A customer logs into their account from a familiar device using the correct password and successfully completes multi-factor authentication (MFA). Minutes later, they change the account recovery phone number, add a new payout destination, and transfer funds. Did the customer authenticate successfully? Yes. Did the organization make the right access…
Most vishing defenses assume the attacker is after a password. The campaigns causing the most damage in 2026 rarely ask for one. Instead, they persuade a help desk representative to enroll a new phone number or convince a user to approve a connected application. The login that follows appears legitimate…
When an agentic AI agent acts on a user’s behalf, most current deployments run it with that user’s privileges and record its activity under the user’s identity. The agentic AI agent itself disappears into the session. That design choice creates the core challenge of governing agentic AI. Two distinct principals,…
Identity weaknesses played a material role in almost 90% of the 750-plus incidents Palo Alto Networks’ Unit 42 investigated in 2025, with 65% of initial access driven by identity-based attacks. This was not solely because those organizations lacked multi-factor authentication (MFA) or security training. Rather, attackers…
Large enterprises and government agencies now manage workforce identities across dozens of cloud services and for thousands of employees and third-party contractors who may never set foot in a physical office. This level of sprawl makes identity a critical factor in determining whether an organization’s broader security architecture is resilient…
Artificial intelligence has unleashed a new wave of threats for enterprise cybersecurity teams. This article explores how adaptive authentication – particularly risk-based, step-up authentication – provides an effective countermeasure to AI-driven fraud.
Regulators and enterprises are moving away from OTPs as a secure factor due to their weakness to SIM swaps, phishing and social engineering attacks. This article will explore why passkeys are now proliferating as an alternate second factor.
Passwords are still everywhere, despite being aa weak link. Passwordless authentication them with a private key or biometric stored only on the user’s device. Nothing reusable travels over the wire, so nothing reusable can be phished.Â
Age gates were once edge‑case plumbing; now they sit squarely in the path of revenue and reputational risk. The good news is that adaptive, policy‑driven workflows can convert what used to be a blunt, ineffective blocker into compliant, parent‑aware verification.
If a vendor’s credentials fall into the wrong hands, your network becomes an open door. Security professionals must manage third-party users with the same (or stricter) standards reserved for internal staff.Â