#identitysecurity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #identitysecurity, aggregated by home.social.
-
Losing your phone is no longer just an annoyance.
Read the blog: https://marshsecurity.org/protecting-against-lost-stolen-mobile-microsoft-security/Losing your phone when it contains access to your email, Microsoft 365, MFA, corporate data, personal accounts, banking, photos and potentially your entire digital identity is a little more serious than "annoyance".
I’ve published a new post looking at what you can do to reduce the impact of a lost or stolen mobile device, both from a personal perspective and also within a business. This blog covers some of the practical protections available through Microsoft and modern device management, as well as the steps worth taking before a device disappears.
Because realistically, the best time to think about how you’d respond to a lost phone probably isn’t five minutes after realising it’s no longer in your pocket.
Read the blog: https://marshsecurity.org/protecting-against-lost-stolen-mobile-microsoft-security/
Tags:
#Microsoft #Security #Cyber #Tech #Technology #CyberSecurity #MicrosoftSecurity #MicrosoftIntune #Intune #Microsoft365 #EntraID #IdentitySecurity #MobileSecurity #InformationSecurity #DataProtection -
🎙️ On the Nexus Podcast, ClearVector Founder & CEO John Laliberte explores one of today's fastest-growing cybersecurity challenges: non-human identities (NHIs) and the role AI agents play in creating and managing machine identities across enterprise and critical infrastructure environments.
Learn why identity visibility, detection, and governance are essential for reducing cyber risk as AI adoption accelerates.
🎧 Listen to the full episode: https://nexusconnect.io/podcasts/nexus-podcast-john-laliberte-on-ai-and-non-human-identity-controls
#Cybersecurity #AI #IdentitySecurity #NonHumanIdentities #CriticalInfrastructure #MachineIdentity
-
Admin Console 17.10.2 builds upon features introduced in 17.9.0 and 17.10.0.
- Admins can configure approval workflows for AI-related request types introduced with the Agentic AI Governance feature for Keeper Endpoint Privilege Manager.
- Admins can directly view Non-Human Identity UIDs, including specific app UIDs for Keeper Secrets Manager devices.
- New event types for Advanced Reporting and Alerts Module include Revealed Password, Moved Folder, Updated Folder and Moved Record. -
🔐 Zero Trust needs more than authentication — it needs enforcement.
How can mTLS, JWT validation, identity-based routing, and Layer 7 micro-segmentation work together to make Zero Trust practical?
Our latest technical guide explores how to implement these principles directly at the application delivery layer with RELIANOID.
👉 Read the full technical guide and discover how to turn your ADC into a Zero Trust enforcement point.
-
If AI can imitate voices, generate realistic faces, automate phishing campaigns, and manipulate human trust, should boards continue measuring security maturity by MFA adoption alone?
Or is it time to redefine identity assurance as a strategic business capability rather than another cybersecurity control?
#Leadership #CyberSecurity #ArtificialIntelligence #IdentitySecurity #DigitalTrust
https://stayingalive.in/cataloguing-strategic-innov/biometric-assured-identity.html -
#TechnicalTalk
Adversary Village at @defcon 34!
Samet Can Tasci, Senior Linux Systems Engineer, and Mehmet Önder Key, Cyber Security Consultant, are speaking on “Emulating the Identity-First Threat Actor: Automated Playbooks for IdP Hijacking” on 8 Aug 2026 at DEF CON Creator Stage 3.
Adversary Village schedule:
https://adversaryvillage.org/adversary-events/DEFCON-34/
More info on the session and speakers: https://adversaryvillage.org/adversary-events/DEFCON-34/Samet-Can-Tasci
https://adversaryvillage.org/adversary-events/DEFCON-34/Mehmet-%C3%96nder-Key
#AdversaryVillage #DEFCON34
#TechnicalTalk #IdentitySecurity #ThreatActors #IdPHijacking
#RedTeam #AdversaryEmulation -
New by me: CybersecKyle Security How-To Series: Power User and Small Team, Part 1 - Account Inventory and Least Privilege
#Cybersecurity #InfoSec #IdentitySecurity #SmallBusiness #CybersecKyleHowTo
-
🔐 Zero Trust isn’t just about identity — it’s about where identity is enforced.
In hybrid and multi-cloud environments, security breaks when identity stops at login and doesn’t control traffic flow.
Our latest article explores why the application delivery layer is becoming the new Zero Trust enforcement point — and how identity-aware traffic control changes everything.
🔗 Read more 👇
https://www.relianoid.com/blog/zero-trust-in-hybrid-environments-why-identity-must-control-the-traffic-layer/#ZeroTrust #CyberSecurity #HybridCloud #IdentitySecurity #DevSecOps #RELIANOID
-
Hello #FediVerse
Do you use ID.me ? Please leave a comment if you have opinions, thoughts or concerns about their service. Thank you. -
🚨 New integration: Keeper Security and Wiz
Our new integration connects Wiz's cloud vulnerability discovery directly to KeeperPAM, automatically rotating compromised credentials and enforcing least privilege – across human users, machine identities, AI agents and database accounts – the moment a risk is found.
#KeeperSecurity #Wiz #CloudSecurity #PrivilegedAccessManagement #IdentitySecurity
-
New by me: Passkeys Are Better Than Passwords, but They Are Not a Silver Bullet
https://www.kylereddoch.me/blog/passkeys-are-better-than-passwords-but-they-are-not-a-silver-bullet/
-
SASE and Zero Trust set the stage for safer cloud work. What path will you take? #SASE #ZeroTrust #CIO #NetworkSecurity #CyberSecurity #CloudSecurity #EnterpriseIT #DigitalTrust #IdentitySecurity
https://www.linkedin.com/pulse/sase-zero-trust-networks-new-nerve-system-modern-cios-mohindroo--b7x0c -
🟦 Entra Tenant Governance | Find Configuration Drift
New preview lets admins detect tenant configuration drift natively across Entra and related services. 🔹
Define JSON baselines as configuration as code and create scheduled monitors. Monitors run every six hours and produce run summaries and detailed drift objects with property level diffs. Govern external tenants via B2B signals and role based templates from a single admin center. 💡
💡 Configuration as code baseline
🔍 Six hour monitor interval
⚖️ Cross tenant governance via B2B signals -
Shashwat Sehgal, CEO & Co-Founder of P0 Security, warns that AI agents are recreating the same access problems that broke early cloud security.
🔐 Broad standing permissions are returning
🔐 Visibility alone does not reduce blast radius
🔐 Runtime governance matters more than authentication“The organizations that avoid repeating the cloud security cycle will be the ones that treat agents as a new class of privileged non-human identity from day one.”
#Cybersecurity #AISecurity #IdentitySecurity #CloudSecurity #AIAgents
-
One government agency. 11 PAM platforms. That's not a security strategy—it's a liability.
@KeeperSecurity is making the case for consolidation, and it's compelling.
My RSAC 2026 Vendor Spotlight: https://paradigmtechnica.com/2026/05/21/rsac-2026-vendor-spotlight-keeper-security/ #PAM #IdentitySecurity
-
AI agents are scaling faster than enterprise identity controls can keep up with, says Alex Bovee, CEO & Co-Founder of C1.
⚡ Humans overapprove access
⚡ Manual IAM workflows cannot scale
⚡ AI agents require real-time governance“Companies need automated, policy-driven access controls that work in real time.”
Full discussion:
https://www.technadu.com/ai-scaling-is-outpacing-enterprise-identity-controls-why-companies-need-ai-level-monitoring/628021/ -
Identity security programs were built for human users - but AI agents, APIs, and service accounts are now expanding the attack surface at machine speed.
New insights from Keeper Security CEO Darren Guccione:
https://www.technadu.com/the-environment-has-changed-but-your-identity-security-still-hasnt/627850/ -
CyberArk + Palo Alto Networks launch Idira for AI-era identity security. 🔐
The platform focuses on securing human, machine & agentic identities with unified PAM and governance.
Is identity becoming the primary AI attack surface?
Follow @technadu for more.
-
📰 89% of IT Leaders Struggle with Identity Sprawl Amid AI Expansion: Report
New report from Keeper Security: 89% of IT leaders are struggling with identity sprawl, a problem accelerated by AI. 72% can't detect credential misuse in real-time, creating major security gaps. 🔑 #IdentitySecurity #AI #CyberSecurity
-
🚨 Most people think red teaming is about exploits.
It’s not.
The most effective attacks today don’t start with vulnerabilities —
they start with **trust**.Modern environments are cloud-heavy, identity-driven, and full of SaaS integrations. In these systems, attackers don’t always need to “break in.”
They move quietly through:
• Over-permissioned identities
• Weak approval workflows
• Misconfigured cloud roles
• OAuth tokens and API access
• Human behavior under pressure
• Business processes no one questionsThis is what I’ve been studying and calling the **Quiet Kill Chain** —
a sequence of legitimate-looking actions that, when chained together, become an attack path.No loud exploits.
No obvious malware.
Just normal activity… used the wrong way.## What changes at an advanced level?
You stop asking:
“What exploit should I use?”And start asking:
• Where does this system trust too easily?
• Which action would look completely normal?
• What would defenders ignore?
• How can I blend into business operations?Because the strongest intrusion today is not the one that is invisible.
It’s the one that looks **legitimate**.
## My takeaway
Offensive security is shifting from breaking systems
to understanding them deeply enough to move inside them unnoticed.I’ve written a full deep-dive on this concept here 👇
Curious to hear your thoughts —
Is detection today ready for this level of subtlety?#CyberSecurity #RedTeam #OffensiveSecurity #ThreatIntel #CloudSecurity #IdentitySecurity #EthicalHacking #BlackCipher
-
The next breach won’t start with malware. It’ll start with an AI agent
https://youtu.be/ATmE3VceSOA #Cybersecurity #ArtificialIntelligence #AIAgents #AgenticAI #AISecurity #EnterpriseSecurity #ZeroTrust #IdentitySecurity #AutomationRisk #DigitalTransformation #Infosec #CyberRisk