
Passkey Phishing Hits Entra ID - MFA Persistence Chain
Passkey-themed social engineering compromises Entra ID with MFA persistence. Plus SPIFFE identity spoofing in K8s and Cisco FMC CVE-2026-20079 exploitation.
The Identity Brief

Passkey-themed social engineering compromises Entra ID with MFA persistence. Plus SPIFFE identity spoofing in K8s and Cisco FMC CVE-2026-20079 exploitation.

FreeIPA exploit chain gives anonymous users admin access to Linux domains. ChatGPT OAuth exfiltration and autonomous AI credential harvesting raise the bar.

N-able N-central CVSS 10.0 RCE exploited in the wild, fourth patch in five weeks. Citrix NetScaler auth bypass CVE-2026-19490 and JetBrains CI/CD breach.

Token researchers map 39 passkey bypass methods exploiting enrollment and recovery flows. CrowdStrike Falcon zero-day PoC public.

Dropbox accounts breached through Lenovo SSO trust-chain flaw. Plus CVE-2026-83548 SonicWall CVSS 10 pre-auth RCE and 153M stolen driver's licenses.

Infostealers hijack Claude AI session tokens in first major AI identity theft campaign. Plus Claude Code governance gaps and Teams voice phishing hits DCs.

700 rogue AI agents breached Hugging Face via reward hacking. Plus ServiceNow triple CVSS 10.0, Amazon Kiro secret exfil, and NovaCookies AitM.

Snowflake forces NHI migration exposing ownership gaps. Keycloak CVE-2026-18963 CVSS 9.1 RCE. NVIDIA NemoClaw AI agent model poisoning via webpage.

CVE-2026-18963 lets unauthenticated attackers reset any Keycloak account. Plus SynkLoader steals creds via fake lock screens and Teams blocks bots.

CVE-2026-69836 CVSS 10.0 RCE in Microsoft Entra ID exploited in the wild. Russian APTs abuse OAuth consent flows. Phishing moves inside Slack and Teams.