Identity & Access
80 материалов
- Linx Security Raises $50 Million for Identity Security and Governance
Cybersecurity Funding · Identity & Access
The company will accelerate product development, scale go-to-market efforts, and expand its global footprint. The post Linx Security Raises $50 Million for Identity Security and Governance appeared first on SecurityWeek.
- Webinar Today: Agentic AI vs. Identity’s Last Mile Problem
Identity & Access · Artificial Intelligence
Join the webcast as we explore what Agentic AI can and cannot solve today, and real world breach scenarios linked to disconnected applications. The post Webinar Today: Agentic AI vs. Identity’s Last Mile Problem appeared first on SecurityWeek.
- Stolen Logins Are Fueling Everything From Ransomware to Nation-State Cyberattacks
Identity & Access · Cybercrime
Report shows how industrialized credential theft underpins ransomware, SaaS breaches, and geopolitical attacks, shifting security focus from prevention to detecting misuse of legitimate access. The post Stolen Logins Are Fueling Everything From Ransomware to Nation-State Cyberattacks appeared first on SecurityWeek.
- Silent Drift: How LLMs Are Quietly Breaking Organizational Access Control
Identity & Access · Artificial Intelligence
LLMs can write complex Rego and Cedar code in seconds, but a single missing condition or hallucinated attribute can quietly dismantle your organization’s least-privilege security model. The post Silent Drift: How LLMs Are Quietly Breaking Organizational Access Control appeared first on SecurityWeek.
- AI Speeds Attacks, But Identity Remains Cybersecurity’s Weakest Link
Identity & Access · Artificial Intelligence
PwC finds AI is amplifying speed and scale of attacks, as identity theft evolves into a cybercriminal supply chain. The post AI Speeds Attacks, But Identity Remains Cybersecurity’s Weakest Link appeared first on SecurityWeek.
- Shadow AI Risk: How SaaS Apps Are Quietly Enabling Massive Breaches
Identity & Access · Artificial Intelligence
From Chaos to Control examines the chaos that often comes from shadow AI hidden in SaaS apps and urges better visibility and control over agentic AI. The post Shadow AI Risk: How SaaS Apps Are Quietly Enabling Massive Breaches appeared first on SecurityWeek.
- SIM Swaps Expose a Critical Flaw in Identity Security
Mobile & Wireless · Identity & Access
SIM swap attacks exploit misplaced trust in phone numbers and human processes to bypass authentication controls and seize high-value accounts. The post SIM Swaps Expose a Critical Flaw in Identity Security appeared first on SecurityWeek.
- Venice Security Emerges From Stealth With $33M Funding for Privileged Access Management
Cybersecurity Funding · Identity & Access
Formerly named Valkyrie, the company’s funding includes $25 million raised in a Series A round. The post Venice Security Emerges From Stealth With $33M Funding for Privileged Access Management appeared first on SecurityWeek.
- Webinar Today: Identity Under Attack – Strengthen Your Identity Defenses
Identity & Access
Gain practical insights on balancing security, user experience, and operational efficiency while staying ahead of increasingly sophisticated threats. The post Webinar Today: Identity Under Attack – Strengthen Your Identity Defenses appeared first on SecurityWeek.
- GitGuardian Raises $50 Million for Secrets and Non-Human Identity Security
Cybersecurity Funding · Identity & Access
The secrets security company has raised more than $100 million since its creation in 2017. The post GitGuardian Raises $50 Million for Secrets and Non-Human Identity Security appeared first on SecurityWeek.
- Microsoft Moves Closer to Disabling NTLM
Identity & Access
The next major Windows Server and Windows releases will have the deprecated authentication protocol disabled by default. The post Microsoft Moves Closer to Disabling NTLM appeared first on SecurityWeek.
- Why Identity Security Must Move Beyond MFA
Identity & Access
By integrating identity threat detection with MFA, organizations can protect sensitive data, maintain operational continuity, and reduce risk exposure. The post Why Identity Security Must Move Beyond MFA appeared first on SecurityWeek.
- Analysis of 6 Billion Passwords Shows Stagnant User Behavior
Identity & Access
The most common stolen passwords in 2025 were 123456, admin, and password, according to a Specops study. The post Analysis of 6 Billion Passwords Shows Stagnant User Behavior appeared first on SecurityWeek.
- Five Cybersecurity Predictions for 2026: Identity, AI, and the Collapse of Perimeter Thinking
Identity & Access · Artificial Intelligence
The perimeter is gone. Credentials are no longer sufficient. And security can no longer rely on static controls in a dynamic threat environment. The post Five Cybersecurity Predictions for 2026: Identity, AI, and the Collapse of Perimeter Thinking appeared first on SecurityWeek.
- Identity Security Firm Saviynt Raises $700 Million at $3 Billion Valuation
Identity & Access · Cybersecurity Funding
The funding round was led by KKR, with participation from Sixth Street Growth, TenEleven, and Carrick Capital Partners. The post Identity Security Firm Saviynt Raises $700 Million at $3 Billion Valuation appeared first on SecurityWeek.
- ServiceNow to Acquire Identity Security Firm Veza in Reported $1 Billion Deal
M&A Tracker · Identity & Access
Veza Security was recently valued at more than $800 million after raising $108 million in Series D funding. The post ServiceNow to Acquire Identity Security Firm Veza in Reported $1 Billion Deal appeared first on SecurityWeek.
- Saporo Raises $8 Million for Identity Security Platform
Identity & Access · Cybersecurity Funding
The Swiss cybersecurity firm will scale its R&D, sales and marketing teams as it pursues expansion across Europe. The post Saporo Raises $8 Million for Identity Security Platform appeared first on SecurityWeek.
- Facial Recognition’s Trust Problem
Identity & Access
Two technologies — one for public safety, one for controlled entry — show why trust in facial recognition must be earned, not assumed. The post Facial Recognition’s Trust Problem appeared first on SecurityWeek.
- Opti Raises $20 Million for Identity Security Platform
Identity & Access · Cybersecurity Funding
The cybersecurity startup plans to use the seed funding to accelerate product expansion and global growth. The post Opti Raises $20 Million for Identity Security Platform appeared first on SecurityWeek.
- AI Is Supercharging Phishing: Here’s How to Fight Back
Identity & Access
AI has given cybercriminals the ability to operate like Fortune‑500‑scale marketing departments—except their product is account takeover, data theft, and identity fraud. The post AI Is Supercharging Phishing: Here’s How to Fight Back appeared first on SecurityWeek.
- Apono Raises $34 Million for Cloud Identity Management Platform
Identity & Access · Cybersecurity Funding
The company will use the investment to accelerate product development, expand go-to-market operations, and hire new talent. The post Apono Raises $34 Million for Cloud Identity Management Platform appeared first on SecurityWeek.
- ConductorOne Raises $79 Million in Series B Funding
Identity & Access · Cybersecurity Funding
Leveraging AI, ConductorOne’s platform secures and manages millions of human, non-human, and AI identities. The post ConductorOne Raises $79 Million in Series B Funding appeared first on SecurityWeek.
- Defakto Raises $30 Million for Non-Human IAM Platform
Identity & Access · Cybersecurity Funding
Defakto’s Series B funding, which brings the total raised to $50 million, was led by XYZ Venture Capital. The post Defakto Raises $30 Million for Non-Human IAM Platform appeared first on SecurityWeek.
- Descope Raises $35 Million in Seed Round Extension
Identity & Access · Cybersecurity Funding
The identity and access management provider will invest in agentic identity R&D, expand to new regions, and hire new talent. The post Descope Raises $35 Million in Seed Round Extension appeared first on SecurityWeek.
- Hush Security Emerges Stealth to Eliminate Credential Threats With No-Secrets Platform
Identity & Access · Cybersecurity Funding
Tel Aviv–based startup replaces vaults and secrets managers with just-in-time policies, aiming to eliminate credentials entirely. The post Hush Security Emerges Stealth to Eliminate Credential Threats With No-Secrets Platform appeared first on SecurityWeek.
- Amazon Disrupts Russian Hacking Campaign Targeting Microsoft Users
Identity & Access · Cloud Security
The Midnight Blizzard cyberspies used compromised websites to trick users into authorizing devices they controlled. The post Amazon Disrupts Russian Hacking Campaign Targeting Microsoft Users appeared first on SecurityWeek.
- Passkey Login Bypassed via WebAuthn Process Manipulation
Identity & Access
Researchers at enterprise browser security firm SquareX showed how an attacker can impersonate a user and bypass passkey security. The post Passkey Login Bypassed via WebAuthn Process Manipulation appeared first on SecurityWeek.
- 1Kosmos Raises $57 Million for Identity Verification and Authentication Platform
Identity & Access · Cybersecurity Funding
1Kosmos has raised $57 million in Series B funding, which brings the total raised by the company to $72 million. The post 1Kosmos Raises $57 Million for Identity Verification and Authentication Platform appeared first on SecurityWeek.
- PLoB: A Behavioral Fingerprinting Framework to Hunt for Malicious Logins
Identity & Access · Incident Response
Splunk researchers developed a system to fingerprint post-logon behavior, using AI to find subtle signals of intrusion. The post PLoB: A Behavioral Fingerprinting Framework to Hunt for Malicious Logins appeared first on SecurityWeek.
- Who’s Really Behind the Mask? Combatting Identity Fraud
Identity & Access · Fraud & Identity Theft
Why context, behavioral baselines, and multi-source visibility are the new pillars of identity security in a world where credentials alone no longer cut it. The post Who’s Really Behind the Mask? Combatting Identity Fraud appeared first on SecurityWeek.
- Palo Alto Networks to Acquire CyberArk for $25 Billion
Identity & Access
Strategic acquisitions marks Palo Alto Networks' formal entry into the identity security space and accelerates its platform strategy. The post Palo Alto Networks to Acquire CyberArk for $25 Billion appeared first on SecurityWeek.
- Thousands of SaaS Apps Could Still Be Susceptible to nOAuth
Identity & Access · Application Security
New research suggests more than 10,000 SaaS apps could remain vulnerable to a nOAuth variant despite the basic issue being disclosed in June 2023. The post Thousands of SaaS Apps Could Still Be Susceptible to nOAuth appeared first on SecurityWeek.
- Identity Is the New Perimeter: Why Proofing and Verification Are Business Imperatives
Identity & Access
The future of secure digital engagement depends on continuous identity verification and proofing that can scale with risk. The post Identity Is the New Perimeter: Why Proofing and Verification Are Business Imperatives appeared first on SecurityWeek.
- Russian Hackers Bypass Gmail MFA With App-Specific Password Ruse
Nation-State · Identity & Access
Russian hackers posed as US State Department staff and convinced targets to generate and give up Google app-specific passwords. The post Russian Hackers Bypass Gmail MFA With App-Specific Password Ruse appeared first on SecurityWeek.
- Misconfigured HMIs Expose US Water Systems to Anyone With a Browser
Identity & Access · ICS/OT
Censys researchers follow some clues and find hundreds of control-room dashboards for US water utilities on the public internet. The post Misconfigured HMIs Expose US Water Systems to Anyone With a Browser appeared first on SecurityWeek.
- Cerby Raises $40 Million for Identity Automation Platform
Identity & Access
Identity security automation platform Cerby has raised $40 million in Series B funding to scale operations. The post Cerby Raises $40 Million for Identity Automation Platform appeared first on SecurityWeek.
- Akamai, Microsoft Disagree on Severity of Unpatched ‘BadSuccessor’ Flaw
Identity & Access · Vulnerabilities
Akamai documents a privilege escalation flaw in Windows Server 2025 after Redmond declines to ship an immediate patch. The post Akamai, Microsoft Disagree on Severity of Unpatched ‘BadSuccessor’ Flaw appeared first on SecurityWeek.
- Microsoft Accounts Go Passwordless by Default
Identity & Access
Microsoft is prioritizing passwordless sign-in and sign-up methods, and is making new accounts passwordless by default. The post Microsoft Accounts Go Passwordless by Default appeared first on SecurityWeek.
- Veza Banks $108 Million Series D at $808 Million Valuation
Identity & Access · Cloud Security
San Francisco identity security play Veza closes a Series D fund round led by New Enterprise Associates (NEA). The post Veza Banks $108 Million Series D at $808 Million Valuation appeared first on SecurityWeek.
- Push Security Raises $30 Million in Series B Funding
Identity & Access · Cybersecurity Funding
Push Security has raised $30 million in Series B funding to scale its browser-based identity security platform. The post Push Security Raises $30 Million in Series B Funding appeared first on SecurityWeek.
- AuthMind Raises $19.3 Million in Seed Funding
Identity & Access · Cybersecurity Funding
Identity protection startup AuthMind has announced raising $19.3 million in a seed funding round led by Cheyenne Ventures. The post AuthMind Raises $19.3 Million in Seed Funding appeared first on SecurityWeek.
- CISA Issues Guidance After Oracle Cloud Hack
Identity & Access
CISA is making recommendations for organizations and users in light of the recent Oracle legacy cloud environment hack. The post CISA Issues Guidance After Oracle Cloud Hack appeared first on SecurityWeek.
- Internet Giants Agree to Reduce TLS Certificate Lifespan to 47 Days by 2029
Identity & Access
Major companies have agreed to gradually reduce the lifetime of TLS certificates over the next few years. The post Internet Giants Agree to Reduce TLS Certificate Lifespan to 47 Days by 2029 appeared first on SecurityWeek.
- Corsha Raises $18 Million to Enhance and Extend Machine-to-Machine Security
Identity & Access · Cybersecurity Funding
The new funds will be used to extend Corsha’s reach into critical infrastructure and further improve its own use of AI. The post Corsha Raises $18 Million to Enhance and Extend Machine-to-Machine Security appeared first on SecurityWeek.
- Island Banks $250M in Series E Funding for Enterprise Browser
Identity & Access
The late-stage startup said the round was led Coatue Management and brings Island’s total external funding to approximately $730 million. The post Island Banks $250M in Series E Funding for Enterprise Browser appeared first on SecurityWeek.
- Microsoft Adds AI Agents to Security Copilot
Identity & Access · Artificial Intelligence
Microsoft has expanded the capabilities of Security Copilot with AI agents tackling data security, phishing, and identity management. The post Microsoft Adds AI Agents to Security Copilot appeared first on SecurityWeek.
- SpecterOps Scores $75M Series B to Scale BloodHound Enterprise Platform
Identity & Access
SpecterOps has raised an unusually large $75 million Series B funding round to accelerate the growth of its BloodHound Enterprise platform. The post SpecterOps Scores $75M Series B to Scale BloodHound Enterprise Platform appeared first on SecurityWeek.
- Jamf to Acquire Identity Automation for $215 Million
M&A Tracker · Identity & Access
Apple device management firm Jamf has entered into an agreement to acquire IAM platform Identity Automation. The post Jamf to Acquire Identity Automation for $215 Million appeared first on SecurityWeek.
- SailPoint IPO Signals Bright Spot for Cybersecurity
Identity & Access
In a signal move for the cybersecurity sector, identity and access management (IAM) vendor SailPoint has made its return to public markets. The post SailPoint IPO Signals Bright Spot for Cybersecurity appeared first on SecurityWeek.
- SGNL Raises $30 Million for Identity Management Solution
Identity & Access · Cybersecurity Funding
Identity management provider SGNL has raised $30 million in a Series A funding round led by Brightmind Partners. The post SGNL Raises $30 Million for Identity Management Solution appeared first on SecurityWeek.
- CyberArk Expands Identity Security Play With $165M Acquisition of Zilla Security
M&A Tracker · Identity & Access
CyberArk acquires early stage Boston startup Zilla Security for $165M, expanding its identity security and IGA capabilities. The post CyberArk Expands Identity Security Play With $165M Acquisition of Zilla Security appeared first on SecurityWeek.
- Clutch Security Raises $20 Million for Non-Human Identity Protection Platform
Identity & Access · Cybersecurity Funding
Clutch Security has raised $20 million in a Series A funding round led by SignalFire to secure non-human identities. The post Clutch Security Raises $20 Million for Non-Human Identity Protection Platform appeared first on SecurityWeek.
- Seraphic Attracts $29M Investment to Chase Enterprise Browser Business
Identity & Access
Seraphic Security banks $29 million investment as VCs remain bullish on startups with security-themed browsers for corporate defenders. The post Seraphic Attracts $29M Investment to Chase Enterprise Browser Business appeared first on SecurityWeek.
- SimpleHelp Remote Access Software Exploited in Attacks
Identity & Access · Vulnerabilities
Threat actors have been exploiting SimpleHelp remote access software shortly after the disclosure of three vulnerabilities. The post SimpleHelp Remote Access Software Exploited in Attacks appeared first on SecurityWeek.
- Cyber Insights 2025: Identities
Identity & Access
Both human and machine identities occupy a unique position: they are simultaneously the foundation of cybersecurity and its weakest link. The post Cyber Insights 2025: Identities appeared first on SecurityWeek.
- Orchid Security Banks Hefty $36M Seed Round
Identity & Access · Artificial Intelligence
New York identity management startup raises $36 million in an unusually large seed round co-led by Team8 and Intel Capital. The post Orchid Security Banks Hefty $36M Seed Round appeared first on SecurityWeek.
- Microsoft MFA Bypassed via AuthQuake Attack
Identity & Access
Oasis Security has disclosed AuthQuake, a method for bypassing Microsoft MFA within an hour without user interaction. The post Microsoft MFA Bypassed via AuthQuake Attack appeared first on SecurityWeek.
- Astrix Security Banks $45M Series B to Secure Non-Human Identities
Identity & Access
Tel Aviv company building software to secure non-human identities banks a $45 million funding round led by Menlo Ventures. The post Astrix Security Banks $45M Series B to Secure Non-Human Identities appeared first on SecurityWeek.
- Microsoft Rolls Out Default NTLM Relay Attack Mitigations
Identity & Access
Microsoft has rolled out new default security protections that mitigate NTLM relaying attacks across on-premises Exchange, AD CS, and LDAP services. The post Microsoft Rolls Out Default NTLM Relay Attack Mitigations appeared first on SecurityWeek.
- Google Cloud Rolling Out Mandatory MFA for All Users
Identity & Access · Cloud Security
Starting this month, Google Cloud will be rolling out mandatory MFA for all users who sign in with a password. The post Google Cloud Rolling Out Mandatory MFA for All Users appeared first on SecurityWeek.
- Passkey News: FIDO Unveils New Specifications, Amazon Announces 175 Million Users
Identity & Access
FIDO Alliance has published new specifications for securely moving passkeys across providers, as Amazon announced 175 million passkey users. The post Passkey News: FIDO Unveils New Specifications, Amazon Announces 175 Million Users appeared first on SecurityWeek.
- MFA Isn’t Failing, But It’s Not Succeeding: Why a Trusted Security Tool Still Falls Short
Identity & Access
Multi-factor authentication is a necessary safeguard, but its limitations show why organizations can't rely on it alone to prevent breaches. The post MFA Isn’t Failing, But It’s Not Succeeding: Why a Trusted Security Tool Still Falls Short appeared first on SecurityWeek.
- Cracking the Cloud: The Persistent Threat of Credential-Based Attacks
Identity & Access · Cloud Security
Credentials are still the most common entry point for bad actors, even as businesses deploy multi-factor authentication (MFA) to strengthen defenses. The post Cracking the Cloud: The Persistent Threat of Credential-Based Attacks appeared first on SecurityWeek.
- Worldcoin: Fighting Deepfakes and Bots With Global Permissionless Blockchain Identity
Identity & Access · Artificial Intelligence
That dream of a decentralized privacy-retaining identity system able to combat AI-driven bots and deepfakes may not be as elusive as feared – courtesy of Tools for Humanity (TfH) and Worldcoin. The post Worldcoin: Fighting Deepfakes and Bots With Global Permissionless Blockchain Identity appeared first on SecurityWeek.
- Five Eyes Agencies Release Guidance on Detecting Active Directory Intrusions
Identity & Access
Five Eyes cybersecurity agencies have released joint guidance on identifying Active Directory compromises. The post Five Eyes Agencies Release Guidance on Detecting Active Directory Intrusions appeared first on SecurityWeek.
- Google Now Syncing Passkeys Across Desktop, Android Devices
Identity & Access
Users can now save passkeys to Google Password Manager on computers running Windows, macOS, and Linux, in addition to Android devices. The post Google Now Syncing Passkeys Across Desktop, Android Devices appeared first on SecurityWeek.
- Hydden Raises $4.4M in Seed Funding for Identity Security Platform
Identity & Access · Cybersecurity Funding
Hydden has raised $4.4 million in seed funding for a solution designed to provide deep visibility into identities, accounts and privileges. The post Hydden Raises $4.4M in Seed Funding for Identity Security Platform appeared first on SecurityWeek.
- Non-Human IAM Provider Aembit Raises $25 Million
Identity & Access · Cybersecurity Funding
Aembit has raised $25 million in Series A funding to protect non-human identities and minimize attack surface. The post Non-Human IAM Provider Aembit Raises $25 Million appeared first on SecurityWeek.
- Crypto Vulnerability Allows Cloning of YubiKey Security Keys
Identity & Access
YubiKey security keys can be cloned via a side-channel attack that leverages a vulnerability in a cryptographic library. The post Crypto Vulnerability Allows Cloning of YubiKey Security Keys appeared first on SecurityWeek.
- Critical Authentication Flaw Haunts GitHub Enterprise Server
Identity & Access · Vulnerabilities
GitHub patches a trio of security defects in the GitHub Enterprise Server product and recommends urgent patching for corporate users. The post Critical Authentication Flaw Haunts GitHub Enterprise Server appeared first on SecurityWeek.
- Microsoft Announces Mandatory MFA for Azure
Identity & Access · Cloud Security
Microsoft is implementing automatic enforcement of multi-factor authentication (MFA) for all Azure users starting October. The post Microsoft Announces Mandatory MFA for Azure appeared first on SecurityWeek.
- Reframing the ZTNA vs. SASE Debate
Identity & Access · Network Security
While ZTNA can be deployed independently, it is an integral component of the SASE architecture as well. The post Reframing the ZTNA vs. SASE Debate appeared first on SecurityWeek.
- Stolen Credentials Have Turned SaaS Apps Into Attackers’ Playgrounds
Identity & Access
SaaS app log analysis highlights the rapid smash and grab raid: in, steal, and leave in 30 minutes. The post Stolen Credentials Have Turned SaaS Apps Into Attackers’ Playgrounds appeared first on SecurityWeek.
- IAM for MSPs Provider Evo Security Raises $6 Million
Identity & Access
TechOperators leads a $6 million Series A funding round for Evo Security, a provider of IAM solutions for MSPs. The post IAM for MSPs Provider Evo Security Raises $6 Million appeared first on SecurityWeek.
- Linx Security Raises $33M to Tackle Digital Identity Threats
Identity & Access
New York startup with roots in Israel banks a hefty $33 million early stage funding round. The post Linx Security Raises $33M to Tackle Digital Identity Threats appeared first on SecurityWeek.
- Okta Announces SaaS Startup Competition
Identity & Access · Cybersecurity Funding
The Okta SaaS Startup Competition will allow early-stage startups a chance to receive a cash investment and support from Okta. The post Okta Announces SaaS Startup Competition appeared first on SecurityWeek.
- Millions Impacted by Breach at Advance Auto Parts Linked to Snowflake Incident
Identity & Access · Data Breaches
Advance Auto Parts says the personal information of 2.3 million was compromised after hackers accessed its Snowflake account. The post Millions Impacted by Breach at Advance Auto Parts Linked to Snowflake Incident appeared first on SecurityWeek.
- BlastRADIUS Attack Exposes Critical Flaw in 30-Year-Old RADIUS Protocol
Identity & Access · Network Security
Security vendor InkBridge Networks calls urgent attention to the discovery of a decades-old design flaw (CVE-2024-3596) in the popular RADIUS protocol. The post BlastRADIUS Attack Exposes Critical Flaw in 30-Year-Old RADIUS Protocol appeared first on SecurityWeek.
- AuthZed Raises $12 Million for Permissions Management Technology
Identity & Access
Permissions management technology startup AuthZed has raised $12 million in a Series A funding round led by General Catalyst. The post AuthZed Raises $12 Million for Permissions Management Technology appeared first on SecurityWeek.
- Access Management Startup Pomerium Raises $13.75 Million
Cybersecurity Funding · Identity & Access
Pomerium raises $13.75 million in Series A funding for dynamic user identity verification and access management platform. The post Access Management Startup Pomerium Raises $13.75 Million appeared first on SecurityWeek.
