·1677 words·8 mins
What Careful Adoption of Agentic AI Services means for non-human identity, privilege design, and compliance programs that haven’t caught up.
·1326 words·7 mins
How the DNS hijacking attack chain worked across 120+ countries, and what practitioners should be checking in their own environments.
·2038 words·10 mins
At least 11 phishing kits now abuse the OAuth device flow to bypass MFA entirely. How the attack works and how to shut it down.
·1696 words·8 mins
If your IAM program doesn’t treat non-human identities with the same rigor as human accounts, you have a problem that’s already being exploited.
·805 words·4 mins
What the IBM X-Force Threat Intelligence Index 2026 says about AI-accelerated attacks, and why basic hygiene failures still cause the damage.
·1545 words·8 mins
AI agents are already inside your environment making decisions and calling APIs. The question is whether anyone knows what access they have.
·664 words·4 mins
Zero Trust assumes no implicit trust based on network location. What that means in practice and how to build toward it incrementally.