Identity Attacks
Campaigns, breaches and techniques aimed at credentials, enrolment and access. Analysis of how enterprise identity systems are actually attacked, for practitioners.
Three Black Hat papers broke passkey deployments. None of them broke passkeys.
Pass-the-Passkey, Pass-Ta-Key and a Windows Hello abuse technique all reached privileged access without ever touching a private key.
Entra ID makes passkeys the default. Attackers went for enrolment first.
Microsoft flips the default in September 2026. Okta has already documented a threat actor phoning users through a fake enrolment flow.
Microsoft maps three ShinyHunters paths into Salesforce
Vishing into a malicious connected app, stolen vendor OAuth tokens, and misconfigured guest access. No Salesforce flaw required.
Attackers are spoofing OAuth client IDs to test stolen Entra credentials
Hostile authentication made to look like traffic from a legitimate application, spread across fictional apps.
A new group called Helix is using vishing and MFA abuse to empty SharePoint
Vishing, device-code phishing and MFA abuse, then it registers its own authenticator app. The second story this fortnight to start that way.