Skip to content
HiveSecurity
  • Home
  • Blog
  • Tags
  • Vulnerabilities
    • Tools
    • Cheat Sheet
    • Security Guides
  • Contact
  • About
Esc
Type to search...
  • Home
  • Blog
  • Tags
  • Vulnerabilities
  • Resources
  • Tools
  • Cheat Sheet
  • Security Guides
  • Contact
  • About
← All tags Tag

Identity Security

14 articles

Week 37 Security Priorities: Revoke Trust Before You Chase Malware

Berlin's published data, exploited SonicWall gateways, a Chrome zero-day, AI-accelerated intrusion, payment-system abuse, and PostGREShell all point to the same task: identify and revoke inherited trust.

13 September 2026
Weekly Roundup Threat Intelligence Vulnerability Management

BREEZE COMET Did Not Steal Card Numbers. It Manipulated the Payment System

Google and Mandiant say BREEZE COMET compromises the identities, certificates, applications, and networks authorized to move money through Brazil's payment systems.

11 September 2026
Threat Intelligence Financial Security Identity Security

AI Compressed an Enterprise Intrusion Into Ten Hours. Speed Was the Weapon

Unit 42 reports that a human attacker used AI agents to move from an exposed API to cloud, identity, source code, secrets, and CI/CD control in under ten hours. The evidence shows acceleration, not a magical new exploit.

10 September 2026
AI Security Incident Response Cloud Security

Rhysida Published Berlin's Stolen Data. The Incident Is Only Starting

Berlin's stolen government data has been released after an extortion deadline expired. The next phase is credential rotation, exposure analysis, victim notification, and long-term fraud monitoring.

7 September 2026
Data Breach Incident Response Ransomware

153M Driver's License Scans for Sale: ID Verification Became the Breach Surface

KrebsOnSecurity reports that the FBI is investigating a dark web service selling more than 153 million driver's license scans. The lesson is not just identity theft. It is vendor concentration around identity proofing.

2 September 2026
Data Breach Identity Security Privacy

KerberLoss and ResetNightmare: Kerberos Can Fail Without Stealing a Ticket

Two Active Directory logic flaws presented at Black Hat show how SPN handling and password reset behavior can enable downgrade, disruption, and domain takeover.

23 August 2026
Active Directory Kerberos Identity Security

WhatsApp Usernames: A Privacy Win That Opens a New Impersonation Surface

WhatsApp usernames reduce phone-number exposure, but they also create a new global namespace where brands, public bodies, and lookalike handles can become fraud infrastructure.

7 July 2026
Phishing Social Engineering Fraud

LSHIY Password Spray: ROPC and MFA Gaps in Microsoft 365

A June 2026 password spray from LSHIY LLC's IPv6 range compromised 78 Microsoft accounts across 64 organizations by abusing Azure CLI ROPC sign-ins that MFA policies did not cover.

1 July 2026
Password Spraying Azure Microsoft 365

SaaS Hacking: The New Internal Network Attackers Already Use

Attackers no longer need malware on every endpoint. With one valid identity, token, or integration, they can move through Microsoft 365, Google Workspace, Salesforce, Slack, GitHub, and other SaaS platforms like an internal network.

12 June 2026
Cloud Security SaaS Security Identity Security

OAuth Consent Phishing in 2026: MFA Stops Password Theft, Not Bad App Grants

Attackers do not always need your password. A single OAuth consent grant can give a malicious or compromised app durable access to mail, files, calendars, and SaaS data.

30 May 2026
Cloud Security Identity Security Phishing

AitM Phishing: How Attackers Bypass MFA and How to Stop Them

Adversary-in-the-Middle phishing silently proxies real login pages and steals session tokens — making MFA useless. Here's how it works and how to detect it.

7 May 2026
Phishing Red Team Blue Team

AWS IAM Privilege Escalation to Data Exfil: The Full Attack Chain

How attackers escalate from a low-privilege AWS IAM credential to full S3 data theft — and the CloudTrail events, GuardDuty findings, and Sigma rules that expose them.

7 May 2026
Cloud Security Red Team Blue Team

Non-Human Identities: The Attack Surface Your Security Team Isn't Managing

Service accounts, API keys, OAuth tokens and machine credentials now outnumber human identities 144 to 1. Most organizations have zero visibility into them. Attackers do.

7 May 2026
Cybersecurity Identity Security Blue Team

Passkeys and FIDO2: The End of Passwords — and What Attackers Do Next

How passkeys and FIDO2 work, why they defeat phishing and credential stuffing, and how attackers are already adapting with downgrade attacks and fallback abuse.

8 April 2026
Cybersecurity Authentication Hardening
HiveSecurity

Offensive thinking. Defensive expertise.

Content
  • Home
  • Blog
  • Tags
  • Vulnerabilities
Resources
  • Tools
  • Cheat Sheet
  • Security Guides
Company
  • Contact
  • About
  • RSS
  • Privacy
  • Security Policy

© 2026 Hive Security. All rights reserved.

Built with zero trust & least privilege