Tag · 213 articles

Security

PingFederate SAML Configuration: Enterprise Federation Setup Guide

Learn how to configure PingFederate for SAML-based enterprise federation. This guide covers setup, security, and troubleshooting with practical examples.

Week in Review: Microsoft Fixes Exploited Office Zero-Day, Fortinet Patches FortiCloud SSO Flaw

Microsoft and Fortinet address critical security flaws affecting Office and FortiCloud SSO. Learn how these vulnerabilities were exploited and how to protect your systems immediately.

CISA Warns of FortiCloud SSO Authentication Bypass Flaw Actively Exploited by Hackers

CISA warns of a critical FortiCloud SSO authentication bypass flaw actively exploited by hackers. Learn how to protect your systems immediately.

CVE-2026-24858: FortiOS SSO Zero-Day Exploited in the Wild - SOC Prime

Breaking: CVE-2026-24858 exploits FortiOS SSO, allowing unauthorized access. Learn how to secure your systems now.

Fortinet Patches CVE-2026-24858 After Active FortiOS SSO Exploitation Detected

Fortinet has patched CVE-2026-24858 after active exploitation was detected. Learn about the vulnerability, its impact, and how to secure your FortiOS SSO configurations immediately.

AWS Adds IPv6 Support to IAM Identity Center Through Dual-Stack Endpoints

AWS recently added IPv6 support to IAM Identity Center via dual-stack endpoints. Learn why this matters now, how to implement it, and best practices for security.

Why Agentic AI Forces a Rethink of Least Privilege

Agentic AI is transforming cloud security. Learn why least privilege principles need a rethink and how to adapt your IAM strategies accordingly.

PingFederate OAuth 2.0 Configuration: Implementing Authorization Server

Step-by-step guide to configuring PingFederate OAuth 2.0 Authorization Server — including OAuth client setup, scope configuration, access token policies, and security best practices for PingFederate OAuth deployments.

No Password Required: CISO at RSA and Champion of a Passwordless Future

Learn why passwordless authentication is becoming essential for modern security. Discover how to implement it effectively and securely at the RSA Conference 2023.

Automated FortiGate Attacks Exploit FortiCloud SSO to Alter Firewall Configurations

Recent automated attacks targeting FortiGate firewalls via FortiCloud SSO highlight critical security risks. Learn how to protect your configurations and prevent unauthorized access.

Managing ESVs in PingOne Advanced Identity Cloud: Best Practices for Environment Variables

Learn best practices for managing Environment-Specific Values (ESVs) in PingOne Advanced Identity Cloud to enhance security and streamline configuration management.

Mandiant Releases Quick Credential Cracker: Hastening the Death of a Bad Protocol

Mandiant's release of a quick credential cracker highlights the urgency to phase out insecure protocols. Learn how to secure your systems now.

Can AI-driven PAM Reduce Stress for Security Teams?

Discover how AI-driven PAM can alleviate stress for security teams by automating tasks, enhancing security, and reducing human error.

Portnox Tightens Channel Focus Around Passwordless Zero Trust - ChannelE2E

Portnox shifts focus to passwordless zero trust, enhancing security for organizations. Learn how to implement this model effectively.

The API Authorization Hierarchy of Needs: Why You Aren’t Ready for AI Agents Yet

The API Authorization Hierarchy of Needs outlines the steps to secure your API for AI agents. Learn why your current setup might not be ready and how to prepare.

Passkey Implementation Guide: From Registration to Authentication

Learn how to implement passkeys using WebAuthn for secure, passwordless authentication. This guide covers registration, authentication, and security best practices.

Identity Dark Matter: The Massive Hidden Cost of Your IAM Program

Discover the hidden costs of your IAM program and learn how to optimize it for better security and cost efficiency. Identity Dark Matter can silently erode your security posture and budget.

Credential-Harvesting Attacks by APT28 Target Turkish, European, and Central Asian Organizations

Recent credential-harvesting attacks by APT28 have targeted Turkish, European, and Central Asian organizations. Learn how to protect your systems and prevent similar breaches.

Google’s OAuth Flaw Potentially Exposing Millions of Accounts

Breaking: OAuth token breach affects Salesforce ecosystem. Learn what happened, who's impacted, and how to protect your integrations immediately.

ZombieAgent Zero Click Vulnerability: Silent Account Takeover Explained

Learn about the ZombieAgent zero-click vulnerability that allows silent account takeover. Discover how it works, its impact, and steps to protect your systems immediately.