Identity & Access
Authentication, credentials, IAM and zero-trust access control.
The Stories You Tell Yourself Shape Who You Become
How the labels and narratives we attach to ourselves become self-fulfilling prophecies that drive achievement, resilience, and personal growth—backed by psychology research on self-efficacy, identity, and mindset.
Sweeping Credential Harvesting Heist Compromises 30K Fortinet Devices Across Nearly 200 Countries
A massive credential harvesting campaign has compromised approximately 30,000 Fortinet security devices worldwide, with attackers compiling working credentials and targeting diverse sectors across nearly 200 countries.
Persistence via Rogue Peering: Analyzing the Cisco Catalyst SD-WAN Authentication Bypass
This post explores the CVE-2026-20127 authentication bypass in Cisco Catalyst SD-WAN, examining how rogue peering and version-downgrade tricks allow threat actors to gain persistent administrative access and absolute root-level control.
Unauthenticated OIDC Token Forgery Exploit Grants Administrative Control of SimpleHelp Servers
A critical flaw in SimpleHelp's OIDC implementation allows attackers to forge assertions, bypass MFA, and spawn unauthorized remote management accounts.
Inclusive Mental Health Services in Portland: Navigating Trauma, Identity-Affirming Care, and Relationship Repair
An exploration of Portland's specialized counseling practices focusing on trauma recovery, social justice principles, multicultural and LGBTQIA+ identities, and evidence-based relationship repair.
How Attackers Bypass MFA: Device Code Phishing and Authentication Workflow Exploits
Optimized analysis of how modern phishing attacks bypass multi-factor authentication through device code flows and trust-based credential theft, drawing on the BleepingComputer webinar with Abnormal AI.
BadHost Vulnerability CVE-2026-48710 Exposes Millions of AI Agents to Authentication Bypass
A critical Starlette vulnerability (CVE-2026-48710, nicknamed BadHost) allows attackers to bypass authentication via malformed Host headers, impacting FastAPI-based AI systems including vLLM, LiteLLM, and MCP gateways. The flaw affects Starlette versions prior to 1.0.1.
Fileless Phantom Stealer Targets Browser Credentials
In addition to executing entirely in memory, the malware's infection chain incorporates other anti-analysis techniques designed to frustrate detection.
73 Malicious Packages Target AI Coding Agents with Self-Replicating Credential Stealer
A coordinated attack discovered in June 2026 revealed 73 malicious npm packages designed specifically to target AI coding agents, executing a self-replicating credential stealer the moment an agent processes or opens the file.