Skip to main content
Vol. I · No. 1

The Identity at the Core

The Definitive Chronicle of Identity & Access Management

Breach: BREACH: Major healthcare provider confirms 2.3M patient records exposed via misconfigured SCIM endpointVulnerability: CVE-2026-31847: Critical RCE in FortiAuthenticator — CVSS 9.8 — Patch immediatelyBreach: BREACH: European fintech platform leaks OAuth tokens affecting 890K usersAdvisory: ADVISORY: CISA warns of active exploitation of SAML implementation flaws in enterprise SSO productsBreach: BREACH: Major healthcare provider confirms 2.3M patient records exposed via misconfigured SCIM endpointVulnerability: CVE-2026-31847: Critical RCE in FortiAuthenticator — CVSS 9.8 — Patch immediatelyBreach: BREACH: European fintech platform leaks OAuth tokens affecting 890K usersAdvisory: ADVISORY: CISA warns of active exploitation of SAML implementation flaws in enterprise SSO products

BREACH: Major healthcare provider confirms 2.3M patient records exposed via misconfigured SCIM endpoint

CVE-2026-31847: Critical RCE in FortiAuthenticator — CVSS 9.8 — Patch immediately

BREACH: European fintech platform leaks OAuth tokens affecting 890K users

Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows
THE HACKER NEWS

Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows

The anonymous security researcher going by the name Chaotic Eclipse (aka Nightmare-Eclipse) has released a proof-of-concept (PoC) exploit for yet another Microsoft Defender zero-day named RoguePlanet. "The exploit is a race condition, so it's a hit or miss," the researcher, who published the exploit under a new GitHub account, "MSNightmare" said. "I have managed to get a 100% success rate on

By The Hacker News
[ IMAGE ]
PAM

Palo Alto rebrands CyberArk as Idira — what PAM customers should do

The $25B acquisition closed in February. On May 12 Palo Alto announced Idira. Here is what changes for the operators who actually run CyberArk in production.

[ IMAGE ]
CIAM

Passkeys are everywhere, and almost nobody is using them

Nearly half of the top 100 consumer sites now support passkeys. Real adoption stalls at 5–10%. The fixes are not technical — they are CIAM design fixes.

[ IMAGE ]
AI

Your IAM platform is not ready for AI agents

Every vendor announcement in 2026 mentions AI agents. Almost none explain how an agent authenticates, gets scoped credentials, and gets audited. Here is what the gap looks like.

[ IMAGE ]
COMPLIANCE

SOC 2 Type II Auditors Now Require Continuous Identity Posture Assessment

The audit landscape shifts from point-in-time reviews to evidence of ongoing access governance.

🇨🇦

IAM in Canada

Regulation, innovation & incidents across the True North
[ FEATURED IMAGE ]
Federal Policy

Treasury Board Mandates Phishing-Resistant MFA Across All Federal Departments by Q4 2026

The new directive requires all Government of Canada systems to implement FIDO2-compliant authentication, phasing out SMS-based MFA.

Privacy

Bill C-27 AIDA Amendments Add Identity Verification Requirements for AI Systems

Yesterday
Provincial

Ontario Digital Identity Program Expands to Include Healthcare Provider Credentialing

2 days ago
Breach

Alberta Municipality Confirms Active Directory Compromise Affecting 45K Citizen Records

3 days ago
Industry

Canadian Banks Pilot Shared KYC Identity Network Using Verified Credentials

4 days ago
🚨 Oops... Another One
Live breach and vulnerability intelligence — updated as it happens
Breach Intelligence
● LIVE
CRITICAL
MedVault Health Systems — 2.3M Records

Misconfigured SCIM provisioning endpoint exposed patient identity data.

32m ago
CRITICAL
NordikPay — 890K OAuth Tokens Leaked

Exposed refresh tokens allowed unauthorized access to customer financial accounts.

2h ago
HIGH
TeleCom Asia — Employee Directory Breach

LDAP injection attack exposed 340K employee records including AD credentials.

4h ago
HIGH
EduConnect — Student SSO Compromise

Federated SAML assertion replay attack affected 45 university systems.

6h ago
MEDIUM
RetailMax — Loyalty Program Credential Stuffing

Automated attack compromised 120K accounts using previously breached credentials.

8h ago

Never Miss a Breach, CVE, or Industry Shift

Join thousands of IAM professionals getting the weekly Intelligence Brief every Monday morning.

How often
What to include