Topic: credential hygiene
-
AI Agents Cause 76% Surge in NHIs, Revealing Governance Gaps
A 2026 survey finds a rapid increase in non-human identities (NHIs), like AI agents and API keys, with 76% of organizations reporting a significant expansion of their digital attack surface. The rise of autonomous AI agents, used by 74% of organizations, introduces a potent new risk due to their ...
Read More » -
Prioritize Security, Not Just Access, for Field Workers
Modern mobile workforce security requires individual accounts with mandatory multifactor authentication (MFA), moving beyond outdated shared credentials to protect sensitive data from sophisticated threats. Implementing the principle of least privilege through role-based access and streamlined re...
Read More » -
MFA Bypass Leads to Major Infostealer Attack on 50 Firms
A major data breach affecting around 50 global companies was enabled by the lack of multi-factor authentication (MFA), allowing an attacker to use stolen credentials for cloud file-sharing platforms. The attacker, using credentials harvested by infostealer malware, accessed accounts where passwor...
Read More » -
Hackers Ditch Encryption, Focus on Data Theft and Extortion
Cybercriminals are increasingly shifting from ransomware to "encryptionless" extortion, stealing and threatening to release data without locking files, which bypasses traditional defenses. The primary attack methods involve exploiting unpatched software vulnerabilities and supply chain weaknesses...
Read More » -
Kraken Ransomware Evolves With Advanced Benchmarking
In August 2025, the Kraken ransomware group emerged as a sophisticated threat, using SMB vulnerabilities for initial access, Cloudflare for persistence, and SSHFS for data exfiltration before deploying cross-platform malware. Kraken's ransomware features an advanced benchmarking process to optimi...
Read More » -
Why Password Changes Fail to Stop Active Directory Breaches
A password reset in Active Directory or hybrid Entra ID environments does not instantly invalidate old credentials across all authentication paths, leaving a window for attackers to exploit. Attackers exploit this gap using techniques like pass-the-hash on cached credentials, active Kerberos tick...
Read More »