<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/"><channel><title>The Identity Brief on it-learn.io | IT, Networking &amp; Cybersecurity Blog</title><link>https://blog.it-learn.io/identity/</link><description>Recent content in The Identity Brief on it-learn.io | IT, Networking &amp; Cybersecurity Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 21 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.it-learn.io/identity/index.xml" rel="self" type="application/rss+xml"/><item><title>Entra ID CVSS 10.0 RCE — CVE-2026-69836 Exploited</title><link>https://blog.it-learn.io/identity/2026-08-21-identity-entra-id-cvss-10-0-rce-cve-2026-69836-exploited/</link><pubDate>Fri, 21 Aug 2026 00:00:00 +0000</pubDate><author>it-learn.io</author><guid>https://blog.it-learn.io/identity/2026-08-21-identity-entra-id-cvss-10-0-rce-cve-2026-69836-exploited/</guid><description>Microsoft patches a maximum-severity RCE in Entra ID exploited in the wild, Russian APTs weaponize OAuth consent flows for persistent access, Unit 42 documents identity phishing inside Slack and Teams, and the ChainDrop npm worm steals developer credentials at machine speed through AI agent hooks.</description><media:content url="https://blog.it-learn.io/images/posts/newsletter-default/banner.png" medium="image"/></item><item><title>Password Spraying Surges 155x — Legacy Auth Bypasses MFA</title><link>https://blog.it-learn.io/identity/2026-08-19-identity-password-spraying-surges-155x-legacy-auth-bypasses-mfa/</link><pubDate>Wed, 19 Aug 2026 00:00:00 +0000</pubDate><author>it-learn.io</author><guid>https://blog.it-learn.io/identity/2026-08-19-identity-password-spraying-surges-155x-legacy-auth-bypasses-mfa/</guid><description>Huntress tracked 81 million password-spray login attempts in two weeks — all through SMTP, POP3, and IMAP protocols that bypass MFA entirely. Today&amp;rsquo;s Identity Brief also covers a CVSS 9.8 macOS authentication bypass now on CISA KEV, unverified claims of 3.6M Entra tenant records stolen, and TWINLOOT — a Python implant running full C2 inside SharePoint and Teams via overprivileged OAuth apps.</description><media:content url="https://blog.it-learn.io/images/posts/newsletter-default/banner.png" medium="image"/></item></channel></rss>