ISC2 domain 5

Identity and Access Management

Who gets in: sign-in, multi-factor, tokens, credential phishing and account takeover.

News

96 articles in this subject area

Records are being pulled from Salesforce and ServiceNow portals that need no login

Reco is tracking an ongoing campaign it calls City-Forum, in which a single tool written in Go pulls records from customer portals in Salesforce Experience Cloud and ServiceNow. All the traffic comes from one server that has been standing since March 2025, and the targets include telecoms, banks, software vendors and public sector portals.

Contractor jailed for two years after trying to extort the company that hired him

A former contract data analyst has been sentenced to two years in prison for attempting to extort 2.5 million dollars in cryptocurrency from an international technology company. Prosecutors state that he sent more than 60 emails under the alias Loot after his contract was not renewed.

A fake donation app steals the logged in Telegram session

On 13 August 2026 Kaspersky described an espionage campaign it attributes to the Armored Likho group, in which an app posing as a donation service is in reality a dropper. The Still Toolkit steals Telegram session data and pulls out conversations, while a separate module listens for speech and records audio.

Attackers picked up the SharePoint exploit code the day after it was published

On 11 August 2026 Rapid7 published a technical analysis of CVE-2026-55040 in Microsoft SharePoint, together with code showing how the flaw is exploited. Defused states on X that attackers were using that same code against its SharePoint honeypots the following day.

How an email with no script at all can steal your password

PortSwigger shows that style rules in an email can break out of the message and reach into the webmail interface. The attacks hit Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail and AOL Mail, and need no script at all.

A flaw in Metabase gave administrator access without a sign-in

Metabase confirmed on 6 August that a vulnerability in version 58 and later is being exploited in attacks. An unauthenticated attacker can inject SQL into Metabase's own application database through the password reset endpoint, and from there gain administrator access.

How attackers reached a Polish power plant through a shared mobile network

CERT Polska published a follow-up report on 8 August covering the 29 December 2025 attacks on Poland's energy supply. It describes an attack on a heat and power plant serving around 50,000 residents, where the way in ran through the grid operator's private mobile network.

Voicemail lures slip past MFA and hunt for payroll payouts

Arctic Wolf has uncovered a widespread phishing campaign against Microsoft 365 accounts in Europe, Canada and the US. The attackers take over the session after MFA is completed, hunting specifically for payroll, HR and finance.

The voice on the phone was not the boss, and the funds were all called the same day

Bloomberg reported on 5 August 2026 that several of Wall Street's largest funds faced attempted attacks using voice phishing, where AI-generated voices impersonate known people over the phone. Two Sigma states the attempt was stopped, Point72 states an initial review found no client data stolen, and no confirmed breaches have been reported.

The AI notetaker let strangers into the meetings, and no one had to break in

Security researcher BobDaHacker reports that AI notetaker tl;dv lacked separation between customers in its database, so any signed-in user could pull meeting data from across the platform. Dark Reading wrote on 4 August 2026 that the exposure was still active, six months after the vendor was first notified.

CrashStealer poses as Apple crash reporting and empties the Keychain on Mac

Kaspersky has described CrashStealer, a macOS information stealer delivered through a fake videoconferencing installer. The installer is both signed and notarized, and the malware asks the user for the password in a dialog that looks like a system message from Apple.

Unit 42 shows how synced passkeys can be taken from a compromised device

Unit 42 has described three attacks against synced passkeys in Google Password Manager, as used in Chrome on Windows machines with a TPM. The cryptography behind passkeys is not broken, but the attacks show what becomes possible once the machine is already compromised.

Two arrested in Pakistan over development of the Tycoon2FA phishing platform

Two people suspected of developing the phishing platform Tycoon2FA have been arrested in Pakistan following cooperation between the Singapore Police Force, INTERPOL and Pakistani authorities. The platform is said to be linked to more than 96,000 victims globally, and several of the cases in Singapore involved business accounts compromised despite multi-factor authentication.

Greatness expands its toolkit for getting past multi-factor authentication

ZeroBEC has analysed the phishing service Greatness, which has grown from credential harvesting into a broader platform. The service combines adversary in the middle, device code phishing and OAuth abuse to obtain authentication tokens.

N-able N-central flaw exploited to take control of an entire network

Sophos has described an attack in which CVE-2026-18577 was exploited to take privileged control of an N-central server. The attackers then used its remote control features to reach domain controllers, backup servers and application servers.

Midnight Blizzard hijacks hotel Wi-Fi and steals logins from travellers

Microsoft published details of the CaptiveCrunch campaign on 31 July 2026, in which the actor Midnight Blizzard hijacks hotel wireless networks and redirects travellers to content the attacker controls. The activity has been observed since early May 2026, and the goal is malware, passwords and Microsoft 365 access tokens.

Critical flaw in Ruflo gave command execution through an open MCP bridge

Noma Labs published CVE-2026-59726 on 29 July 2026, a vulnerability scoring 10.0 in Ruflo, a platform for orchestrating AI agents. In the default setup the MCP bridge listened on port 3001 across all interfaces without authentication, exposing 233 tools including shell execution. The flaw is fixed in version 3.16.3.

Broadcom fixes authentication bypass and code execution in VMware vCenter

Broadcom published advisory VMSA-2026-0006 on 29 July 2026, fixing five vulnerabilities in VMware vCenter, ESX, Workstation and Fusion. Two of them score 9.8, and a third lets an attacker escape from a virtual machine.

Static account in Cisco Secure FMC actively exploited

On 29 July 2026 CISA added CVE-2026-20316 to its catalog of known exploited vulnerabilities. The vulnerability is a static user account in the web interface of Cisco Secure Firewall Management Center, and Cisco states that it is being actively exploited.

Updated , first published

Identity security in 2026: attackers sign in

Omdia expects AI agents in core systems, and attackers sign in rather than break in. We walk through the numbers from Verizon, Microsoft and IBM, and four real incidents that show how identity attacks work.

Three identity moves for security leaders in the age of AI

AI agents act as digital employees with access of their own, writes John Zhao at ISACA. He recommends behaviour-based authentication, governing the agent economy and measuring zero trust maturity.

Phishing is moving from email into Teams

Microsoft blocked 7.6 billion email phishing threats in Q2 while malicious voice calls in Teams reached nearly ten times mid-2025 levels.

Critical Zoom flaw allows account takeover

CVE-2026-53412 in Zoom Workplace for Windows can let an unauthenticated attacker take over an account with no user interaction.

A look inside three Microsoft 365 phishing operations

Lexfo gained visibility into three Microsoft 365 phishing operations via an open directory; 94 percent of victims were corporate mailboxes.