The January 8 deal puts continuously granted and revoked access at the center of the Falcon roadmap. Anyone signing a PAM or IGA renewal this year now has a harder question to answer.
Publishers:crowdstrike.com
Reality
- Evidence32
- Adoption12
- Hype gap+46
- Incentives90
- Confidence42
build1 distinct publisher A spraying campaign against Entra ID used OAuth's password grant for Azure CLI to get tokens with no MFA prompt. The lesson is about policy coverage, not about second factors.
Publishers:dev.to
Reality
- Evidence52
- Adoption58
build1 distinct publisher A new Bedrock AgentCore pattern from AWS treats the agent as an orchestrator with no say over access, pushing per-user enforcement down to DynamoDB, Knowledge Bases and Salesforce.
Publishers:aws.amazon.com
Reality
- Evidence56
- Adoption
- Insufficient
- Hype gap
Wiz says rogue device registrations are drifting toward benign names, while nearly one in seven Entra tenants saw such an attack in 90 days. Naming strings were never the signal.
Publishers:wiz.io
Reality
- Evidence42
- Adoption55
A Tenable walkthrough of the Azure ransomware crew makes one operational point worth keeping: the alert that matters fires in the control plane, before anything is encrypted.
Publishers:tenable.com
Reality
- Evidence28
- Adoption
- Insufficient
- Hype gap
Kaspersky says an Iranian-linked framework now picks its channel per transaction from a DNS record, and can swap the Google relay behind it. Allowlisted SaaS domains carry the traffic.
Publishers:thehackernews.com
Reality
- Evidence68
- Adoption62
build1 distinct publisher A Foundry governance walkthrough splits agent permissions into on-behalf-of reads, unattended agent identity, and human approval. Collapsing them into one credential is a publish-time failure.
Publishers:dev.to
Reality
- Evidence42
- Adoption
- Insufficient
- Hype gap