There probably wasn't an #Azure breach. Someone logged in.
Millions of #Entra directory records reportedly for sale. Infrastructure intact. The platform authenticated the wrong person.
Attackers rarely defeat #MFA. They get someone to complete it. hubs.la/Q04y6Tys0
Generative AI removed every signal phishing training taught employees to spot. Grammar. Formatting. Branding. Tone.
There is nothing obviously fake about the message anymore. Training people to recognize what AI made unrecognizable is not a strategy.
hubs.la/Q04y6Tkq0
MFA confirms someone completed the challenge. It cannot tell you it was the wrong person.
Domain-bound credentials. A live fingerprint on dedicated hardware. Keys that never leave the secure element.
How the Apollo attack worked: hubs.la/Q04xx1-l0
Firewalls, EDR, SIEM, threat intel all operate downstream of the login.
Once an attacker is recognized as an employee, your team inherits the harder job.
Why the Azure headlines are really an identity story: hubs.la/Q04xKypK0
Apollo wasn't hacked. Their own employees authenticated the attackers.
Attackers impersonated internal IT. Employees entered credentials on a fake login page, then approved the MFA prompt.
No exploit. No malware. Authentication was the attack. hubs.la/Q04xx1F90
Some IdPs accept assertions from credentials whose signature counter never advances. A copy signs alongside the original and nothing looks unusual.
What enterprises should require for privileged access:
hubs.la/Q04x4yrl0#IdentitySecurity
#AI agents can recommend, prepare, and execute routine work. Irreversible actions get approved by a human — trusted device, biometric verification. Email confirmations, basic pop-ups, and second agents don't clear that bar.
hubs.la/Q04xfYJ50
Your passkey is phishing-resistant. That does not mean you would know if it had been copied.
Most synced passkeys return a signature counter of zero. Zero cannot regress. There is nothing to compare.
Phishing resistance is not clone detection.
hubs.la/Q04x4xQW0
They never got inside. They didn't need to. A DDoS campaign has disrupted Norway's national identity gateway since 3:38am Monday. Kevin Surace, Token CEO: "Keeping people from getting in is enough." hubs.la/Q04vsdsJ0
~850,000 files leaked from one water-sector supplier. "Protecting the water utility itself is only half the problem," says @Token CEO Kevin Surace. CISA's ask is the least glamorous one: get OT off the public internet when it doesn't need to be there.
hubs.la/Q04vs02f0
They never got inside. They didn't need to.
A DDoS campaign has disrupted ID-porten, MinID and Altinn since Monday. No breach — just Norway locked out of its own government. Kevin Surace, Token CEO: "Keeping people from getting in is enough." hubs.la/Q04vsgJP0
CISA logged more than 100 internet-exposed water systems attacked in a single month.
Most were PLCs wired straight to a cellular modem. Reachable by anyone who knows where to look. Not a run of bad luck. A structural problem.
hubs.la/Q04vs2qS0
#MFA is not failing. It is doing exactly what it was designed to do. Prompt bombing. SIM swapping. AiTM proxies. Session theft. OAuth consent abuse.
None of them break #MFA. They go around it. Possession is not identity. hubs.la/Q04tJJBM0
Sept 1: Microsoft starts auto-enabling SMS and voice users for passkeys. Enrollment is where attackers are working.
Restrict by AAGUID. Enforce attestation. Require device-bound biometric hardware. Entra supports it today.
hubs.la/Q04t41pw0#BiometricAuthentication
A stolen password and an intercepted code do not authenticate an employee. They authenticate two pieces of compromised data.
Biometric match. Domain binding. Proximity. Keys in hardware.
Each #MFA bypass, and what closes it: hubs.la/Q04tJSQY0
Attackers aren't breaking passkeys. They're getting organizations to trust theirs. The pretext is the migration itself.
"This is IT. We need to finish your Microsoft passkey enrollment." The cryptography held. The enrollment ceremony did not.
hubs.la/Q04tlpQK0
Credential compromise is still the leading cause of enterprise breaches.
Not because the attacks got smarter. Because the credential never changed.
AI moved phishing to machine speed. The secret underneath still works the way it did a decade ago. hubs.la/Q04sylnB0
AI didn't invent a new way in. It used the old one at machine speed.
Exposed identity data. Predictable password variations. Authentication that automation can compromise at scale.
Bind access to a verified human who is physically present.
hubs.la/Q04t50Pb0
Taiwan confirmed an AI-assisted attack on government systems. Token CEO Kevin Surace, in SC Media: "near-autonomous rather than completely independent." Humans picked the targets and built the framework. The AI had real latitude inside the mission.
hubs.la/Q04t3--50
When an AI agent executes a high-consequence action, who approved it?
A credential cannot answer that. A verified person can.
Token: Gold, Identity Access Management, 2026 Cybersecurity Excellence Awards. hubs.la/Q04syl8C0