Jun 23, 2026
•
4 min read
The attack that broke Microsoft's login doesn't need your password at all.
authentication
+3
Jun 16, 2026
Attackers aren't breaking in anymore. They're deleting the evidence that they were ever there.
defense evasion
+4
Jun 9, 2026
3 min read
CISA left government cloud keys in public GitHub. Microsoft shipped a debug flag to 3 billion phones. Meta's AI gave away Instagram accounts. Same week.
identity
+5
Jun 2, 2026
The forensics always leads back to the same place — an account that shouldn't have existed, with access it shouldn't have had. Here's what to fix before the 2 AM alert.
identity-security
+7
CISA left live AWS GovCloud credentials in a public repo named "Private." It sat there for six months. Nobody inside the agency noticed.
Credential Security
Convention files, prompt injection, and why the line between productivity tool and data pipeline just disappeared
Zero Trust
+6
You clicked "Add to Chrome" because it promised to make you faster. You actually installed a wiretap.
chrome-extensions
A self-spreading worm just ran through the tools developers use to build every app you touch. Here's what that means for you — and what to do about it.
AppSec
The Vercel breach wasn't a credential failure. It was a token problem — and your IAM program probably can't see it.
Oauth Security
Five vendors. Six weeks. The same architectural failure. Here's why agents keep shipping with godmode permissions — and what good actually looks like.
Least Privilege
The Agent Permission Paradox
Most enterprises are carrying identity debt they can't see. Here's what it looks like — and where to start paying it down.
identity-governance
+2
Practitioner intelligence on identity, AI agents, and enterprise trust.