Identity & Access
Authentication, credentials, IAM and zero-trust access control.
Hades Campaign: How Poisoned PyPI Packages Are Scraping Your Cloud Credentials
The Hades Campaign weaponizes 19 PyPI packages to deploy a Bun-based credential stealer that scrapes cloud tokens from process memory across Linux, macOS, and Windows. The malware also injects prompts into AI security scanners to evade detection — a first for supply chain attacks.
Open Doors in the Water Sector: How Exposed PLCs and Default Passwords Invite State-Sponsored Sabotage
Iran, Russia, and China are exploiting internet-facing PLCs and HMIs protected by weak or default credentials to breach water and wastewater systems worldwide — not always for destruction, but for signaling, disruption, reconnaissance, and strategic pre-positioning.
How a Compromised CDN Credential Exposed Over One Million WordPress Sites
A deep dive into the recent supply-chain attack on Awesome Motive's CDN, explaining how a single compromised API key led to the hijacking of over a million WordPress sites, detailed remediation steps, and the critical lessons for site administrators.
New York’s Jewish Voters Are Leaving the Democratic Party — And No One’s Talking About It
Analysis of how New York City's recent electoral trends reflect growing alienation among its large Jewish population, particularly in relation to Democratic Party positions perceived as enabling antisemitism.
ServiceNow’s Blind Spot: How an Unauthenticated API Endpoint Exposed Customer Secrets
Attackers exploited a misconfigured ServiceNow API endpoint to query customer data—while the vendor delayed action, waiting for a bug bounty report to trigger a fix.
Stale Credentials, Stolen Tokens: How the Klue Breach Unlocked Salesforce Data Across Dozens of Companies
After attackers breached competitive-intelligence vendor Klue through a dormant integration credential, they harvested OAuth tokens and used them to exfiltrate CRM data from customers including Huntress, LastPass, Recorded Future, HackerOne, Tanium, and others — prompting the extortion group Icarus to claim responsibility and leak victim data.
How Attackers Broke Dashlane’s 2FA — And Why Your Master Password Still Matters
Dashlane disclosed a coordinated campaign in which attackers abused device-registration API endpoints to brute-force one-time 2FA codes across thousands of user accounts simultaneously. The attack successfully generated valid tokens for fewer than 20 personal-plan customers, allowing encrypted vault downloads — though master passwords protected by Argon2 hashing likely remain secure.
The Startup Building Identity Infrastructure for the Age of AI Workers
Cybersecurity startup NewCore emerged from stealth with $66M in seed funding to build a platform that manages both human and AI-agent identities in one system — treating autonomous software workers as first-class employees with persistent credentials, lifecycle controls, and revocation mechanisms.
Your Netflix Password Isn't Enough Anymore: The New Email Rule Explained
Netflix is requiring every profile on a shared subscription to link a unique email address — a permanent change that's causing confusion for families, solo users with multiple profiles, and anyone who thought their login was private. Here's what the policy shift means for your account, your privacy, and why it matters beyond just streaming.
Langflow’s Unauthenticated File Write Flaw Is Being Actively Weaponized
A high-severity path traversal flaw (CVE-2026-5027) in the popular open-source AI development platform Langflow is being actively exploited. The vulnerability in the file upload endpoint allows unauthenticated attackers to write arbitrary files to server filesystems, with roughly 7,000 instances exposed online.
Unauthenticated Remote Code Execution in Fortinet FortiSandbox Under Active Exploitation by Threat Actors
Attackers are actively exploiting multiple critical vulnerabilities in Fortinet's FortiSandbox platform, including unauthenticated command injection flaws that allow remote code execution without user interaction.
The Hidden Identity Crisis: Why Your AI Agents Are Running Wild in Your Enterprise
Security teams built their programs around controlling human identities. Now AI agents are acting as autonomous actors across enterprise systems — and most organizations have no idea how many they actually have, what those agents can access, or who owns them.