Categories
Identity
Passkeys, SSO, SCIM, device trust, and the standards underneath them.
-
The agent handed over its API key, and the logs looked normal
Attackers prompted a METR agent into revealing its API key, then spent about $600,000 in model credits over three weeks inside normal-looking evaluation traffic.
-
The forged SAML login your logs will call legitimate
Actively exploited miniOrange SAML bypasses (CVE-2026-15981, CVE-2026-61979) forge admin logins the IdP never saw and version scanners called patched.
-
The passkeys held. The signals around them didn't.
Three August research releases defeated passkeys without breaking the cryptography. Each broke the plumbing around the key: logging, binding, and the audit trail.
-
Service accounts never offboard
Every human identity gets a leaving day. Machine identities are created, granted, and forgotten — and access reviews rarely list them. The gap is structural.