Tag · 294 articles

Iam

Week in Review: Microsoft Fixes Exploited Office Zero-Day, Fortinet Patches FortiCloud SSO Flaw

Microsoft and Fortinet address critical security flaws affecting Office and FortiCloud SSO. Learn how these vulnerabilities were exploited and how to protect your systems immediately.

CVE-2026-24858: FortiOS SSO Zero-Day Exploited in the Wild - SOC Prime

Breaking: CVE-2026-24858 exploits FortiOS SSO, allowing unauthorized access. Learn how to secure your systems now.

Fortinet Patches CVE-2026-24858 After Active FortiOS SSO Exploitation Detected

Fortinet has patched CVE-2026-24858 after active exploitation was detected. Learn about the vulnerability, its impact, and how to secure your FortiOS SSO configurations immediately.

PingOne AIC Journey Editor: Building Modern Authentication Flows

Learn how to build modern authentication flows using PingOne AIC Journey Editor. This guide covers setup, configuration, and security best practices with practical examples.

Why Agentic AI Forces a Rethink of Least Privilege

Agentic AI is transforming cloud security. Learn why least privilege principles need a rethink and how to adapt your IAM strategies accordingly.

PingFederate OAuth 2.0 Configuration: Implementing Authorization Server

Step-by-step guide to configuring PingFederate OAuth 2.0 Authorization Server — including OAuth client setup, scope configuration, access token policies, and security best practices for PingFederate OAuth deployments.

FedRAMP Issues Final Proposed Changes to Cloud Authorization Process, Seeks Comments from Industry

FedRAMP issues final proposed changes to the cloud authorization process, seeking industry feedback. Understand the impacts and how to prepare for compliance.

No Password Required: CISO at RSA and Champion of a Passwordless Future

Learn why passwordless authentication is becoming essential for modern security. Discover how to implement it effectively and securely at the RSA Conference 2023.

DPoP: Next-Gen OAuth Token Security

Complete guide to DPoP (Demonstrating Proof of Possession) for OAuth 2.0 — how DPoP proof of possession works, implementation with code examples, and why DPoP OAuth tokens are more secure than bearer tokens.

Okta SSO Accounts Targeted in Vishing-Based Data Theft Attacks

Recent vishing attacks targeting Okta SSO accounts highlight the importance of robust security measures. Learn how to protect your SSO setup and prevent data theft.

Automated FortiGate Attacks Exploit FortiCloud SSO to Alter Firewall Configurations

Recent automated attacks targeting FortiGate firewalls via FortiCloud SSO highlight critical security risks. Learn how to protect your configurations and prevent unauthorized access.

Managing ESVs in PingOne Advanced Identity Cloud: Best Practices for Environment Variables

Learn best practices for managing Environment-Specific Values (ESVs) in PingOne Advanced Identity Cloud to enhance security and streamline configuration management.

Mandiant Releases Quick Credential Cracker: Hastening the Death of a Bad Protocol

Mandiant's release of a quick credential cracker highlights the urgency to phase out insecure protocols. Learn how to secure your systems now.

Crittora Introduces Agent Permission Protocol (APP): Execution-Time Authorization for AI Agents

Crittora's Agent Permission Protocol (APP) introduces execution-time authorization for AI agents. Learn how it secures your AI systems and why it matters now.

ForgeRock Blue-Green Deployment: Zero-Downtime Upgrades with Kubernetes

Learn how to implement ForgeRock Blue-Green Deployment with Kubernetes for zero-downtime upgrades. Complete guide with code examples and security tips.

Bay State Overhauls Insurance Authorization Rules

Bay State's overhaul of insurance authorization rules mandates stricter compliance and enhanced security measures. Learn how to adapt your IAM systems accordingly.

Keycloak User Federation with LDAP and Active Directory

Keycloak LDAP and Active Directory user federation setup guide — connection configuration, attribute mapping, group sync, LDAPS troubleshooting, and security best practices.

Can AI-driven PAM Reduce Stress for Security Teams?

Discover how AI-driven PAM can alleviate stress for security teams by automating tasks, enhancing security, and reducing human error.

Portnox Tightens Channel Focus Around Passwordless Zero Trust - ChannelE2E

Portnox shifts focus to passwordless zero trust, enhancing security for organizations. Learn how to implement this model effectively.

The API Authorization Hierarchy of Needs: Why You Aren’t Ready for AI Agents Yet

The API Authorization Hierarchy of Needs outlines the steps to secure your API for AI agents. Learn why your current setup might not be ready and how to prepare.