Skip to main content

The Identity at the Core

The Definitive Chronicle of Identity & Access Management

Breach: BREACH: Major healthcare provider confirms 2.3M patient records exposed via misconfigured SCIM endpointVulnerability: CVE-2026-31847: Critical RCE in FortiAuthenticator - CVSS 9.8 - Patch immediatelyBreach: BREACH: European fintech platform leaks OAuth tokens affecting 890K usersAdvisory: ADVISORY: CISA warns of active exploitation of SAML implementation flaws in enterprise SSO productsBreach: BREACH: Major healthcare provider confirms 2.3M patient records exposed via misconfigured SCIM endpointVulnerability: CVE-2026-31847: Critical RCE in FortiAuthenticator - CVSS 9.8 - Patch immediatelyBreach: BREACH: European fintech platform leaks OAuth tokens affecting 890K usersAdvisory: ADVISORY: CISA warns of active exploitation of SAML implementation flaws in enterprise SSO products

BREACH: Major healthcare provider confirms 2.3M patient records exposed via misconfigured SCIM endpoint

CVE-2026-31847: Critical RCE in FortiAuthenticator - CVSS 9.8 - Patch immediately

BREACH: European fintech platform leaks OAuth tokens affecting 890K users

[ FEATURED IMAGE ]
INVESTIGATION

The Silent Collapse: How Broken Service Account Hygiene Is Enabling the Next Wave of Enterprise Breaches

An in-depth investigation into how 78% of Fortune 1000 companies still fail to rotate service account credentials.

By Paulo Valadares12 min read
[ FEATURED IMAGE ]
ANALYSIS

Post-Quantum Identity: Why Your PKI Infrastructure Needs a Migration Plan Now

NIST's finalized post-quantum cryptography standards demand immediate action on certificate-based authentication systems.

By Paulo Valadares9 min read
[ FEATURED IMAGE ]
EXCLUSIVE

Inside the $340M Identity Fraud Ring: How Synthetic Identities Bypassed KYC at 12 Major Banks

Law enforcement sources reveal the sophisticated identity fabrication techniques that exploited gaps in federated identity verification.

By Paulo Valadares15 min read
🇨🇦

IAM in Canada

Regulation, innovation & incidents across the True North
[ FEATURED IMAGE ]
Federal Policy

Treasury Board Mandates Phishing-Resistant MFA Across All Federal Departments by Q4 2026

The new directive requires all Government of Canada systems to implement FIDO2-compliant authentication, phasing out SMS-based MFA.

Privacy

Bill C-27 AIDA Amendments Add Identity Verification Requirements for AI Systems

Yesterday
Provincial

Ontario Digital Identity Program Expands to Include Healthcare Provider Credentialing

2 days ago
Breach

Alberta Municipality Confirms Active Directory Compromise Affecting 45K Citizen Records

3 days ago
Industry

Canadian Banks Pilot Shared KYC Identity Network Using Verified Credentials

4 days ago
🚨 Oops... Another One
Live breach and vulnerability intelligence - updated as it happens
Breach Intelligence
● LIVE
CRITICAL
MedVault Health Systems - 2.3M Records

Misconfigured SCIM provisioning endpoint exposed patient identity data.

32m ago
CRITICAL
NordikPay - 890K OAuth Tokens Leaked

Exposed refresh tokens allowed unauthorized access to customer financial accounts.

2h ago
HIGH
TeleCom Asia - Employee Directory Breach

LDAP injection attack exposed 340K employee records including AD credentials.

4h ago
HIGH
EduConnect - Student SSO Compromise

Federated SAML assertion replay attack affected 45 university systems.

6h ago
MEDIUM
RetailMax - Loyalty Program Credential Stuffing

Automated attack compromised 120K accounts using previously breached credentials.

8h ago

Never Miss a Breach, CVE, or Industry Shift

Join thousands of IAM professionals getting the weekly Intelligence Brief every Monday morning.

How often
What to include