SAML vs OAuth vs OIDC in three lines:
SAML: who is this user? Enterprise SSO, XML.
OAuth: what may this app access? Not login.
OIDC: who is this user? OAuth plus an ID token.
https://t.co/ZIZlaVmuBI
Uber, 2022: the attacker didn't break MFA. They sent push after push, posed as IT, and waited for one tap on approve.
Fixes: number matching, prompt rate limits, phishing-resistant MFA for admins.
https://t.co/tKxAR8VsnX
A password is a shared secret. A passkey is not.
The site stores only a public key, and your device won't sign in to a lookalike domain. Nothing to phish, reuse, or leak.
One catch: SMS recovery undoes it all.
https://t.co/bSQ6bwE3QN
Most attackers don't break in. They log in.
22% of breaches start with stolen credentials, the #1 way in (Verizon DBIR 2025).
Fastest fixes: phishing-resistant MFA, leaked-credential checks, short sessions.
https://t.co/O0mZu80Ob2
Most attackers don't break in. They log in.
22% of breaches start with stolen credentials, the #1 way in (Verizon DBIR 2025).
Fastest fixes: phishing-resistant MFA, leaked-credential checks, short sessions.
https://t.co/O0mZu80Ob2
Attackers exploited a zero-day in an unnamed security product Bitget used, reached an internal management system, and inserted withdrawal commands while posing as administrators. Private keys were never touched; they did not need to be.
https://t.co/dGOttrJmgd
UpGuard found over 16,000 Supabase databases exposing readable tables with personal data, plaintext passwords and authentication tokens, caused by missing or ineffective row-level security and misused keys.
Read more at: https://t.co/GbN5Vo8Fjq
https://t.co/tDUOkNFheI, an AI-assisted entry point to federal services, was launched today. The executive order behind it makes https://t.co/C9ftx8VVEm the authentication service and commits to no central citizen database.
https://t.co/v3Yy1AbFdC launched today: one AI front door to roughly 29,000 federal websites, powered by Gemini and Grok. No account required.
Today it answers and routes. It does not transact yet.
That distinction is the whole story.
https://t.co/tDUOkNFheI launched on September 29, 2026 as an AI front door to federal services. The chatbot got the headlines; the identity decisions in the executive order will decide whether it is safe.
https://t.co/YEyknK9jEi
After a 300,000-user trial, https://t.co/Z2ACO8QHwq One Login is offering passkeys to more than 23 million people across childcare, driving licences, State Pension and tax services. Nearly one in ten daily sign-ins already use one.
Read more at: https://t.co/mNaCdIHqX5
🥇 OpenZiti just landed the #1 spot on @startidentity's Top 7 Open-Source Zero Trust Tools for 2026 — beating Pomerium, Teleport, Headscale, NetBird, Boundary & Authelia.
Called "the most complete open-source zero trust networking platform," Apache 2.0 top to bottom.
https://t.co/bCFJVC4ofH
#ZeroTrust #OpenSource
Identity engineering is one of the best-paid, most durable specialties in security, and you do not need a specific degree to get in. Here is a concrete path.
https://t.co/3CPmwxncyj
A world where every identity and security professional, in every country, has free and independent access to the knowledge, connections, and opportunities to master IAM.
https://t.co/P9JCw9sXSQ