Technical University of Denmark says a login with compromised credentials to its IAM system may have exposed data on up to 200,000 people. The records reach back to 2003, and active users' entries include CPR national ID numbers that DTU warns can be used for identity fraud.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence62
MacPaw, the CleanMyMac maker, is launching Leebry, an AI platform for IT teams whose prototype resolved 30% of MacPaw's own level 1 tickets. Admins weighing it are working from MacPaw's own survey and MacPaw's own help desk, so a pilot on their own ticket queue is the evidence that counts.
Reality
- Evidence30
- Adoption10
- Hype gap+35
- Incentives70
- Confidence40
Okta's forward earnings multiple went from about 18x to about 50x in five months while its full-year EPS guide rose about 2%. That ties the price as much to investors' view of AI security stocks as to Okta's own forward bookings.
Reality
- Evidence55
- Adoption40
- Hype gap+35
- Incentives
- Insufficient
- Confidence50
Anthropic and OpenAI took a joint problem statement covering six agent authorization problems to the OAuth Working Group on September 28, 2026. A dev.to analysis of the session argues integration teams can fix the data model they own before any standard arrives.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence40
Delinea's 2026 survey found 99.7% of IT and security leaders have a formal AI data policy, but only about 51% check AI access against it in real time. For responders, the shortfall comes after an agent starts acting: how fast out-of-scope access is seen, and how fast it is taken away.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence40
PwC's survey of about 4,000 business and tech leaders found no agreed owner for AI risk, with the CIO or CTO the top answer at just 29%. Until that settles, the usable control is per agent: its own credential and one named owner.
Reality
- Evidence45
- Adoption33
- Hype gap+15
- Incentives50
- Confidence50
Ping Identity has launched three agents that let Gemini Enterprise administrators reset passwords, end sessions and change access by typing a request. IT teams now have to decide whether a confirmation inside a chat window meets their change-control and audit rules.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+20
- Incentives75
- Confidence45
GroundedDocs, a FastAPI RAG service, verifies Keycloak-signed tokens that expire in about 15 minutes and holds no key that can sign one. Keycloak now keeps the passwords and the signing key, so the identity provider becomes the system worth attacking.
Reality
- Evidence55
- Adoption8
- Hype gap+5
- Incentives20
- Confidence45
Okta has gathered a dozen-odd technology companies into the Blueprint Alliance to write open security and interoperability standards for AI agents. The standards are still unwritten, and the six principles published so far are identity-management rules, the category Okta sells.
Reality
- Evidence45
- Adoption10
- Hype gap+25
- Incentives75
- Confidence40
Microsoft will allow only scripts from its own CDN domains during Entra ID browser sign-ins under a Content Security Policy enforced from mid-October 2026. Browser extensions and tools that inject code into the sign-in page will stop working as the rollout completes in late October.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence70
Okta and 11 vendors including AWS, Google Cloud and CrowdStrike signed six shared principles for securing AI agents under a new Blueprint Alliance. Buyers can put the list to vendors in procurement now, while Okta's release describes a reference architecture with no stated way to test compliance.
Publishers:okta.com · scworld.com Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+35
- Incentives70
- Confidence55
Microsoft shipped 22 updates, six of them scored 10.0, mostly in Entra ID, Exchange Online and Azure. Fixed server-side is not the same as verified in your tenant.
Perspective Coverage
5 publishers
- Builder
- Builder 20%
- Operator
- Operator 65%
- Investor
- Investor 15%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+40
- Incentives55
- Confidence55
A ReliaQuest employee gave up a password and an MFA push five days after the company named the .claims campaign. Device trust, not training, kept the session worthless.
Perspective Coverage
5 publishers
- Builder
- Builder 29%
- Operator
- Operator 56%
- Investor
- Investor 15%
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+25
- Incentives70
- Confidence62
CVE-2026-18963 lets an unauthenticated request skip the emailed reset token entirely. Upstream 26.7.2 and four Red Hat errata are out, and the stopgap has to be set realm by realm.
Publishers:access.redhat.com · github.com · keycloak.org · thehackernews.com Perspective Coverage
4 publishers
- Builder
- Builder 43%
- Operator
- Operator 51%
- Investor
- Investor 6%
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap+8
- Incentives30
- Confidence72
According to SecurityWeek, every technique in the chain was ordinary and the detection stack correlated it correctly. The time was lost in escalation, the part of the playbook most teams still size for an intruder working at human speed.
Publishers:redwoodresearch.org · securityweek.com Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+25
- Incentives35
- Confidence55
The flag rate on US-based remote IT roles climbed from 11% in the third quarter of 2024 to an estimated 47%, which prices candidate verification into every application even as venture money for identity startups fell to $0.3bn in a quarter.
Reality
- Evidence35
- Adoption25
- Hype gap+45
- Incentives75
- Confidence40
Gartner surveyed 297 senior security leaders between March and May 2026 and found deepfaked video calls close behind at 36%. Its advice is to put a verification step in front of payment authorization, account recovery and privileged access.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives40
- Confidence60
Microsoft told admins on Friday that SMS first-factor sign-in retires from February 2027, and that its own SMS and voice delivery ends on February 1, so tenants that want to keep phone codes must buy telephony elsewhere.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap0
- Incentives35
- Confidence74
ShareGate surveyed nearly 1800 IT professionals across nine countries and found 77% had a Microsoft 365 governance incident last year, with full Copilot deployments doubling to 56% of organisations over the same period.
Reality
- Evidence38
- Adoption55
- Hype gap+30
- Incentives80
- Confidence45
Writing for the Forbes Technology Council, Proofpoint's Sumit uses three incidents since 2023 to argue that access control answers whether an action is allowed while agents need a check on whether it should happen at all.
Reality
- Evidence24
- Adoption
- Insufficient
- Hype gap+34
- Incentives82
- Confidence58
Earlier coverage
- Scoped identity with iam:PassRole could potentially run as prod-admin via a Lambda function it creates, if unblocked by policy controls
Security · September 23, 2026 · 1 publisher
- A rogue external MFA provider plants a fake Microsoft password prompt in Entra's login flow
Security · September 22, 2026 · 1 publisher
- Unauthenticated attackers can reset any Industrial Edge Management password without the email link
Security · September 22, 2026 · 1 publisher
- Okta puts an enforcement point between AI agents and the tools they call
Product · September 22, 2026 · 1 publisher
- Storing each domain and mailbox proof as a timestamped event lets an auditor replay a disputed join
Build · September 21, 2026 · 1 publisher
- Crossing $1M in revenue turns Duende's free IdentityServer tier into a $12,500 bill
Build · September 21, 2026 · 1 publisher
- Trail of Bits traces SAML's insecurity to the XML signature layer underlying most fielded implementations
Security · September 21, 2026 · 1 publisher
- Six agencies in five countries name the 17 most common Active Directory attacks
Security · September 21, 2026 · 1 publisher
- Microsoft folds Storm-2372 into Midnight Blizzard 17 months after first naming it
Leadership · September 20, 2026 · 1 publisher
- Revoking the stolen tokens left GhostCode's Intune device inside the tenant
Leadership · September 20, 2026 · 1 publisher
- Enterprise admins can revoke every SSO-authorized GitHub credential in one action
Security · September 20, 2026 · 1 publisher
- Hard-coded static key in SolarWinds Access Rights Manager hands unauthenticated attackers RCE
Security · September 19, 2026 · 1 publisher
- Restricting an agent to read-only views removes the runtime SQL construction it once had
Build · September 18, 2026 · 1 publisher
- A recovery-decision event can be written before the provider's own event id exists
Build · September 18, 2026 · 1 publisher
- NIST and CISA finalise token-protection guidance citing a single stolen signing key
Science · September 18, 2026 · 1 publisher
- Protected Resource Metadata lets an MCP client discover the sign-in flow behind a 401 -- but Entra can still block the token
Build · September 18, 2026 · 1 publisher
- A Ping-sponsored paper would tie every AI agent to a named human owner
Security · September 17, 2026 · 1 publisher
- AWS runs four JWT claim gates in one Lambda before an MCP tool call reaches its data
Build · September 17, 2026 · 1 publisher
- Handing an agent the user's session token gives it every permission the user has
Build · September 17, 2026 · 1 publisher
- Cisco Patches 44 CVEs Across ISE, FMC, Nexus Dashboard; Separately Warns of Exploited ISE Authentication Bypass Zero-Day
Security · September 17, 2026 · 1 publisher
- Every cross-account role in an AWS landing zone stops at the aws-eusc partition line
Build · September 16, 2026 · 1 publisher
- Google Cloud's security office says an agent ban pushes employees toward less secure automation
Leadership · September 14, 2026 · 1 publisher
- An external app with user consent reads mail without holding an account in the tenant
Build · September 13, 2026 · 1 publisher
- ELN ID promoted its de facto admin check after an audit found zero ServiceRole users
Build · September 13, 2026 · 1 publisher
- Cognito ships a new user pool with MFA off and its sign-in risk model disabled
Build · September 13, 2026 · 1 publisher
- Two of Ping's four AI agent classes act on a human's own login
Security · September 11, 2026 · 1 publisher
- IP Services' CEO would audit a security program by asking when it last restored from backup
Leadership · September 10, 2026 · 1 publisher
- Orchid ships drift detection and a kill switch for agents that inherit unmanaged identity
Security · September 10, 2026 · 2 publishers
- NIST traces the agent accountability gap to users handing over their own credentials
Science · September 10, 2026 · 1 publisher
- Cymphony raises $25M to put AI agents on the same permissions map as employees
Invest · September 10, 2026 · 1 publisher
- Noma's Workflow Identity Hijacking turns a service account into a privilege proxy for strangers
Build · September 9, 2026 · 1 publisher
- Patched, modern Active Directory setups largely mitigate FreeIPA's cross-realm PAC impersonation flaw, FreeIPA says
Security · September 9, 2026 · 1 publisher
- Scattered Spider talks help desks into moving MFA onto attacker-controlled devices
Security · September 9, 2026 · 1 publisher
- An unauthenticated LDAP client can write itself into FreeIPA's administrators group
Security · September 8, 2026 · 1 publisher
- Anonymisation trades away the property that made the test fixture useful
Build · September 8, 2026 · 1 publisher
- authentik checked the PKCE verifier only when the request bothered to include one
Build · September 5, 2026 · 1 publisher
- CNIL puts €500,000 on the control gaps behind a 727,113-record hospital breach
Security · September 3, 2026 · 1 publisher
- October moves NIS2 from transposition into enforcement across the EU
Security · August 31, 2026 · 1 publisher
- Three items, one tier: Keycloak's reset bug, an N-able password leak, a Grok data-theft trick
Security · August 26, 2026 · 1 publisher
- UDS Core's default operator authentication accepted any client secret for three release trains
Security · August 25, 2026 · 1 publisher