Microsoft warns attackers are using passkey and MFA update requests to phish employees, hijack sessions, and access Microsoft 365 data.
MFA is essential, but it cannot replace OAuth governance, least-privilege scopes, consent monitoring, and rapid revocation.
Research traces cloud compromises to fake passkey setup requests that trick users into authorizing attacker access and ...
A new phishing kit abuses a legitimate Microsoft device authorization flow intended for use with printers or smart TVs to steal authentication tokens, register attacker-controlled devices and gain ...
CVE-2026-69843 — a CVSS 10.0 unauthenticated bypass by spoofing — joins four other Microsoft authentication flaws since September 1, extending the identity-layer attack surface from the control plane ...
Sentire uncovers the GhostCode phishing kit abusing Microsoft OAuth to steal tokens, register attacker devices and access ...
Machine Identity Isolation policies can reject valid credentials unless controllers meet the Server 2025 functional level ...
Problems with updates for Windows 11 users continue, and while Microsoft is able to release fixes for many of them, this is ...
Barracuda researchers have published an analysis of an email attack campaign that replaces the traditional phishing website with a phishing page generated directly inside the victim’s browser using ...
State laws are forcing Microsoft to bake age verification into Windows 11. Here's how your government ID and facial scans ...
Apache 2.0 release separates agent governance from agent logic for the first time at framework scale — identity, guardrails, and observability become an infrastructure layer, not a developer burden.
The 10 best SSPM tools of 2026 scored on app coverage, misconfig detection, and SaaS identity — plus the CrowdStrike acquisition that reshaped the market.