A sustained attempt against AWS root accounts shows how low-rate credential attacks still matter when the target is the one identity that can reach everything.
Session-cookie theft can sidestep 2FA in SaaS apps, turning a user’s signed-in browser into the weakest link in the chain.
A credential-stealing campaign aimed at Claude accounts shows why modern account security is no longer just about passwords - it is about revoking live sessions before an attacker can replay them.
Anthropic’s warning points to a familiar but still underappreciated threat: endpoint malware can steal live SaaS sessions and let an attacker act as the authenticated user without ever learning the password.
Identity fabric is emerging as a way to connect fragmented IAM systems, watch identity behavior in real time, and reduce the blind spots created by unmanaged machine accounts.
A discounted bundle for encrypted passwords, passkeys, aliases, and leak alerts shows how consumer security is moving from isolated tools to layered identity control.
The most dangerous entry points are often not exotic exploits, but a convincing message, a forgotten app grant, and a slow response window.
AWS defenders can turn CloudTrail, VPC Flow Logs, and Route 53 Resolver data into a single timeline that makes suspicious activity easier to interpret.
AWS’s detection guidance spotlights a hard truth in cloud security: credential theft is often only the opening move, and the real story emerges when identity, storage, network, and DNS signals are read together.
The earnings pop is only part of the story. The deeper signal is that buyers are treating machine identities and AI agents as security objects, not just automation tools.
Identity abuse, not malware, is doing the heavy lifting in a campaign built around OAuth, device-code phishing, and suspected reverse-proxy phishing infrastructure.
Ending passwords for legacy machine identities is only the visible move; the harder task is finding every hidden integration, its owner, and the access it still deserves.
The security lesson is not that multi-factor authentication fails, but that it can succeed at the wrong job if identity proofing and monitoring are treated as afterthoughts.
A new security update adds multiple passkeys, longer alphanumeric passwords, and caller context - a small set of changes that could matter a lot in a platform where trust is often tested before a message is even opened.
New security features point to a broader shift away from one-time codes and toward phishing-resistant authentication, with extra friction added before users trust an unknown caller.
A new security rollout on the messaging giant pushes login away from shared secrets and toward phishing-resistant credentials, while also tightening fallback and scam cues.
The login story is only half the picture: WhatsApp is pairing passkeys with a stronger second-step secret and caller-context cues aimed at lowering phishing, recovery abuse, and scam pressure.
A CISA red-team lessons-learned advisory shows how identity compromise can become a business crisis when detection, escalation, and containment do not move fast enough.
WhatsApp is pushing account security toward device-bound login, tougher two-step verification, and more caller context on Android, a small interface shift with real anti-phishing value.
The app is tightening account access with multiple passkeys and a tougher second-step secret, while Android users get more context when an unknown number rings through.