerica’s Credential Breach Exposed 6.9 Million Drivers
A March 2026 breach targeting an employee credential at AssuranceAmerica exposed names, driver’s license numbers, insurance policy information, and claims data for nearly 7 million individuals across 14 states.
BioShocking: When a Puzzle Game Trains Your AI Browser to Steal Its Own Passwords
LayerX researchers discovered a prompt injection technique called BioShocking that uses themed puzzle games to train AI-powered browsers into ignoring safety guardrails, then commands them to exfiltrate sensitive credentials.
Oak Steps Out of Stealth to Fix the Identity Mess AI Agents Are Making Worse
Co-founded by serial entrepreneur Shai Morag, Oak emerges with $60M to deliver an AI-native unified control plane that replaces legacy IAM tools with real-time access mapping and revocation—ending the era of periodic reviews in a world where AI agents operate at scale. Learn about how AI governance and identity security intersect for autonomous systems.
Beyond the Credential: How an Authentication Bug Facilitated Trade Secret Theft in the Apple-OpenAI Dispute
A breakdown of the zero-day authentication flaw allegedly exploited by a former Apple employee to exfiltrate confidential files, highlighting the critical necessity of rigorous corporate credential offboarding.
LastPass Warns of Fake DocuSign Phishing Campaign Targeting IAM & Access Teams
LastPass and Bitwarden users are being targeted by sophisticated phishing emails mimicking DocuSign to steal master passwords. Here’s what IAM and access management teams need to know—and why your training might be making things worse.
Navigating the New Wave of MFA-Bypassing Phishing Toolkits Targeting Microsoft 365
Analysis of two recently uncovered phishing kits, Jalisco and OmegaLord, and how they utilize specific techniques like device-code abuse and credential harvesting to bypass multi-factor authentication (MFA) on Microsoft 365 accounts.
U.S. Eases AI Export Rules for Anthropic’s Mythos and Fable Models
The United States government has lifted the mandatory export license requirement for Anthropic's Mythos and Fable models, aiming to restore access and adjust to global AI competition.
The AUR Rootkit Crisis: How 400+ Linux Packages Became a Credential-Theft Pipeline
Analysis of a supply chain attack targeting the Arch User Repository (AUR) where over 400 packages were compromised to distribute a Linux rootkit and credential-stealing infostealer malware, exploiting orphaned packages and modified PKGBUILD scripts to deliver eBPF-based rootkit capabilities and targeted credential theft from developer workstations.
One Key to Rule Them All: The Danger of Shared Credentials in Enterprise AI Fleets
New survey data reveals that 69% of enterprises use shared credentials across their autonomous AI agent systems. This architectural shortcut creates a massive security flaw, enabling a single compromised agent to grant access to the entire fleet.
Apple's iOS 27 Will Fix Your Weak Passwords—If the Website Lets It
Apple's iOS 27 introduces an agentic password update feature, allowing users to automatically refresh compromised credentials with a single tap. But how well does it work in the real world?