#1 Trusted Cybersecurity News Platform
Followed by 5.20+ million
The Hacker News Logo
Subscribe – Get Latest News

Credential Security | Breaking Cybersecurity News | The Hacker News

Category — Credential Security
The New Insider Has No Pulse: Securing Privilege When the Actor Is an AI Agent

The New Insider Has No Pulse: Securing Privilege When the Actor Is an AI Agent

Jul 20, 2026
When I work on an incident, the first question I ask is almost never "what malware ran." It's "whose credentials did it use, and what was that account allowed to touch." Nine times out of ten, the interesting part of the story isn't the exploit. It's the access. The exploit gets you in the door. The privilege is what lets you walk through the building. For thirty years, that question had a human-shaped answer. A person clicked something, a person got phished, a person reused a password, an admin left a service account sitting on a domain controller with a password from 2014. The identity at the center of the incident belonged to somebody with a badge and a manager. That assumption is quietly dying, and most enterprises have not adjusted their controls to match. The actor on your network is increasingly not a person at all. It is a workload, a script, a bot, an API (application programming interface) client, and now an AI agent that can reason, plan...
The Most Monitored Device in the Company is Still Hiding Dangerous Access

The Most Monitored Device in the Company is Still Hiding Dangerous Access

Jul 20, 2026
Attackers prefer the path of least resistance. Why break in when you can log in? That is what makes working credentials so valuable. A leaked password, token, or API key does more than reveal sensitive data; it offers a way in. No vulnerability or privilege escalation chain necessary. If the credential is valid, the attacker can simply use it, and the session will look like ordinary activity. This shifts the questions from "where can attackers break in?" to "where do usable keys tend to accumulate? Increasingly, the answer is the developer laptop: one of the most instrumented machines most companies own, and one of the easiest places for credentials to go unnoticed. The endpoint is watched for malware, behavior, posture, and configuration. But a valid plaintext credential is something else: a door an attacker may not need to force. A fully patched fleet can still have usable keys scattered across its devices, enough to turn one foothold into something much larger....
How to "Go Passwordless" Without Getting Rid of Passwords

How to "Go Passwordless" Without Getting Rid of Passwords

Jul 21, 2025 Passwordless / SaaS Security
With every credential breach that hits the news, CISOs and security professionals continually reach the same conclusion: passwords are insecure, and we should abandon them in favor of less risky authentication factors. But, secure or not, passwords are stubborn. The 2025 Verizon DBIR rated the likelihood of this being the year we finally eliminate passwords as being on par with "this being the year of the Linux desktop."  Any IT or security pro who has had to explain passkeys to their coworkers can tell you that 2025 isn't going to be the year we do away with passwords. Frankly, that year's not likely to come any time soon. Even if it were technically feasible (it often isn't) to transition every single login at a company to passkeys or biometrics, that would take years of concentrated effort. In the meantime, security leaders can't afford to sit on their hands and ignore the credential risks currently facing their company.  We need a new approach to thinking about secur...
Cybersecurity Resources