IAM / Zero Trust
IAM / ZERO TRUST
LogoKit Phishing Kit Screenshots Victim Sites in Real Time
LogoKit now builds per-victim phishing pages using live screenshots of the target's real website...
IAM / ZERO TRUST
Device Code Phishing Up 1,500% in 2026; Vishing Doubles
Newer social engineering techniques help attackers ignore entrenched security controls and limit the evidence they leave behind....
IAM / ZERO TRUST
Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages
Check Point researchers detail phishing attack as an example of attackers dropping fake Microsoft login pages in favor of abusing...
IAM / ZERO TRUST
AiTM Phishing Becomes Top Initial Access Threat to Law Firms
AiTM phishing is now the top entry point into law firms, with identity behind 56% of threats...
IAM / ZERO TRUST
Why Resetting Passwords No Longer Stops Attackers
As attackers shift from password theft to session and token theft to bypass multifactor authentication controls, organizations must move beyond...
IAM / ZERO TRUST
Thousands of Data Center Controllers Open to Takeover
A host of Internet-exposed remote hardware management processors are subject to offline password-cracking attacks — and adversaries have taken note....
IAM / ZERO TRUST
USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports
The organization behind Team USA's Olympic/Paralympic fencing teams has automated identity verification to handle growing membership, cutting manual review time...
IAM / ZERO TRUST
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved...
IAM / ZERO TRUST
Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
Dormant nonhuman identities can create security blind spots, says security researcher Aleksandr Krasnov, who plans to release an open source...
IAM / ZERO TRUST
Hugging Face Hack: Lessons for Cyber Defenders
Dark Reading Confidential Episode 20: Expert Rich Mogull reflects on lessons cyber teams should pull from the OpenAI agent's attack...