Skip to main content
Tag

Identity security

9 articles on identity security.

← All blog posts
MFA Fatigue: Stop Push-Bombing Attacks
Identity2026-08-24

MFA Fatigue: Stop Push-Bombing Attacks

Detect and prevent MFA fatigue with number matching, rate limits, risk signals, phishing-resistant authentication, and an identity incident playbook.

3 min read
Browser-in-the-Browser Phishing: Detection Guide
Phishing2026-08-24

Browser-in-the-Browser Phishing: Detection Guide

Understand browser-in-the-browser phishing, spot fake SSO windows, detect campaign infrastructure, and reduce risk with phishing-resistant authentication.

4 min read
The Kratos Phishing Kit Takedown: 200 Servers Gone, 1,800 Copies Still Out There
Phishing2026-08-08

The Kratos Phishing Kit Takedown: 200 Servers Gone, 1,800 Copies Still Out There

German and US law enforcement dismantled Kratos, the AiTM phishing service behind roughly 15,000 Microsoft 365 campaigns a month. The infrastructure is offline, but the kit is not. Here is what to hunt for now.

7 min read
SSO Vishing And SaaS Data Theft: Domain Monitoring Before The Helpdesk Call
Phishing2026-07-13

SSO Vishing And SaaS Data Theft: Domain Monitoring Before The Helpdesk Call

ShinyHunters-style SSO vishing shows how fake login domains, MFA enrollment abuse, and SaaS access can become data theft. Domain monitoring gives defenders early warning.

3 min read
AI-Enabled Device Code Phishing: How OAuth Tokens Became the New Credential Theft Target
Phishing2026-05-10

AI-Enabled Device Code Phishing: How OAuth Tokens Became the New Credential Theft Target

Device code phishing turns a legitimate OAuth flow into a token theft path. Learn how AI-assisted lures, Entra ID abuse, and session token replay change phishing detection in 2026.

10 min read
LLMjacking Explained: How Attackers Abuse Cloud Credentials to Steal AI Compute
Cloud2026-05-08

LLMjacking Explained: How Attackers Abuse Cloud Credentials to Steal AI Compute

LLMjacking combines cloud credential theft with expensive AI workloads. Learn how attackers find exposed keys, abuse model APIs, hide compute costs, and how defenders can detect the pattern.

10 min read
Non-Human Identity Security: API Keys, Service Accounts, and Workload Credentials in 2026
Identity2026-05-07

Non-Human Identity Security: API Keys, Service Accounts, and Workload Credentials in 2026

Non-human identities now outnumber users in most environments. Learn how API keys, service accounts, CI tokens, and workload credentials become attack paths and how to govern them.

10 min read
OAuth Consent Phishing: Detecting Malicious App Grants Before Data Exfiltration
Phishing2026-05-06

OAuth Consent Phishing: Detecting Malicious App Grants Before Data Exfiltration

OAuth consent phishing tricks users into granting access instead of giving up passwords. Learn how malicious app grants work, which permissions matter, and how to detect abuse early.

10 min read
Session Token Theft: Why Infostealers Bypass MFA and How Defenders Respond
Malware2026-05-05

Session Token Theft: Why Infostealers Bypass MFA and How Defenders Respond

Infostealers increasingly target browser cookies, session tokens, and refresh tokens. Learn why MFA is not enough, what token theft looks like, and how to detect replay.

10 min read