FusionAuth

@fusionauth.io

The only Customer Identity and Access Management (CIAM) with hybrid, single-tenant deployment you can dev and test anywhere

Most breaches are transactional, but a data catalog breach? That's a whole different game. If compromised, attackers gain a complete view of your enterprise. Credential rotation doesn't work. Discover the fresh approach for catalog remediation: www.cybersecurity-insiders.com/why-a-data-c...

Why a Data Catalog Breach Is Different — And Why You Can't Just Rotate Your Way Out of It

Alation disclosed a breach; catalog metadata can map sensitive fields, data flows and service accounts, guiding attacks for years to come.

cybersecurity-insiders.com

When engineers ignore the AI tools you've invested in, it’s not just a matter of adoption, it’s a procurement issue. Dan Moore points out that if you can’t pinpoint the problem your tool solves, measure its impact, and show improvements, you're just following trends. leaddev.com/ai/you-bough...

Bild

Attackers are targeting US water systems by exploiting long-standing weaknesses, not AI. Essential defenses like patching, limiting internet exposure, strong access controls, and proper authentication are vital. Check out Dan Moore's insights in Route Fifty: www.route-fifty.com/cybersecurit...

States, feds scramble to prevent more water cyberattacks

In the weeks after nine states were hit, lawmakers at the federal and state levels have proposed new funding to harden infrastructure, but experts warned they remain vulnerable.

route-fifty.com

A translation plugin on 400,000 WordPress sites exposed admin password-reset links via a public API. Two seemingly harmless features combined, allowing attackers access to admin accounts. Check out Dan Moore's insights on the TranslatePress flaw: itnerd.blog/2026/08/27/4...

400,000 WordPress Sites Impacted by Account Takeover Vuln in TranslatePress Plugin

Researchers have uncovered a critical vulnerability with a CVSS score of 9.8 in the TranslatePress WordPress plugin, with 400,000 active installations, that could allow unauthenticated attackers to…

itnerd.blog

A rogue app hits a wall and stops. An AI agent? It finds a way around it. Dave Hayes, VP of Product, dives into the shift in shadow AI: unsanctioned apps connect to one system, while agents connect to many, pushing past obstacles. Read more from Tech News Vision: technewsvision.co.uk/invisible-ai...

Invisible AI Agents Creating New Enterprise Security Risks | Tech News Vision

Lurking in many business environments are AI agents that pose serious security risks but, for the most part, remain out of sight of security teams, according

technewsvision.co.uk

Valid provenance can still lead to malware. In the AsyncAPI attack, attackers exploited trusted pipelines to deliver backdoored packages. @mooreds.com from FusionAuth explains that malicious code activates upon library import, not installation. Read more: www.reversinglabs.com/blog/why-sof...

Why software delivery cannot depend on trust alone | RL Blog

Attackers turned the trusted AsyncAPI CI/CD publishing pipeline against its users, and the provenance checks all came back clean.

reversinglabs.com

Attackers are logging in, not breaking through firewalls. Ensure AI agents use short-lived identity rules to prevent insider threats. Service accounts aren’t enough—opt for scoped tokens! Check out this report by TechnologyAdvice, sponsored by FusionAuth: fusionauth.io/ebooks/insid...

Bild

Black Hat 2026 felt like #CES! While vendors splurged on flashy booths, the truth remains: attackers are logging in, not breaking in. We focused on real identity infrastructure with our '90s-themed booth instead of gimmicks. Let's chat auth—DM us for a fluff-free sync! #BlackHat2026

Bild

Two-thirds of breaches stem from login issues, highlighting the importance of identity management. In Episode 127 of the SourceForge Podcast, we discuss how in-house customer auth can pose silent security risks. Full episode: www.youtube.com/watch

Bild