Skip to content

Topic

Identity and Access Management

IAM is the field of technology and practice for verifying identities and controlling access, encompassing authentication and authorization.

Current stories

security2 publishers

Compromised login to DTU's identity system put up to 200,000 people's records at risk

Technical University of Denmark says a login with compromised credentials to its IAM system may have exposed data on up to 200,000 people. The records reach back to 2003, and active users' entries include CPR national ID numbers that DTU warns can be used for identity fraud.

Reality

Evidence55
Adoption
Insufficient
Hype gap+15
Incentives
Insufficient
Confidence62
security1 publisher

Blueprint Alliance coalition aims to build agentic AI security standards around four key questions, lists six identity principles as governance guidance

Okta has gathered a dozen-odd technology companies into the Blueprint Alliance to write open security and interoperability standards for AI agents. The standards are still unwritten, and the six principles published so far are identity-management rules, the category Okta sells.

Publishers:scworld.com

Reality

Evidence45
Adoption10
Hype gap+25
Incentives75
Confidence40
security2 publishers

Entra ID sign-in pages will run only Microsoft-hosted scripts from mid-October

Microsoft will allow only scripts from its own CDN domains during Entra ID browser sign-ins under a Content Security Policy enforced from mid-October 2026. Browser extensions and tools that inject code into the sign-in page will stop working as the rollout completes in late October.

Reality

Evidence62
Adoption
Insufficient
Hype gap+10
Incentives30
Confidence70
security2 publishers

Okta's Blueprint Alliance gives buyers a six-point checklist for AI agent identity

Okta and 11 vendors including AWS, Google Cloud and CrowdStrike signed six shared principles for securing AI agents under a new Blueprint Alliance. Buyers can put the list to vendors in procurement now, while Okta's release describes a reference architecture with no stated way to test compliance.

Publishers:okta.comscworld.com

Reality

Evidence40
Adoption
Insufficient
Hype gap+35
Incentives70
Confidence55
security5 publishers

Six 10.0s in the control plane, and nothing in your patch queue to show for it

Microsoft shipped 22 updates, six of them scored 10.0, mostly in Entra ID, Exchange Online and Azure. Fixed server-side is not the same as verified in your tenant.

Perspective Coverage

5 publishers
Builder
Builder 20%
Operator
Operator 65%
Investor
Investor 15%

Reality

Evidence62
Adoption
Insufficient
Hype gap+40
Incentives55
Confidence55
security5 publishers

ShinyHunters phished the firm that had just profiled it, and device trust was the only thing that mattered

A ReliaQuest employee gave up a password and an MFA push five days after the company named the .claims campaign. Device trust, not training, kept the session worthless.

Perspective Coverage

5 publishers
Builder
Builder 29%
Operator
Operator 56%
Investor
Investor 15%

Reality

Evidence58
Adoption
Insufficient
Hype gap+25
Incentives70
Confidence62
security3 publishers

Keycloak's forgotten-password flow hands over admin accounts, and the fix is already tagged

CVE-2026-18963 lets an unauthenticated request skip the emailed reset token entirely. Upstream 26.7.2 and four Red Hat errata are out, and the stopgap has to be set realm by realm.

Publishers:access.redhat.comgithub.comkeycloak.orgthehackernews.com

Perspective Coverage

4 publishers
Builder
Builder 43%
Operator
Operator 51%
Investor
Investor 6%

Reality

Evidence78
Adoption
Insufficient
Hype gap+8
Incentives30
Confidence72

Earlier coverage

  1. Scoped identity with iam:PassRole could potentially run as prod-admin via a Lambda function it creates, if unblocked by policy controls

    Security · September 23, 2026 · 1 publisher

  2. A rogue external MFA provider plants a fake Microsoft password prompt in Entra's login flow

    Security · September 22, 2026 · 1 publisher

  3. Unauthenticated attackers can reset any Industrial Edge Management password without the email link

    Security · September 22, 2026 · 1 publisher

  4. Okta puts an enforcement point between AI agents and the tools they call

    Product · September 22, 2026 · 1 publisher

  5. Storing each domain and mailbox proof as a timestamped event lets an auditor replay a disputed join

    Build · September 21, 2026 · 1 publisher

  6. Crossing $1M in revenue turns Duende's free IdentityServer tier into a $12,500 bill

    Build · September 21, 2026 · 1 publisher

  7. Trail of Bits traces SAML's insecurity to the XML signature layer underlying most fielded implementations

    Security · September 21, 2026 · 1 publisher

  8. Six agencies in five countries name the 17 most common Active Directory attacks

    Security · September 21, 2026 · 1 publisher

  9. Microsoft folds Storm-2372 into Midnight Blizzard 17 months after first naming it

    Leadership · September 20, 2026 · 1 publisher

  10. Revoking the stolen tokens left GhostCode's Intune device inside the tenant

    Leadership · September 20, 2026 · 1 publisher

  11. Enterprise admins can revoke every SSO-authorized GitHub credential in one action

    Security · September 20, 2026 · 1 publisher

  12. Hard-coded static key in SolarWinds Access Rights Manager hands unauthenticated attackers RCE

    Security · September 19, 2026 · 1 publisher

  13. Restricting an agent to read-only views removes the runtime SQL construction it once had

    Build · September 18, 2026 · 1 publisher

  14. A recovery-decision event can be written before the provider's own event id exists

    Build · September 18, 2026 · 1 publisher

  15. NIST and CISA finalise token-protection guidance citing a single stolen signing key

    Science · September 18, 2026 · 1 publisher

  16. Protected Resource Metadata lets an MCP client discover the sign-in flow behind a 401 -- but Entra can still block the token

    Build · September 18, 2026 · 1 publisher

  17. A Ping-sponsored paper would tie every AI agent to a named human owner

    Security · September 17, 2026 · 1 publisher

  18. AWS runs four JWT claim gates in one Lambda before an MCP tool call reaches its data

    Build · September 17, 2026 · 1 publisher

  19. Handing an agent the user's session token gives it every permission the user has

    Build · September 17, 2026 · 1 publisher

  20. Cisco Patches 44 CVEs Across ISE, FMC, Nexus Dashboard; Separately Warns of Exploited ISE Authentication Bypass Zero-Day

    Security · September 17, 2026 · 1 publisher

  21. Every cross-account role in an AWS landing zone stops at the aws-eusc partition line

    Build · September 16, 2026 · 1 publisher

  22. Google Cloud's security office says an agent ban pushes employees toward less secure automation

    Leadership · September 14, 2026 · 1 publisher

  23. An external app with user consent reads mail without holding an account in the tenant

    Build · September 13, 2026 · 1 publisher

  24. ELN ID promoted its de facto admin check after an audit found zero ServiceRole users

    Build · September 13, 2026 · 1 publisher

  25. Cognito ships a new user pool with MFA off and its sign-in risk model disabled

    Build · September 13, 2026 · 1 publisher

  26. Two of Ping's four AI agent classes act on a human's own login

    Security · September 11, 2026 · 1 publisher

  27. IP Services' CEO would audit a security program by asking when it last restored from backup

    Leadership · September 10, 2026 · 1 publisher

  28. Orchid ships drift detection and a kill switch for agents that inherit unmanaged identity

    Security · September 10, 2026 · 2 publishers

  29. NIST traces the agent accountability gap to users handing over their own credentials

    Science · September 10, 2026 · 1 publisher

  30. Cymphony raises $25M to put AI agents on the same permissions map as employees

    Invest · September 10, 2026 · 1 publisher

  31. Noma's Workflow Identity Hijacking turns a service account into a privilege proxy for strangers

    Build · September 9, 2026 · 1 publisher

  32. Patched, modern Active Directory setups largely mitigate FreeIPA's cross-realm PAC impersonation flaw, FreeIPA says

    Security · September 9, 2026 · 1 publisher

  33. Scattered Spider talks help desks into moving MFA onto attacker-controlled devices

    Security · September 9, 2026 · 1 publisher

  34. An unauthenticated LDAP client can write itself into FreeIPA's administrators group

    Security · September 8, 2026 · 1 publisher

  35. Anonymisation trades away the property that made the test fixture useful

    Build · September 8, 2026 · 1 publisher

  36. authentik checked the PKCE verifier only when the request bothered to include one

    Build · September 5, 2026 · 1 publisher

  37. CNIL puts €500,000 on the control gaps behind a 727,113-record hospital breach

    Security · September 3, 2026 · 1 publisher

  38. October moves NIS2 from transposition into enforcement across the EU

    Security · August 31, 2026 · 1 publisher

  39. Three items, one tier: Keycloak's reset bug, an N-able password leak, a Grok data-theft trick

    Security · August 26, 2026 · 1 publisher

  40. UDS Core's default operator authentication accepted any client secret for three release trains

    Security · August 25, 2026 · 1 publisher