The Silent Collapse: How Broken Service Account Hygiene Is Enabling the Next Wave of Enterprise Breaches
An in-depth investigation into how 78% of Fortune 1000 companies still fail to rotate service account credentials.
The Definitive Chronicle of Identity & Access Management
BREACH: Major healthcare provider confirms 2.3M patient records exposed via misconfigured SCIM endpoint
CVE-2026-31847: Critical RCE in FortiAuthenticator - CVSS 9.8 - Patch immediately
BREACH: European fintech platform leaks OAuth tokens affecting 890K users
An in-depth investigation into how 78% of Fortune 1000 companies still fail to rotate service account credentials.
NIST's finalized post-quantum cryptography standards demand immediate action on certificate-based authentication systems.
Law enforcement sources reveal the sophisticated identity fabrication techniques that exploited gaps in federated identity verification.
Researchers say JadePuffer is the first documented ransomware operation run end-to-end by an automated agent — here's what that means for IAM defenses.
Many banks still make MFA optional for customers, and that gap is costing account holders. Here's what IAM practitioners can take from it.
A flaw in Leantime's verifyState() method means OIDC login CSRF is trivially exploitable — attackers can fix sessions and hijack accounts.
The Eventer WordPress plugin stores password reset keys in plaintext, enabling full account takeover when chained with a SQL injection flaw.
The new directive requires all Government of Canada systems to implement FIDO2-compliant authentication, phasing out SMS-based MFA.
Misconfigured SCIM provisioning endpoint exposed patient identity data.
Exposed refresh tokens allowed unauthorized access to customer financial accounts.
LDAP injection attack exposed 340K employee records including AD credentials.
Federated SAML assertion replay attack affected 45 university systems.
Automated attack compromised 120K accounts using previously breached credentials.
Unauthenticated remote code execution via crafted RADIUS authentication packet.
Token validation flaw allows authentication bypass in specific OIDC flow configurations.
XML External Entity injection in SAML metadata parser allows SSRF.
Custom policy XML injection allows privilege escalation in B2C tenants.
Session token not rotated after authentication in specific broker flows.
Join thousands of IAM professionals getting the weekly Intelligence Brief every Monday morning.