NIST and CISA have finalized IR 8587, guidance that spells out how signing keys, token verification and revocation are supposed to be handled in cloud identity systems.
Perspective Coverage
4 publishers
- Builder
- Builder 40%
- Operator
- Operator 55%
- Investor
- Investor 5%
Reality
- Evidence80
- Adoption
- Insufficient
- Hype gap+5
- Incentives30
- Confidence75
The FBI published version 6.1 on June 25, 2026, keeping v6.0's NIST-aligned structure while lifting SC-13 and SC-28 to a 256-bit minimum and tripling how often agencies must run vulnerability scans.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives65
- Confidence55
NIST and CISA have finalised implementation guidance for the identity tokens behind single sign-on, written for federal agencies and their cloud providers. The case the announcement rests on is one cited attack.
Reality
- Evidence58
- Adoption16
- Hype gap+12
- Incentives45
- Confidence60
Pulumi's research preview builds a threat model before it looks for anything, then leans on two inputs its own post treats as conditional, the infrastructure code behind a resource and the runtime telemetry around it.
Publishers:pulumi.com
Reality
- Evidence22
- Adoption8
- Hype gap+45
- Incentives90
- Confidence45
An essay on dev.to argues ISO 27001, SOC 2 and NIST SP 800-53 were built around authenticated human decisions with a paper trail. AI sessions leave none, and you cannot reconstruct them later.
Reality
- Evidence24
- Adoption
- Insufficient
- Hype gap+34
- Incentives
- Insufficient
- Confidence30