Identity Briefing.
Identity AttacksAI & Agent IdentityAuthenticationStandards & RegulationVendor MovesCommunity & Events
community & events · The lead

Four takeaways from the New York Identity Summit

Thirty per cent of enterprise applications never reach the IDP, only half the room could prove who has access to what, and session timeouts are quietly doing more damage than step-up prompts.

Read the analysis

This fortnight

All briefings →
identity attacks

Three Black Hat papers broke passkey deployments. None of them broke passkeys.

Pass-the-Passkey, Pass-Ta-Key and a Windows Hello abuse technique all reached privileged access without ever touching a private key.

standards & regulation

The new MCP specification makes agent tool calls something you can actually govern

Stateless requests, the method and tool name exposed in HTTP headers, and a tighter OAuth story. MCP is moving from convenient to controllable.

vendor moves

Cyera is paying about $1 billion for Oasis, betting identity and data are one problem

A data security company buying a non-human identity company is a wager that "who is accessing this" and "how sensitive is it" stop being separate questions.

vendor moves

Saviynt's Zuma moves agent access decisions to runtime

Standing entitlements answer whether an agent can reach Salesforce. Saviynt's pitch is that the question worth answering is what the agent is trying to do right now.

community & events

Identity podcasts, roundtables and events for the rest of 2026

Identiverse interviews still landing, two NHI roundtables this month, and the two events worth the diary space before the year closes.

vendor moves

Okta buys Permiso and keeps walking towards the SOC

The ITDR acquisition brings identity risk signals and behavioural analytics in-house, and Okta is explicit that the destination is the security operations centre.

Between issues

Identity Threat Radar

CISA’s Known Exploited Vulnerabilities catalogue, reorganised around identity failure modes and annotated with exploitation likelihood and the Briefing’s notes on each entry. What broke, not how loud the CVSS score is.

Catalogue updated 26 Aug 2026

The full radar →

Pre-authentication bypass
CVE-2026-72529Top 27% for exploitation likelihood
TrueConf · Server

TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via…

CISA: Apply mitigations in accordance with vendor instructions. Federal deadline 23 Aug 2026.

CVE-2026-65400Top 5% for exploitation likelihood
Apple · macOS

Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid…

CISA: Apply mitigations in accordance with vendor instructions. Federal deadline 21 Aug 2026.

CVE-2026-18556Top 10% for exploitation likelihood
N-able · N-central

N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

The original N-central bypass, added to KEV a day after its successor. RMM platforms are the auth boundary for every customer downstream of them.

CISA: Apply mitigations in accordance with vendor instructions. Federal deadline 7 Aug 2026.

CVE-2026-18577Top 7% for exploitation likelihood
N-able · N-central

N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This…

Pre-auth and internet-facing by default. The story is that this is the second patch. 18556 didn't hold.

CISA: Apply mitigations in accordance with vendor instructions. Federal deadline 6 Aug 2026.

Federation and SSO trust
CVE-2026-55040Top 8% for exploitation likelihood
Microsoft · SharePoint

Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.

CISA: Apply mitigations in accordance with vendor instructions. Federal deadline 21 Aug 2026.

Credential exposure and recovery
CVE-2026-20316Top 5% for exploitation likelihood
Cisco · Secure Firewall Management Center (FMC)

Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could…

A hard-coded password in the console that manages your firewalls. No exploit chain required, just a login nobody could rotate or disable.

CISA: Apply mitigations in accordance with vendor instructions. Federal deadline 1 Aug 2026.

Get Identity Briefing

Independent analysis for identity practitioners. Fortnightly and free.

Join identity architects, IAM leads and security leaders worldwide.