MFA isn’t foolproof—it’s just a hurdle attackers know how to leap. If your identity pipeline views MFA as a simple pass/fail, you’re overlooking 10 risk signals that can bypass basic 2FA. See them all at fusionauth.io/lp/10-attack...
FusionAuth
@fusionauth.io
The only Customer Identity and Access Management (CIAM) with hybrid, single-tenant deployment you can dev and test anywhere
We're live at Black Hat USA! Come find the FusionAuth team at Booth #5642 at Mandalay Bay. Spin to Win kicks off at 4:30pm today. Bingo at 6pm. Come say hello! fusionauth.io/event/blackh... #BlackHat2026 #BHUSA #FusionAuth #CIAM
Ever feel like your auth setup is a ticking time bomb? 💣 Join us at Black Hat Booth #5642, Aug 4–6, Mandalay Bay, Vegas! FusionAuth gives you control with a CIAM platform that's self-hosted or cloud-based. No surprises! fusionauth.io/event/blackh... #BHUSA #CIAM #AppSec #FusionAuth #Auth
We're at #BlackHat2026. Booth #5642, August 4–6 in Las Vegas. CIAM that you actually control. No lock-in. Deploy anywhere. Come talk auth or just spin to win. fusionauth.io/event/blackh... #BHUSA
BlackHat USA 2026 - FusionAuth Event
Meet the FusionAuth Crew at Booth #5642
fusionauth.io
Over 24,000 servers are leaking password hashes due to a 20-year-old flaw in their BMC interfaces. Researchers cracked HPE factory passwords in just a day! Dan Moore from FusionAuth discusses why simply rotating passwords isn't enough: itnerd.blog/2026/07/29/t... 🔒💻
Thousands of Servers Leak Authentication Password Hashes via 20 Year-Old Vuln in BMC Interface
Researchers have uncovered more than 24,000 servers leaking authentication password hashes from a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. Lava HQ has a …
itnerd.blog
FusionAuth Appoints Jamey Miller as SVP of Engineering and Technology fusionauth.io/blog/jamey-m...
FusionAuth Appoints Jamey Miller as SVP of Engineering and Technology
FusionAuth Appoints Jamey Miller as SVP of Engineering and Technology - https://fusionauth.io/blog/jamey-miller-svp-engineering
fusionauth.io
Credential stuffing is still a threat in 2026. @mooreds.com details the Chick-fil-A breach at itnerd.blog/2026/07/22/c...
Credential stuffing continues as users often don't change compromised passwords. @mooreds.com details the Chick-fil-A breach where attackers used new devices and IPs for thousands of rapid attempts. Stronger identity verification could have helped. Read more: itnerd.blog/2026/07/22/c...
Service accounts and hardcoded keys aren't enough for thousands of autonomous AI agents needing API access. 🤖🔐 In Ep. 72 of Cyber Security Matters, FusionAuth CEO Brian Bell discusses non-human identity security and the shift in CIAM. Listen here: fusionauth.io/podcast/ai-a... #AI #IdentitySecurity
New research: 88% of organizations running AI in production have already had a confirmed or near-miss identity security incident. We walked through the data — nonhuman identities, the confidence paradox, deployment architecture as a risk variable.
Build vs. buy for authentication isn't a straightforward answer. It depends on your team size, timeline, and how you factor in compliance overhead. FusionAuth’s Build vs. Buy calculator lets you plug in your actual numbers and see where things land. fusionauth.io/buildvsbuy
FusionAuth Launches Intelligent MFA in Latest Release as Demand Surges for Identity Infrastructure Customers Can Control fusionauth.io/blog/fusiona...
FusionAuth Launches Intelligent MFA in Latest Release as Demand Surges for Identity Infrastructure Customers Can Control
FusionAuth Launches Intelligent MFA in Latest Release as Demand Surges for Identity Infrastructure Customers Can Control - https://fusionauth.io/blog/fusionauth-intelligent-mfa-pr
fusionauth.io
AI agents don't click password reset links or respond to MFA prompts. But most teams are still authenticating them like humans. Dan Moore from FusionAuth on what that's costing you: scworld.com/perspective/...
Your AI agent can't be authenticated by a password reset email
AI agents expose identity gaps as machine accounts outpace governance.
scworld.com
84% of the most AI-security-confident organizations in our survey had a confirmed breach. The faster you move, the bigger the gap between what your policies say and what your infrastructure actually enforces. Full report: fusionauth.io/ebooks/the-2...
Most MFA runs in a vendor's cloud. Challenge or pass. No explainability, no paper trail. FusionAuth 1.68 runs the scoring inside your own instance. 10 deterministic signals, full webhook logs to your SIEM, and no black box. Included in every paid plan. fusionauth.io/blog/intelli...
SaaS identity deployments report over double the confirmed AI security incidents of self-hosted environments (83% vs 38%). Tomorrow at 10:30 AM MT / 12:30 PM ET, Dayna Rothman outlines the architectural choices that determine your AI blast radius. Register: fusionauth.io/webinar/the-...
Intelligent MFA Should Challenge Risk, Not Loyal Customers fusionauth.io/blog/intelli...
Intelligent MFA Should Challenge Risk, Not Loyal Customers
Intelligent MFA Should Challenge Risk, Not Loyal Customers - https://fusionauth.io/blog/intelligent-mfa
fusionauth.io
Jim McDonald (IDAC) chats with Dan Moore from FusionAuth about the future of customer identity management. Discover insights on authentication, risk-based MFA, and the role of AI. Watch the full episode: youtu.be/aaHEajBFAbI #CIAM
#433 - Sponsor Spotlight - FusionAuth
Jim McDonald sits down with Dan Moore, Senior Director of CIAM Strategy and Identity Standards at FusionAuth, for an in-depth conversation on customer identity and access management. Dan explains how FusionAuth views authentication as the front door to any application and why control, deployment flexibility, and developer ownership are central to their approach. The discussion covers progressive registration, friction vs. usability, customization options, identity standards, the build vs. buy debate, risk-based MFA, and how AI agents will shape the future of customer identity. This episode and others is made possible with support from FusionAuth. Learn more at fusionauth.io/idac. Connect with Dan: https://www.linkedin.com/in/mooreds/ Learn more about FusionAuth: https://fusionauth.io/idac Blog article mentioned: https://bobdahacker.com/blog/fifa-hack Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com 00:00:00 Introduction 00:01:18 What is FusionAuth? 00:03:15 Dan's identity origin story 00:04:19 Developer focus and ethos 00:06:54 Authentication as the front door 00:10:00 Balancing friction and usability 00:15:24 Customization in CIAM 00:18:10 What sets FusionAuth apart 00:20:33 FusionAuth's customer sweet spot 00:25:48 Deployment flexibility and the control spectrum 00:30:19 Common challenges in CIAM 00:33:06 Build vs. buy for authentication 00:36:00 Omni-channel authentication 00:40:27 Why identity standards matter 00:42:07 Risk-based MFA and intelligent challenges 00:45:00 AI agents and the future of CIAM 00:49:23 Closing thoughts 00:51:35 Vacation roundup Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Dan Moore, FusionAuth, CIAM, customer identity, authentication, access management, IAM, identity standards, MFA, risk-based authentication, progressive registration, OAuth, OIDC, SAML, AI agents, deployment flexibility, build vs buy, Sponsor Spotlight
youtu.be
Meta's AI support chatbot recently gave attackers access to Instagram accounts by misinterpreting customer support requests. It even sent a confirmation code to the attacker's email. Read the full exploit breakdown here: itnerd.blog/2026/06/02/h...
Hackers hijacked Instagram accounts by tricking Meta AI support chatbot into granting access
Instagram has resolved a security issue that allowed several users’ accounts to get hacked. The attack appeared to rely on tricking Meta’s own AI-powered support chatbot into granting access to a v…
itnerd.blog
85% of security leaders labeled "well prepared" for AI faced identity incidents last year. Why? Policies on paper don’t ensure runtime enforcement. Join CMO Dayna Rothman on July 14th at 10:30 AM MT/12:30 PM ET to learn why! Register: fusionauth.io/webinar/the-...
A 95% patch compliance rate may look good, but without context, it can be misleading. That unpatched 5% could be a major risk if tied to core systems. Focus on actual business impact, not just coverage percentages. Get the full guide at www.csoonline.com/article/4189...
The confidence-reality gap in AI security is eye-opening. Our recent AI report, covered by MSSP Alert, reveals that 84% of leaders who felt "extremely confident" experienced breaches last year. Evaluating machine identity at the deployment layer? Get the details at www.msspalert.com/news/mssp-ma...
The average enterprise has a staggering 144:1 ratio of non-human to human identities, with 97% holding excessive privileges. Join Dayna Rothman on July 14th as she dives into agentic auth with real data—no fluff! Register: fusionauth.io/webinar/the-... #AI #IdentityManagement #Webinar 🚀
🚀 Excited for #DenverDevDay! Join our own Lyle Schemmerling as he presents "Protecting Your API with OAuth." Learn about secure token handling & essential API checks! 📍 Community Room, 3:20 PM - 4:20 PM. #APISecurity #OAuth #TechTalk
Your AI agent can't click links or check inboxes. Let's stop using human-oriented CIAM for machine identities. The tech is there—let's treat it with the seriousness it deserves. Read @mooreds.com's full SC Media commentary here: www.scworld.com/perspective/... #AI #Cybersecurity #TechTalk
The FBI warns about Kali365 — a phishing attack that exploits legitimate OAuth flows to steal 90-day tokens. Dan Moore from FusionAuth explains why limiting device code grants is a crucial fix many overlook. Check it out at itnerd.blog/2026/05/27/f... #CyberSecurity #PhishingAlert
A leaked password can be reset, but a leaked database revealing how you categorize customers is permanent. The Madison Square Garden breach exposed sensitive identity data and highlighted the need for better protections. #Cybersecurity #Identity
Today is #InternationalPasswordlessDay! 🔐 The tech is here, standards are set, but why are we still using passwords? Integration can be tricky, but it's an engineering challenge, not a standards one. With passkeys, magic links, and one-time codes available, why haven't you made the switch yet?
Two-thirds of organizations faced AI identity incidents, despite 84% claiming confidence in their AI security. The gap between perception and reality is telling. Check out FusionAuth's 2026 State of AI & Identity Report in Corporate Compliance Insights. #AISecurity #Identity #CIAM