Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2618+ Articles
162+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
20 articles

#Identity Security

All CosmicBytez Labs articles tagged #Identity Security, across news, security advisories, how-to guides, and projects.

  • HOWTOAug 31, 2026

    Deploying Vaultwarden: A Self-Hosted Password Manager

    Stand up a lightweight, Bitwarden-compatible password vault on your own infrastructure — with Docker, TLS via reverse proxy, and an automated backup routine.

  • NewsAug 19, 2026

    Password Spraying Attacks Surge 155x as Hackers Exploit MFA Gaps

    Huntress reports a 155x surge in password spraying in H1 2026, with one campaign logging 81 million login attempts in two weeks via MFA and legacy auth gaps.

  • NewsAug 10, 2026

    When Credentials Are No Longer Enough: Device Trust in the AI Era

    AI is making phishing, credential theft, and MFA bypass faster and cheaper than ever. As traditional trust signals — passwords, MFA codes, IP geolocation — become routinely defeated, security teams must shift toward hardware-anchored device trust and continuous session evaluation to maintain meaningful access control.

  • NewsJul 28, 2026

    Cyera Acquiring Oasis Security in $1 Billion Deal

    Data security platform Cyera is acquiring Oasis Security, an agentic access management specialist, in a deal valued at approximately $1 billion. The acquisition combines Cyera's data security posture management capabilities with Oasis's non-human identity and agentic AI access controls.

  • NewsJul 24, 2026

    Seeing AI Agents Is Not Enough — Security Teams Must Enforce What They Can Do

    Visibility into AI agents is a starting point, not a security control. Security teams need to move from agent discovery to enforcement — defining...

  • NewsJul 22, 2026

    How Enterprise GenAI Can Amplify Ransomware Risk — and How to Contain It

    Enterprise AI assistants and agents that inherit excessive permissions or compromised identities create new ransomware attack paths. Identity controls,...

  • NewsJul 16, 2026

    Identity Attacks Overtake Exploits as Top Ransomware Cause

    Sophos 2026: 79% of ransomware attacks start with stolen identities. MFA was present in 97% of credential-based cases yet failed to stop every one of them.

  • NewsletterJul 14, 2026

    Weekly Digest #27 — Zero-Days Everywhere, Sanctions Escalate, and Your Browser Extension Just Betrayed You

    This week: Progress ShareFile and SonicWall hit with chained zero-days, the US sanctions its first VPN provider, ShinyHunters walks into Salesforce...

  • NewsJul 13, 2026

    Breach at the Beach: Play the Ultimate Entra ID CTF

    Varonis has launched Breach at the Beach, a free hands-on Capture the Flag competition designed to teach defenders how attackers abuse Microsoft Entra ID...

  • NewsJun 27, 2026

    Cisco Adds NHI to Security Stack With Astrix, WideField Acquisitions

    Cisco has acquired Astrix Security and WideField to build out non-human identity (NHI) protection capabilities, betting that securing AI agents, service...

  • NewsJun 18, 2026

    SailPoint to Acquire Entro in Reported $200 Million Deal

    SailPoint's acquisition of Israeli startup Entro adds non-human identity and secrets management to its IGA platform, addressing a critical gap as machine...

  • NewsMay 27, 2026

    Can You Enforce Strong Active Directory Password Rules Without Frustrating Users?

    Strong AD passwords don't have to mean frustrated users — passphrases, breached-password checks, and self-service resets balance security and usability.

  • NewsMay 11, 2026

    Why Changing Passwords Doesn't End an Active Directory

    Resetting compromised passwords is a natural first response to a breach, but it's not enough. Cached credentials, Kerberos ticket grants, and persistent...

  • NewsMay 2, 2026

    ConsentFix v3 Automates Azure OAuth Abuse With Mass

    A new iteration of the ConsentFix attack toolkit has surfaced on cybercriminal forums, adding automation and scaling capabilities to OAuth consent...

  • NewsApr 29, 2026

    Learning from the Vercel Breach: Shadow AI and OAuth Sprawl

    The Vercel breach, traced to a compromised third-party AI tool with OAuth access, illustrates how Shadow AI adoption and unchecked OAuth integrations are...

  • NewsApr 21, 2026

    No Exploit Needed: How Attackers Walk Through the Front

    Stolen credentials remain the dominant initial access vector in 2026 — no zero-days, no malware, just valid logins that blend in with normal activity...

  • NewsApr 11, 2026

    Your Next Breach Will Look Like Business as Usual

    Credential-based attacks now dominate the threat landscape, and traditional detection models are failing. Here are the fundamental shifts cybersecurity...

  • NewsApr 6, 2026

    Why Simple Breach Monitoring Is No Longer Enough

    Infostealers are harvesting credentials and session cookies at scale, quietly bypassing MFA and traditional defenses. Here's why organizations need...

  • NewsMar 31, 2026

    Stolen Logins Are Fueling Everything From Ransomware to Nation-State Cyberattacks

    A new report reveals how industrialized credential theft has become the common thread connecting ransomware campaigns, SaaS platform breaches, and...

  • NewsFeb 7, 2026

    CISA Mandates Full Zero Trust Architecture for Federal

    New CISA directive requires all federal civilian agencies to implement comprehensive zero trust security architecture by September 2027, setting a...