Identity Briefing: Attackers have Agents too
The fortnightly read for identity practitioners.
The fortnightly read for identity practitioners.
Louis Jannett's USENIX-award-winning research found 18 critical and 53 high-severity vulnerabilities across 103 real-world passkey deployments. The biggest companies were the worst offenders.
A maximum-severity deserialization bug that could have meant remote code execution, patched on the service side before customers ever saw an action item.
We surveyed the Identity Leaders Network and ran a roundtable on agent inventory and governance. 40% have no idea how many agents they are running, and 40% say nobody owns the problem.
A critical Keycloak flaw, a Kerberos attack called ResetNightmare and a wave of helpdesk social engineering all point at the same gap: recovery is weaker than the login it replaces.
A ReliaQuest employee entered their password on a fake SSO page and approved the MFA push. What stopped the attacker was everything sitting behind the login.
A custom two-pack under the Advanced Account Security programme. Hardware-backed passkeys are becoming a consumer product, not a privileged-user control.
CISA’s Known Exploited Vulnerabilities catalogue, cut down to the entries where identity was the way in. We group them by how the failure actually happened and add our own notes on the ones worth your time.
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
CISA Apply mitigations in accordance with vendor instructions. Federal deadline 19 Sep 2026.
Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
CISA Apply mitigations in accordance with vendor instructions. Federal deadline 17 Sep 2026.
JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
CISA Apply mitigations in accordance with vendor instructions. Federal deadline 25 Sep 2026.
MikroTik RouterOS contains a missing authentication for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.
CISA Apply mitigations in accordance with vendor instructions. Federal deadline 13 Sep 2026.
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
CISA Apply mitigations in accordance with vendor instructions. Federal deadline 12 Sep 2026.
Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.
CISA Apply mitigations in accordance with vendor instructions. Federal deadline 12 Sep 2026.
ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation.
CISA Apply mitigations in accordance with vendor instructions. Federal deadline 14 Sep 2026.
JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
CISA Apply mitigations in accordance with vendor instructions. Federal deadline 25 Sep 2026.
Catalogue updated 18 Sep 2026 · Likelihood from FIRST’s EPSS. · All 259 identity entries
The fortnightly read for identity practitioners.
Original data from identity leaders, one proper deep dive, and the fortnight's news that actually matters. Free, every two weeks.
Read by identity architects, IAM leads and security leaders across ANZ, the US and the UK.
You're subscribed. Read the latest issue →