Identity Decoded

Practitioner intelligence on identity, AI agents, and enterprise trust.

LATEST ISSUES


Your AI Code Reviewer Just Approved Malware It Never Saw

Your AI Code Reviewer Just Approved Malware It Never Saw

A hidden comment in a pull request is all it takes to hijack the AI gatekeeper your team trusts to ship safe code

Zero Trust

+6

The Email That Convinced Your AI You're Allergic to Penicillin

The Email That Convinced Your AI You're Allergic to Penicillin

One email is all it takes to plant a permanent lie in your AI assistant's memory — and there's no patch coming, because it isn't a bug.

identity-security

+6

The 3-Minute Security Audit Every Developer Should Run Before AI Touches Their Code

The 3-Minute Security Audit Every Developer Should Run Before AI Touches Their Code

Symlink attacks, hallucinated packages, and prompt injection are turning your AI pair programmer into an attacker's easiest way in

NHI

+6

You Just Gave Microsoft Permission to Let Strangers Into Your Account. It Took Three Seconds

You Just Gave Microsoft Permission to Let Strangers Into Your Account. It Took Three Seconds

ConsentFix and ClickFix attacks are turning OAuth consent prompts into skeleton keys — no password theft, no MFA bypass required. Here's how they work and what to revoke today.

Microsoft 365

+6

Nobody Is Talking About AI Agent Skills Yet. They Will Be

Nobody Is Talking About AI Agent Skills Yet. They Will Be

Malicious code is now delivered as helpful app features — and 26,000 AI agents just installed one.

third-party integrations

+3

Your Password Is Safe. You're Still Getting Hacked

Your Password Is Safe. You're Still Getting Hacked

The attack that broke Microsoft's login doesn't need your password at all.

authentication

+3