FusionAuth
@fusionauth.io
The only Customer Identity and Access Management (CIAM) with hybrid, single-tenant deployment you can dev and test anywhere
Most breaches are transactional, but a data catalog breach? That's a whole different game. If compromised, attackers gain a complete view of your enterprise. Credential rotation doesn't work. Discover the fresh approach for catalog remediation: www.cybersecurity-insiders.com/why-a-data-c...
Why a Data Catalog Breach Is Different — And Why You Can't Just Rotate Your Way Out of It
Alation disclosed a breach; catalog metadata can map sensitive fields, data flows and service accounts, guiding attacks for years to come.
cybersecurity-insiders.com
5 Warning Signs Your Company Has Outgrown Its Current Authentication Solution fusionauth.io/blog/5-warni...
5 Warning Signs Your Company Has Outgrown Its Current Authentication Solution
5 Warning Signs Your Company Has Outgrown Its Current Authentication Solution - https://fusionauth.io/blog/5-warning-signs-outgrown-auth
fusionauth.io
AI Is Exposing the Limits of Your Identity Infrastructure fusionauth.io/blog/ai-expo...
AI Is Exposing the Limits of Your Identity Infrastructure
AI Is Exposing the Limits of Your Identity Infrastructure - https://fusionauth.io/blog/ai-exposing-limits-identity-infrastructure
fusionauth.io
LLMjacking an emerging AI threat, stealing access to your paid models and running up bills. Dan Moore (FusionAuth) likens it to cryptojacking. Protect yourself with scoped credentials & least privilege. 💻🔒 Read more: www.itbrew.com/stories/what... #LLMjacking #Cybersecurity #Identity #AISecurity
What is LLMjacking, and why should IT pros care?
As anybody who follows cybersecurity knows, when a new technology emerges, it’s usually followed by a threat actor trying to -jack it up. There’s clickjacking (tricking someone into hitting a disguised URL), sessionjacking (stealing a token to impersonate a user and gain their web access), and DNSjacking (redirecting someone to an attacker-controlled destination). And now, with attackers trying to take over large language models, we have…LLMjacking.
itbrew.com
In just 23 days, AWS's agent tools faced four CVEs due to a common security issue: giving models too much decision-making power. Our 2026 AI Identity Report shows 66% of organizations experienced an AI identity breach, but only 28% can link actions back to a human. tech.yahoo.com/cybersecurit...
AWS Strands Agents Tools Received Four CVEs in 23 Days — And They All Share the Same Root Cause
Between July 15 and August 6, 2026, AWS Strands Agents Tools — the first-party tool package for the Strands Agents SDK — received four distinct security advisories. The vulnerabilities range from credential disclosure to arbitrary command execution, but they share a singular root cause: security-sensitive parameters were exposed as LLM-controllable inputs in the tool schema. […]
tech.yahoo.com
You Don't Own the Customer Experience If You Don't Control Identity fusionauth.io/blog/custome...
You Don't Own the Customer Experience If You Don't Control Identity
You Don't Own the Customer Experience If You Don't Control Identity - https://fusionauth.io/blog/customer-experience-control-identity
fusionauth.io
Homegrown Auth Is a Business Continuity Risk, Not Just a Security Risk fusionauth.io/blog/homegro...
Homegrown Auth Is a Business Continuity Risk, Not Just a Security Risk
Homegrown Auth Is a Business Continuity Risk, Not Just a Security Risk - https://fusionauth.io/blog/homegrown-auth-business-continuity-risk
fusionauth.io
Who Actually Owns Customer Identity in Your Organization? fusionauth.io/blog/who-own...
Who Actually Owns Customer Identity in Your Organization?
Who Actually Owns Customer Identity in Your Organization? - https://fusionauth.io/blog/who-owns-customer-identity
fusionauth.io
When engineers ignore the AI tools you've invested in, it’s not just a matter of adoption, it’s a procurement issue. Dan Moore points out that if you can’t pinpoint the problem your tool solves, measure its impact, and show improvements, you're just following trends. leaddev.com/ai/you-bough...
Attackers are targeting US water systems by exploiting long-standing weaknesses, not AI. Essential defenses like patching, limiting internet exposure, strong access controls, and proper authentication are vital. Check out Dan Moore's insights in Route Fifty: www.route-fifty.com/cybersecurit...
States, feds scramble to prevent more water cyberattacks
In the weeks after nine states were hit, lawmakers at the federal and state levels have proposed new funding to harden infrastructure, but experts warned they remain vulnerable.
route-fifty.com
A translation plugin on 400,000 WordPress sites exposed admin password-reset links via a public API. Two seemingly harmless features combined, allowing attackers access to admin accounts. Check out Dan Moore's insights on the TranslatePress flaw: itnerd.blog/2026/08/27/4...
400,000 WordPress Sites Impacted by Account Takeover Vuln in TranslatePress Plugin
Researchers have uncovered a critical vulnerability with a CVSS score of 9.8 in the TranslatePress WordPress plugin, with 400,000 active installations, that could allow unauthenticated attackers to…
itnerd.blog
New episode of the Maintainable Software Podcast! 🎙️ Join David Hayes from FusionAuth as he discusses why boring software wins. Dive into topics like long-lasting API decisions and the impact of technical debt on customer outcomes. Listen here: maintainable.fm/episodes/dav...
David Hayes: Boring Software, Clear Incentives, and Better Checklists
David Hayes believes maintainable software starts with a simple idea: fitness for purpose.
maintainable.fm
🚨 400k WordPress sites compromised due to weak API authentication! An attacker exploited this by requesting an admin password reset link. This breach emphasizes the importance of user context segregation for security. Full story and @mooreds.com quote at: itnerd.blog/2026/08/27/4...
A rogue app hits a wall and stops. An AI agent? It finds a way around it. Dave Hayes, VP of Product, dives into the shift in shadow AI: unsanctioned apps connect to one system, while agents connect to many, pushing past obstacles. Read more from Tech News Vision: technewsvision.co.uk/invisible-ai...
Invisible AI Agents Creating New Enterprise Security Risks | Tech News Vision
Lurking in many business environments are AI agents that pose serious security risks but, for the most part, remain out of sight of security teams, according
technewsvision.co.uk
AI didn't create the identity problem. It removed the speed limit fusionauth.io/blog/announc...
AI didn't create the identity problem. It removed the speed limit
AI didn't create the identity problem. It removed the speed limit - https://fusionauth.io/blog/announcing-fusionauth-1-69
fusionauth.io
Valid provenance can still lead to malware. In the AsyncAPI attack, attackers exploited trusted pipelines to deliver backdoored packages. @mooreds.com from FusionAuth explains that malicious code activates upon library import, not installation. Read more: www.reversinglabs.com/blog/why-sof...
Why software delivery cannot depend on trust alone | RL Blog
Attackers turned the trusted AsyncAPI CI/CD publishing pipeline against its users, and the provenance checks all came back clean.
reversinglabs.com
You wouldn’t hand a contractor a master key, so why let AI agents access your infrastructure without oversight? Join Dan Moore on the Security Strategist Podcast to discover why unique identities for AI agents are vital for security. Listen: em360tech.com/podcasts/why...
Attackers are logging in, not breaking through firewalls. Ensure AI agents use short-lived identity rules to prevent insider threats. Service accounts aren’t enough—opt for scoped tokens! Check out this report by TechnologyAdvice, sponsored by FusionAuth: fusionauth.io/ebooks/insid...
Fake accounts are exploiting free credits to resell cheap AI tokens. To combat this, decouple credits from signup. Insights from Dave Hayes, VP of Product at FusionAuth: itnerd.blog/2026/08/08/p...
Poison Claude Selling Discounted AI Tokens Built on Fake Accounts and Free Credits
Researchers have found online service Poison Claude reselling access to Anthropic’s premium AI models at a significant discount with suspicions that these discounts are coming from fraudulently reg…
itnerd.blog
AI adoption is skyrocketing, but 68% of teams lack clear metrics on its impact. Costs are rising too, with concerns jumping from 35% to 62%. Join @mooreds.com at LeadDev for insights on the AI Impact Report 2026. Details & registration: leaddev.com/event/how-ai... #AI #Engineering #LeadDev
Black Hat 2026 felt like #CES! While vendors splurged on flashy booths, the truth remains: attackers are logging in, not breaking in. We focused on real identity infrastructure with our '90s-themed booth instead of gimmicks. Let's chat auth—DM us for a fluff-free sync! #BlackHat2026
Two-thirds of breaches stem from login issues, highlighting the importance of identity management. In Episode 127 of the SourceForge Podcast, we discuss how in-house customer auth can pose silent security risks. Full episode: www.youtube.com/watch
MFA isn’t foolproof—it’s just a hurdle attackers know how to leap. If your identity pipeline views MFA as a simple pass/fail, you’re overlooking 10 risk signals that can bypass basic 2FA. See them all at fusionauth.io/lp/10-attack...
We're live at Black Hat USA! Come find the FusionAuth team at Booth #5642 at Mandalay Bay. Spin to Win kicks off at 4:30pm today. Bingo at 6pm. Come say hello! fusionauth.io/event/blackh... #BlackHat2026 #BHUSA #FusionAuth #CIAM
Ever feel like your auth setup is a ticking time bomb? 💣 Join us at Black Hat Booth #5642, Aug 4–6, Mandalay Bay, Vegas! FusionAuth gives you control with a CIAM platform that's self-hosted or cloud-based. No surprises! fusionauth.io/event/blackh... #BHUSA #CIAM #AppSec #FusionAuth #Auth
We're at #BlackHat2026. Booth #5642, August 4–6 in Las Vegas. CIAM that you actually control. No lock-in. Deploy anywhere. Come talk auth or just spin to win. fusionauth.io/event/blackh... #BHUSA
BlackHat USA 2026 - FusionAuth Event
Meet the FusionAuth Crew at Booth #5642
fusionauth.io