Tag · 294 articles

Iam

Signal Account Takeover: A Case Study on Former Germany’s Foreign Intelligence VP

Learn about the recent Signal account takeover of a former Germany’s foreign intelligence VP and how it impacts IAM practices. Protect your communications today.

AI Has Given You Two New Problems – And Identity Governance Is the Only Place They Meet

AI has brought new challenges to identity governance. Learn how to address data privacy and model governance issues with robust IAM strategies.

Best Practices for Safe Subtree Deletion (SubtreeDelete) in ForgeRock DS

Learn best practices for safely performing SubtreeDelete operations in ForgeRock DS. Protect your directory data while efficiently managing deletions.

Keycloak Kubernetes Deployment: Helm Charts and Operator Guide

Deploy Keycloak on Kubernetes with the official Helm chart or Keycloak Operator: helm repo add, values.yaml TLS config, PostgreSQL backend, Keycloak CRDs, and production HA setup.

Credential Stuffing with Burp Suite - PortSwigger

Learn how to detect and prevent credential stuffing attacks using Burp Suite by PortSwigger. Protect your applications from automated login attempts and safeguard user data.

Machine Identity Management: Securing Non-Human Identities in Cloud

Learn how to secure non-human identities in cloud environments using machine identity management techniques. Complete guide with code examples and security tips.

Week in Review: Weaponized OAuth Redirection Logic Delivers Malware, Patch Tuesday Forecast

Recent attacks leveraging OAuth redirection logic have delivered malware. Learn how to protect your applications and stay ahead of Patch Tuesday updates.

ThreatLocker Expands Zero Trust Platform with Network and Cloud Access Controls - The Fast Mode

ThreatLocker introduces Fast Mode, streamlining zero trust network and cloud access controls. Learn how to implement it securely and efficiently.

Steward Training Revs Up NFFE-IAM’s Forest Service Council - IAM Union

Steward Training is revamping NFFE-IAM’s Forest Service Council, enhancing cybersecurity awareness among union members. Learn how this impacts IAM and what developers need to know.

OAuth Redirection Abuse Enables Phishing and Malware Delivery - Microsoft

Learn about OAuth redirection abuse and how it enables phishing and malware delivery. Protect your applications with best practices.

Duncan: 2 Key Changes Pushing DOD Toward 2027 Zero Trust Finish Line - MeriTalk

DOD's push toward Zero Trust by 2027 is driven by two key changes. Learn how these shifts impact IAM and what developers need to know to stay compliant and secure.

Keycloak Token Exchange: Implementing OAuth 2.0 Token Exchange

Learn how to implement OAuth 2.0 Token Exchange in Keycloak for secure and efficient token management. Complete guide with code examples and security tips.

Go Secretless with Snowflake Workload Identity Federation - Snowflake

Configure Snowflake Workload Identity Federation with AWS IAM roles — including EXTERNAL_OAUTH_CLIENT_ID, EXTERNAL_OAUTH_TYPE=AWS_IAM, and trust policy setup to eliminate static secrets and stop managing long-lived Snowflake credentials.

OAuth Permissions in Microsoft Entra ID Enable Stealthy Corporate Email Access

Learn how OAuth permissions in Microsoft Entra ID can enable stealthy corporate email access and how to secure your applications against unauthorized access.

Microsoft’s Entra OAuth Tokens Could Be Exploited - What You Need to Know

Microsoft’s Entra OAuth tokens were recently found vulnerable to exploitation. Learn how this affects your security and what steps to take to protect your applications.

Digital Identity Provider V-Key Secures Strategic Investment

Digital identity provider V-Key secures strategic investment, enhancing its capabilities to offer robust authentication solutions. Learn how this impacts security and how developers can leverage V-Key in their applications.

Configuring Hosted Login Journey URLs in ForgeRock Identity Cloud

Configure hosted login journey URLs in ForgeRock Identity Cloud: set journey baseUrl, override per-realm endpoints, and fix redirect mismatches. Includes AM console walkthrough, HTTPS requirements, and troubleshooting common 302 redirect errors.

Threat Actors Target Microsoft 365 Accounts In OAuth Token Theft Operation

Learn about the recent OAuth token theft operation targeting Microsoft 365 accounts. Discover how to protect your integrations and prevent similar breaches.

Keycloak Docker Compose Production: Complete Deployment Guide for 2026

Production-ready Keycloak 26.x Docker Compose deployment with PostgreSQL, reverse proxy, clustering, monitoring, and security hardening. Copy-paste configurations for Nginx, Traefik, and Caddy.

Keycloak Realm Federation: Connecting Multiple Identity Sources

Learn how to implement Keycloak Realm Federation for connecting multiple identity sources. This guide covers setup, security, and best practices with code examples.