authentication

Microsoft Entra ID will auto-enable passkey profiles, synced passkeys

Microsoft Entra ID will auto-enable passkey profiles, synced passkeys 2026-01-26 at 10:52 By Sinisa Markovic Starting March 2026, Microsoft Entra ID will automatically enable passkey profiles and introduce support for synced passkeys. Passkey profiles move into general availability The update brings passkey profiles and synced passkeys into general availability. Administrators gain access to a new […]

Microsoft Entra ID will auto-enable passkey profiles, synced passkeys Read More »

The internet’s oldest trust mechanism is still one of its weakest links

The internet’s oldest trust mechanism is still one of its weakest links 2026-01-22 at 07:23 By Anamarija Pogorelec Attackers continue to rely on domain names as an entry point into enterprise systems. A CSC domain security study finds that large organizations leave this part of their attack surface underprotected, even as attacks become more frequent.

The internet’s oldest trust mechanism is still one of its weakest links Read More »

Wi-Fi evolution tightens focus on access control

Wi-Fi evolution tightens focus on access control 2026-01-09 at 07:33 By Anamarija Pogorelec Wi-Fi networks are taking on heavier workloads, more devices, and higher expectations from users who assume constant access everywhere. A new Wireless Broadband Alliance industry study shows that this expansion is reshaping priorities around security, identity, and trust, alongside adoption of new

Wi-Fi evolution tightens focus on access control Read More »

Counterfeit defenses built on paper have blind spots

Counterfeit defenses built on paper have blind spots 2025-12-24 at 08:17 By Anamarija Pogorelec Counterfeit protection often leans on the idea that physical materials have quirks no attacker can copy. A new study challenges that comfort by showing how systems built on paper surface fingerprints can be disrupted or bypassed. The research comes from teams

Counterfeit defenses built on paper have blind spots Read More »

Formal proofs expose long standing cracks in DNSSEC

Formal proofs expose long standing cracks in DNSSEC 2025-12-23 at 09:41 By Sinisa Markovic DNSSEC is meant to stop attackers from tampering with DNS answers. It signs records so resolvers can verify that data is authentic and unchanged. Many security teams assume that if DNSSEC validation passes, the answer can be trusted. New academic research

Formal proofs expose long standing cracks in DNSSEC Read More »

Session tokens give attackers a shortcut around MFA

Session tokens give attackers a shortcut around MFA 2025-12-22 at 07:45 By Help Net Security In this Help Net Security video, Simon Wijckmans, CEO at cside, discusses why session token theft is rising and why security teams miss it. He walks through how web applications rely on browsers to store session tokens after login often

Session tokens give attackers a shortcut around MFA Read More »

Passwordless is finally happening, and users barely notice

Passwordless is finally happening, and users barely notice 2025-12-16 at 07:32 By Anamarija Pogorelec Security teams know the strain that comes from tightening authentication controls while keeping users productive. A new report from Okta suggests this strain is easing. Stronger authentication methods are gaining traction, and many of them let users move through sign in

Passwordless is finally happening, and users barely notice Read More »

Europe’s DMA raises new security worries for mobile ecosystems

Europe’s DMA raises new security worries for mobile ecosystems 2025-12-15 at 08:43 By Anamarija Pogorelec Mobile security has long depended on tight control over how apps and services interact with a device. A new paper from the Center for Cybersecurity Policy and Law warns that this control may weaken as the European Union’s Digital Markets

Europe’s DMA raises new security worries for mobile ecosystems Read More »

New image signature can survive cropping, stop deepfakes from hijacking trust

New image signature can survive cropping, stop deepfakes from hijacking trust 2025-12-09 at 08:02 By Sinisa Markovic Deepfake images can distort public debate, fuel harassment, or shift a news cycle before anyone checks the source. A new study from researchers at the University of Pisa examines one specific part of this problem. They introduced a

New image signature can survive cropping, stop deepfakes from hijacking trust Read More »

What zero trust looks like when you build it step by step

What zero trust looks like when you build it step by step 2025-12-01 at 08:36 By Help Net Security In this Help Net Security video, Jonathan Edwards, Managing Director at KeyData Cyber, walks us through what practical zero trust adoption looks like in stages. He explains why he dislikes the term itself, then shifts to

What zero trust looks like when you build it step by step Read More »

Social data puts user passwords at risk in unexpected ways

Social data puts user passwords at risk in unexpected ways 2025-11-28 at 09:08 By Anamarija Pogorelec Many CISOs already assume that social media creates new openings for password guessing, but new research helps show what that risk looks like in practice. The findings reveal how much information can be reconstructed from public profiles and how

Social data puts user passwords at risk in unexpected ways Read More »

Why password management defines PCI DSS success

Why password management defines PCI DSS success 2025-11-28 at 08:03 By Sinisa Markovic Most CISOs spend their days dealing with noisy dashboards and vendor pitches that all promise a shortcut to compliance. It can be overwhelming to sort out what matters. When you dig into real incidents involving payment data, a surprising number come down to

Why password management defines PCI DSS success Read More »

The identity mess your customers feel before you do

The identity mess your customers feel before you do 2025-11-27 at 07:55 By Anamarija Pogorelec Customer identity has become one of the most brittle parts of the enterprise security stack. Teams know authentication matters, but organizations keep using methods that frustrate users and increase risk. New research from Descope shows how companies manage customer identity

The identity mess your customers feel before you do Read More »

Research shows identity document checks are missing key signals

Research shows identity document checks are missing key signals 2025-11-21 at 10:06 By Anamarija Pogorelec Most CISOs spend their time thinking about account takeover and phishing, but identity document fraud is becoming a tougher challenge. A new systematic review shows how attackers are pushing past old defenses and how detection models are struggling to keep

Research shows identity document checks are missing key signals Read More »

Is your password manager truly GDPR compliant?

Is your password manager truly GDPR compliant? 2025-11-20 at 08:34 By Sinisa Markovic Passwords sit at the core of every critical system, but many organizations still overlook how fragile their password workflows can be. When something goes wrong, security teams rush to uncover who had access, how those passwords were stored and whether sensitive data

Is your password manager truly GDPR compliant? Read More »

Product showcase: Proton Pass, a password manager with identity protection

Product showcase: Proton Pass, a password manager with identity protection 2025-11-19 at 07:02 By Help Net Security Managing passwords can be a real headache, and it’s still common to fall back on reusing them or storing them in a browser without much protection. Proton Pass, built by the Swiss company Proton AG (the team behind

Product showcase: Proton Pass, a password manager with identity protection Read More »

Wi-Fi signals may hold the key to touchless access control

Wi-Fi signals may hold the key to touchless access control 2025-11-10 at 09:00 By Mirko Zorz Imagine walking into a secure building where the door unlocks the moment your hand hovers near it. No keycards, no PINs, no fingerprints. Instead, the system identifies you by the way your palm distorts the surrounding Wi-Fi signal. That

Wi-Fi signals may hold the key to touchless access control Read More »

Passwordless adoption moves from hype to habit

Passwordless adoption moves from hype to habit 2025-10-31 at 08:00 By Anamarija Pogorelec With the average person juggling more than 300 credentials and credential abuse still the top attack vector, the password’s decline is long overdue. Across every major sector, organizations are changing how users log in, and new data shows the shift is picking

Passwordless adoption moves from hype to habit Read More »

WhatsApp now lets you secure chat backups with passkeys

WhatsApp now lets you secure chat backups with passkeys 2025-10-30 at 15:46 By Anamarija Pogorelec Messaging service WhatsApp is launching passkey-encrypted chat backups for iOS and Android, allowing users to encrypt their stored message history using their face, fingerprint, or device screen-lock code. Backups have long been a weak link in messaging-security. Even if chats

WhatsApp now lets you secure chat backups with passkeys Read More »

Can your earbuds recognize you? Researchers are working on it

Can your earbuds recognize you? Researchers are working on it 2025-10-27 at 09:05 By Mirko Zorz Biometric authentication has moved from fingerprints to voices to facial scans, but a team of researchers believes the next step could be inside the ear. New research explores how the ear canal’s unique acoustic properties can be used to

Can your earbuds recognize you? Researchers are working on it Read More »

Scroll to Top