Duo Security

@duosec.bsky.social

📱 | Duo.com 🔑 | Duo is now a part of @Cisco.com 💚 | Human-Centered Security Solutions

IAM compliance isn't just a checkbox. It's your first line of defense. Weak passwords, orphaned accounts, and excessive access quietly put businesses at risk. Learn what IAM compliance really means and how to stay secure and audit-ready: cs.co/63329B1bGuP

IAM compliance

Nearly 1 in 3 MFA spray attacks now targets identity & access management systems. Adversaries follow the path of least resistance, and right now that path runs through identity. The good news? We have a blueprint. Treat every AI agent like a new employee. cs.co/63320B1wrbs

Nearly 1 in 3 MFA spray attacks now targets identity & access management systems.

We’re proud to share that Cisco Systems was named a Customers’ Choice in the 2026 Gartner Peer Insights™ Access Management Voice of the Customer. Thank you to our customers for taking the time to share your experience! cs.co/63323B1uZJZ

Cisco Systems was named a Customers’ Choice in the 2026 Gartner Peer Insights™ Access Management Voice of the Customer.

SMS and phone callbacks were once reliable MFA. Now SIM swapping, phishing, and message interception make them a liability. NIST recommends phishing resistant auth, & insurers are starting to require it. Duo Push, security keys, & biometrics are the shift: cs.co/63321B1OI3h

SMS and phone callbacks were once reliable MFA. Now SIM swapping, phishing, and message interception make them a liability.

Would your team fall for a phishing attack that uses Microsoft's own login system against them? Device code phishing takes advantage of the built-in authentication flow which means traditional MFA isn’t enough to stop it. Full article in comments 👇

A successful passwordless rollout rarely starts with technology. It starts with people, roles, and risk levels. Our guide walks you through evaluating readiness, choosing the right methods, and rolling out passwordless in a way that builds trust. Learn more: cs.co/63325B1K13l

Passwordless authentication with Duo

The least-privilege principle has guided access management for decades. Now it needs to evolve for agents. Autonomous systems work best when their access matches their purpose. Good agentic design isn't about restriction, it's about precision: cs.co/63323BE7R6l

Behind every secure login, every seamless MFA prompt, every 2 a.m. fire drill—there's a SysAdmin making sure the business never notices a thing. Today, we notice. Happy SysAdmin Day from Duo Security. We know exactly how hard you work to keep access secure and systems running.

SysAdmin Day

50 million rides a month means 50 million reasons to get security right. Lyft needed device visibility, strong access controls, and a path to zero trust. Here's how they consolidated MFA, MDM, and device trust without slowing anyone down: cs.co/63325BEIu2R

50 million rides a month means 50 million reasons to get security right.

An AI agent with access to corporate email was tricked into forwarding AWS credentials and a CRM export containing $1.28M in customer revenue data. Researchers found the weak point wasn't the model — it was overprivileged access and a lack of human oversight. cs.co/63323BEIuLV

An AI agent with access to corporate email was tricked into forwarding AWS credentials and a CRM export containing $1.28M in customer revenue data.

Your organization might have thousands of user accounts. Do you know which ones still have access to systems they shouldn't? IGA manages digital identities across their full lifecycle, keeping permissions aligned with roles, policies, & compliance requirements. Learn more: cs.co/63326BEIuIQ

Your organization might have thousands of user accounts. Do you know which ones still have access to systems they shouldn't?

"How do I get consistent identity controls when my agent infrastructure is all over the place?" Agents operate 24/7 across diverse gateways-without unified authorization, every deployment creates a blind spot. Your policies should travel with you. Learn more: cs.co/63325BEx8e7

"How do I get consistent identity controls when my agent infrastructure is all over the place?"

Fact or Fiction? Zero Trust only protects your network perimeter. Fiction: Zero Trust eliminates the idea of a perimeter entirely. Every user, device, and access request is treated as potentially hostile — whether it's coming from the office, home, or a café's Wi-Fi. cs.co/63326BEcXRk

We often think of phishing as a problem that happens before authentication. But that's only half the story. Security that stops at the login screen isn't full coverage. It's just the beginning. Here's what protecting the full authentication journey looks like: cs.co/63329BEcXux

We often think of phishing as a problem that happens before authentication.

Most identity breaches don't start with a sophisticated attack. They start with an undetected gap that nobody knew existed. Episode 4 of Duo's podcast explores how Cisco Identity Intelligence closes the gaps before they become breaches. cs.co/63323BEcXPN

"We'd love to go passwordless, but we'd have to migrate hundreds of apps." We hear this a lot. Federating your domain to Duo leaves your Entra ID-connected apps exactly where they are. What changes: your users stop typing passwords. Learn how it works: cs.co/63321BEcX1D

"We'd love to go passwordless, but we'd have to migrate hundreds of apps."

Every hour your team spends managing authentication incidents is an hour not spent on real threats. Forrester found Duo reduced authentication-related incident response by 50% — giving security teams back the time and visibility to focus on what matters. cs.co/63320BEpUhr

The most exploited credential in security isn't a weak password. It's the idea that passwords are still acceptable. Passkeys eliminate the guessing, sharing, and phishing that make passwords a liability. Check out the PCMag article to learn more: cs.co/63320BEpUCC

The most exploited credential in security isn't a weak password. It's the idea that passwords are still acceptable.

Non-compliance isn't just a regulatory issue. It's a risk to your reputation, operations, & bottom line. The companies staying ahead treat compliance as a foundation, not an afterthought. Strong security & compliance should be accessible to everyone. Learn more: cs.co/63326BEpUCY

Non-compliance isn't just a regulatory issue.

When an employee leaves, how fast does their access actually disappear? Done well, user lifecycle management protects the business without slowing people down. Done manually, it introduces errors, delays, & orphaned accounts that attackers can exploit. Learn more: cs.co/63320BEpdJ6

When an employee leaves, how fast does their access actually disappear?

Duo Passport changes how authentication works. Instead of repeated logins that frustrate users & create risk, it verifies identity & device trust, then stays out of the way. Continuous security, zero interruptions, & fewer gaps for threats to slip through. cs.co/63320BEHZoA

Duo Passport

When the U.S. Open tees off, millions are watching, but behind the scenes there's an IT team making sure everything runs without a hitch. For the USGA, world-class golf means world-class IT. See how their team secures one of the most complex environments in sports: cs.co/63329BEBSWN

When the U.S. Open tees off, millions are watching, but behind the scenes there's an IT team making sure everything runs without a hitch