Tag: Passwords
-

Phishing Statistics 2026: What the Numbers Actually Look Like
The phishing statistics in 2026 run worse than the phishing statistics in 2020 on every measure that matters. The volume went up, the click through rate went up, the credential capture rate went up, the time to first click went down, the time to first report went up. The state of the phishing problem in…
-

Non-Human Identity Attestation in 2026
Non-human identity attestation is the work of knowing what every service account, every API key, every bot identity, and every machine credential can do, who owns it, when it was last used, and whether it is still needed. Most enterprises in 2026 have not done this work. The attackers know. The auditors are catching up.
-

The Service Account Attestation Problem
The service account attestation problem is the largest unknown risk in the typical enterprise. The defender who solves the attestation problem has solved a category of breach the defender did not know existed. Here is the approach.
-

The Machine Identity Attestation Problem
Machine identity attestation in 2026 amounts to the work of knowing what every workload, every container, every service mesh identity, every machine credential, every certificate, every API token can do, who owns it, when it was last rotated, whether it sits still needed. Most enterprises in 2026 have not done this work. The 2026 guide…
-

The Raspberry Pi in Production Is a Security Incident Waiting to Happen
The Raspberry Pi in a homelab is a learning tool. The Raspberry Pi in a production rack is an unmanaged device running unpatched firmware on the same network as the payment system. Here is what to do about it.
-

Session Token Theft Has Replaced Password Theft (And You Are Not Ready)
Infostealer logs have made session token theft the dominant credential attack. The password is no longer the thing the attacker wants. The session is. Here is what to do about it.
-

The Non-Human Identity Problem You Have Not Mapped Yet
Service accounts, API keys, OAuth tokens, machine certificates. The non-human identity surface in 2026 is larger than the human one, and almost nobody has mapped it.
-

Why SSO Isn’t Magic and Your Service Account Problem Is Worse
Single sign on solved the human password problem. It did not solve the service account problem. The service account problem is now larger than the human password problem was in 2015.
-

The Passkey Migration Is a Mess (And How to Fix It)
Passkeys are the right answer to the password problem. The migration is full of edge cases the FIDO Alliance did not think through. Here is what is broken, and what the realistic path forward looks like.
-

Modern Phishing as a Service Is Boring (And That Is Why It Works)
Phishing in 2026 is not a clever technical exploit. Phishing in 2026 is a service industry, a well oiled business, and the most reliable way into a corporate network. Here is why it works.