-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

Identity Security | Breaking Cybersecurity News | The Hacker News

Category — Identity Security
The AI Velocity Paradox: Why Security Is Decades Behind AI Ambition

The AI Velocity Paradox: Why Security Is Decades Behind AI Ambition

Oct 09, 2026 Identity Security / Artificial Intelligence
As enterprises race to deploy autonomous AI agents to accelerate business, a new report reveals they are tethered to security architectures built for a different era. The " Horizons of Identity Security " report from SailPoint highlights a critical “velocity paradox,” in which organizations invest in AI-speed business operations while continuing to rely on human-speed security controls, creating a structural failure that legacy approaches cannot solve. The data shows that while businesses have spent years maturing their identity programs for human employees, those same playbooks are fundamentally broken when applied to the ephemeral, autonomous, and rapidly multiplying world of non-human AI agents. A Market Stalled at the Starting Line Despite years of investment in identity and access management, the market's overall security maturity has hit a wall. According to the report, the center of gravity remains firmly planted in the foundational stages, with a combined 6...
Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

Oct 09, 2026 Vulnerability / Network Security
Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions. " CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial-of-service under specific configuration conditions," Citrix said. The vulnerability carries a CVSS score of 9.5 out of 10.0. There is no evidence that the issue has been exploited in the wild. Citrix has credited Michael Tucker, Chew Keong Tan, and Alex Bernier of the JPMorgan Chase XOR Team, along with Maxim Suhanov, for discovering and reporting the flaw. Successful exploitation hinges on the NetScaler deployments being configured as a SAML identity provider (IdP) or service provider (SP). Customers can determine if their instances meet the criteria by checking the configuration for entries like below - SAML SP: add authentication samlAction SAML IdP: ...
FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

Oct 08, 2026 Data Breach / Cyber Espionage
Hackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agencies in 6 other countries said on October 8. The company, Integrity Technology Group , has been sanctioned by the U.S. and the UK. The hackers scanned websites for flaws using a tool containing more than 1,300 scripts, guessed passwords for Microsoft 365 and Exchange accounts, and copied mailboxes using tools designed to collect mail. The hackers have been breaking into networks since at least mid-January 2021, according to the agencies'  joint advisory . It describes the hacking in the present tense but provides no date for any theft and does not specify how many organizations were breached. The same hackers targeted U.S. government services, critical manufacturing, healthcare, and IT organizations, along with U.S. law enforcement, education, and religious groups. Organizations ...
cyber security

New Priorities for Critical Infrastructure: A Nation-State Threat Roundtable

websiteSANSCritical Infrastructure / Cybersecurity
Experts from SANS Institute, FirstEnergy, MITRE and Dragos unpack what leaders should prioritize next.
cyber security

AI adoption is outpacing IT visibility

website1PasswordSaaS Security / AI Governance
Individual dashboards only show part of the story. Learn how IT can get a unified view of AI spend and usage.
Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

Oct 08, 2026 Web Security / Threat Intelligence
Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials. Attackers are increasingly building filtering, session management, and traffic controls into the infrastructure that delivers the phishing page itself. ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia. The campaign uses a multi-stage routing chain to screen visitors and automated traffic before delivering an Adobe-themed Device Code phishing page. For security teams, that makes Wazza more than another malicious URL. The campaign shows how attackers can control the path to the final lure, making the initial link less informative and potentially complicating automated detection. MSSPs face an added challenge, as they investigate alerts across multiple customer environments while keeping response times under control. That uncertainty can translate directly into longer in...
Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

Oct 06, 2026 Data Breach / Privacy
Unauthorized parties have gained access to the names, addresses, and personal identification numbers of about 8.8 million people, living and dead, in Denmark's national population register, the country's digitalization ministry  said on October 5 . They used a private Danish company's lawful right to look up records in the Central Person Register (CPR). The ministry has told people never to give passwords or other confidential information to anyone who calls or emails, even someone who seems to know those details. The register's administration has stopped the company's access and reported the case to Datatilsynet, Denmark's data protection authority. Police are investigating. A very large number of automated lookups were made in the register to identify valid personal identification numbers, known as CPR numbers, Datatilsynet  said in a notice  on October 5. Its account comes from the notification it received from the register a day earlier. It has not y...
⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests

⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests

Oct 05, 2026 Cybersecurity News / Hacking
A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook. There are actively exploited bugs in the mix, cleaner intrusion paths, smarter automation, and a long patch list waiting behind them. Some attacks are getting more capable. Others are still getting in because the basics gave way first. Here’s what mattered this week. ⚡ Threat of the Week Citrix Warns of Newly Exploited NetScaler ADC and Gateway Flaw — Citrix released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0. "CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific depl...
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing

China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing

Oct 04, 2026 Cyber Espionage / Phishing
A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a U.S. think tank in February 2026. The phishing email carried the subject line "Request for Feedback on Military Integration of Claude." "This activity likely supports wider Chinese intelligence objectives to better understand ongoing developments within the U.S. AI policy and regulatory landscape and occurs amid intense strategic competition, accusations of model distillation, and export controls involving the U.S. and China," Proofpoint said in an analysis published this week. The enterprise security company has described TA419 as a China-aligned and espionage-motivat...
The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations

The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations

Oct 03, 2026 Identity Security / Artificial Intelligence
Featuring: Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and internet-facing infrastructure, security is shifting toward continuous visibility, control, and the ability to respond to risk at scale. This report examines how core areas of cybersecurity are evolving in response to that shift. Across identity security, telemetry management, human security, endpoint management, human risk intelligence, exposure management, email and domain security, connected device security, AI-native security operations, and cloud security, it explores how organizations are adapting to threats that increasingly move across systems, identities, and infrastructure rather than targeting a single point of failure. Read the full report here:  https://report.papryon.com/thehackernews
Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report

Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report

Oct 02, 2026 Enterprise Security / Artificial Intelligence
The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spreadsheet to reconcile them. Someone else is turning that spreadsheet into slides. Then a board member asks three questions: How secure is the organization, overall? What is the actual financial exposure? Is the security posture better than it was last quarter? Most security leaders cannot answer any of them with confidence. Not because the data doesn't exist, but because it lives in a dozen tools that don't share context. A new guide to confident board reporting for CISOs takes on exactly this problem. This article walks through why traditional reporting fails and what a better model looks like. Boards Have Stopped Trusting Activity Metrics For years, security reporting has run on counts. Vulnerabilities found. Patches applied. Alerts closed. P...
Know Your Enemy: Browser-Based Attack Techniques in 2026

Know Your Enemy: Browser-Based Attack Techniques in 2026

Sep 30, 2026 Web Security / Phishing
Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browser session. Often, they never leave it, with the entire attack chain from initial access to exfiltration playing out in the browser. Here are the six most dangerous techniques that should be on every security team's radar in 2026. 1. Phishing for credentials and sessions Modern phishing kits don't just steal passwords — they intercept live sessions. Reverse-proxy adversary-in-the-middle (AiTM) kits like Tycoon2FA, Sneaky2FA, and Evilginx relay credentials and session tokens in real time, bypassing most forms of MFA. These kits are sold as turnkey Phishing-as-a-Service platforms with anti-bot protection, dynamic lure generation, and automated session replay — reducing the barrier to sophisticated phishing to effectively zero. At the same time, phishing delivery has moved well beyond email — attackers deliver link...
French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

Sep 29, 2026 Data Breach / Network Security
An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France's national cybersecurity agency saw the data leave. The attack was not sophisticated, the agency, ANSSI, says in a  report  (in French) published on Tuesday: it worked because of weak login protection, poorly separated networks and gaps in monitoring. The tax administration, known as the DGFIP, runs France's tax website, impots.gouv.fr. The data came from E-Contact, the tool taxpayers use to message the tax administration. The stolen data covers  a little over 350,000 individuals  and  a little over 250,000 businesses , the DGFIP says. Taxpayers' own online accounts and passwords were not compromised. For individuals, the data that may have been viewed or copied includes their tax ID, contact details, family situation, reference taxable income and tax...
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

Sep 29, 2026 Identity Security / Artificial Intelligence
A malicious MCP server could trick an application built on the official  MCP Python SDK  into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and 2.2.0. The Model Context Protocol (MCP) is an open standard for connecting AI applications to outside tools and data, and this package is its official Python SDK for building MCP servers and clients. With the stolen credentials, the attacker can request a valid access token from the real login service. Cycode, the security firm that reported the flaw , demonstrated that full exchange in a test and says the resulting token carries whatever permissions the app was granted. The client secret is long-lived, so it keeps working until it is changed. The flaw is rated high (7.5) for the two prov...
IAM for AI agents: A Practical Enterprise Framework

IAM for AI agents: A Practical Enterprise Framework

Sep 28, 2026 AI Agent Security / Enterprise Security
What is IAM for AI agents? AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identity-control architecture that governs those actors. This guide covers the limits of conventional provisioning, the components that matter, how to evaluate framework choices, and what runtime evidence proves an agent behaved as intended. Identity and access management (IAM) for AI agents treats each agent as a non-human identity with a human owner, a defined purpose, scoped authorization, an expiration, and continuous monitoring. The complication is architectural. IAM platforms express intended access, while applications and infrastructure reveal what the agent actually executed. Between the two sits identity dark matter: the agents, credentials, application-local accounts, and authentication paths that central identity data never reports. A framework that cannot observe that surface produces policy intent, not assurance. Wh...
⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

Sep 28, 2026 Cybersecurity News / Hacking
A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface. Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing exotic. Mostly things nobody expected to matter anymore. Here’s the full recap of what mattered this week. ⚡ Threat of the Week Citrix Warns of Actively Exploited NetScaler ADC and Gateway Flaws — Citrix released patches to address multiple vulnerabilities, including CVE-2026-88771 and CVE-2026-88772, that have come under active exploitation. CVE-2026-88771 is an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands, while successful exploitation of CVE-2026-88772 could allow for remote code execution or denial-of-service. CISA...
Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI

Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI

Sep 28, 2026 Identity Security / AI Agent Security
AI agents are moving into production faster than security teams can govern them. They are connecting to apps, handling data, calling APIs, and acting across business systems—often without the same controls applied to human users. According to Okta’s Global CISO Insights 2026 report, only 47% of CISOs are confident they can identify every AI agent in their environment. Even among those who feel confident about visibility, roughly 80% still worry that excessive access may be going unreviewed. That is the real problem: seeing an agent is not the same as controlling what it can do. Join Matt Immler , Regional CSO at Okta, for a practical session on how to bring AI agents under stronger identity governance before excessive access becomes harder to contain.
JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

Sep 28, 2026 Cloud Security / Identity Security
The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168 , has called it an evolution of the threat actor's tradecraft. The attack took place in early June 2026 over a period of about 18 hours. "The destructive operations were facilitated by compromising service principals and targeted Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, Virtual Machines, and App Services," researchers Yossi Weizman and Tushar Mudi, along with the Microsoft Security Research team, said . JADEPUFFER was first documented by Sysdig, describing it as the first-ever ransomware operation run end-to-end with the help of a large language model (LLM). The agentic attack exploited a known security flaw in Langflow (CVE-2025-3248) to break in, harvested credentials, burrowed deepe...
Zero Trust for AI Agents Starts With Fixing Zero Visibility

Zero Trust for AI Agents Starts With Fixing Zero Visibility

Sep 26, 2026 Artificial Intelligence / Cloud Security
Before an AI agent gets access to your environment, you should be able to answer a few basic questions. Who owns it? What is it allowed to do? What can it reach, and how will you know when it does something outside its assigned task? These are familiar questions in security architecture. Agents make them harder to answer because they can select tools, act on external content, and, in some deployments, delegate work to other agents. An attacker who hijacks an agent’s intent may be able to turn its legitimate access against you. The agent may still present valid credentials and call an expected API while acting outside its assigned task. Research from Veeam illustrates the visibility gap: 70% of organizations surveyed reported AI workflows interacting with sensitive corporate data without full oversight, and 67% reported that employees were creating autonomous workflows IT could not fully track. These workflows can acquire access to business systems before security teams know they...
Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore

Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore

Sep 24, 2026 Artificial Intelligence / Application Security
AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuardian’s 2026 State of Secrets Sprawl Report , commits identified as AI-assisted are leaking secrets at approximately twice the rate of human-written ones. Most of the fastest-growing categories of leaked credentials are now connected to AI services, meaning the tools meant to advance development are also accelerating the exposure of the keys development relies on. This isn’t a new vulnerability; what is new is AI changing the scale and pace at which those mistakes can happen. A coding agent can read an entire project, modify files, generate configurations and interact with external services in the time a developer might take to review a single pull request. The main issue isn’t that AI agents sometimes encounter secrets but that many of those secrets were never designed for an environment in which software can act autonomously. A...
TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

Sep 24, 2026 Cloud Security / Identity Security
Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses. "The campaign compromised 7 accounts – all of which were unmanaged functional or service accounts rather than individual employee accounts – highlighting a critical exposure gap around forgotten, non-human identities carrying default or unrotated passwords and no MFA [multi-factor authentication]," the enterprise security company said in a statement. The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events - July 21-24, targeting approximately 100–120 ...
A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

Sep 23, 2026 DevOps Security / Supply Chain
The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this address behind a button labeled "Email work item to this project." Mail sent to it opens an issue in that project, authored by you. The string in the middle of the address is a token tied to your account, and GitLab's documentation says it does not expire. The address looks like it belongs to one project. It does not.  Aikido Security , which reported the behavior, found that the addresses GitLab creates for a user's different projects all share the same token, and that the token applies to every project the account can open, public or private. GitLab does not check who sent the email. Any mailbox can write to the address, and GitLab acts on the message as if it came from you. Whoever holds...
⚡ Top Stories This Week
Expert Insights Articles Videos
Cybersecurity Resources