Four takeaways from the New York Identity Summit
Thirty per cent of enterprise applications never reach the IDP, only half the room could prove who has access to what, and session timeouts are quietly doing more damage than step-up prompts.
This fortnight
All briefings →Three Black Hat papers broke passkey deployments. None of them broke passkeys.
Pass-the-Passkey, Pass-Ta-Key and a Windows Hello abuse technique all reached privileged access without ever touching a private key.
The new MCP specification makes agent tool calls something you can actually govern
Stateless requests, the method and tool name exposed in HTTP headers, and a tighter OAuth story. MCP is moving from convenient to controllable.
Cyera is paying about $1 billion for Oasis, betting identity and data are one problem
A data security company buying a non-human identity company is a wager that "who is accessing this" and "how sensitive is it" stop being separate questions.
Saviynt's Zuma moves agent access decisions to runtime
Standing entitlements answer whether an agent can reach Salesforce. Saviynt's pitch is that the question worth answering is what the agent is trying to do right now.
Identity podcasts, roundtables and events for the rest of 2026
Identiverse interviews still landing, two NHI roundtables this month, and the two events worth the diary space before the year closes.
Okta buys Permiso and keeps walking towards the SOC
The ITDR acquisition brings identity risk signals and behavioural analytics in-house, and Okta is explicit that the destination is the security operations centre.
Identity Threat Radar
CISA’s Known Exploited Vulnerabilities catalogue, reorganised around identity failure modes and annotated with exploitation likelihood and the Briefing’s notes on each entry. What broke, not how loud the CVSS score is.
Catalogue updated 26 Aug 2026
TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via…
CISA: Apply mitigations in accordance with vendor instructions. Federal deadline 23 Aug 2026.
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid…
CISA: Apply mitigations in accordance with vendor instructions. Federal deadline 21 Aug 2026.
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
The original N-central bypass, added to KEV a day after its successor. RMM platforms are the auth boundary for every customer downstream of them.
CISA: Apply mitigations in accordance with vendor instructions. Federal deadline 7 Aug 2026.
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This…
Pre-auth and internet-facing by default. The story is that this is the second patch. 18556 didn't hold.
CISA: Apply mitigations in accordance with vendor instructions. Federal deadline 6 Aug 2026.
Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.
CISA: Apply mitigations in accordance with vendor instructions. Federal deadline 21 Aug 2026.
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could…
A hard-coded password in the console that manages your firewalls. No exploit chain required, just a login nobody could rotate or disable.
CISA: Apply mitigations in accordance with vendor instructions. Federal deadline 1 Aug 2026.