CuraSec

tag: Identity · 6 items

2026-09-02 · BleepingComputer · source ↗ #third-party-breach#identity#saas
  • Engineer — Plan: The flaw is on Lenovo’s side, not patchable by your team, but audit all corporate Dropbox accounts for unauthorized access and disable any Lenovo-linked authentication integrations in your Dropbox admin console.
  • SOC/IR — Act: Dropbox accounts are actively compromised — review Dropbox audit logs for anomalous sign-ins tied to Lenovo ID authentication since the earliest affected date and sweep for any corporate accounts flagged by Dropbox’s warning.
  • Leader — Act: Confirm this week whether your organization uses Dropbox accounts linked to Lenovo credentials, request Dropbox’s breach notification details, and assess whether customer or regulatory disclosure obligations are triggered.
  • Engineer — Plan: Run an Entra ID privileged role audit this quarter: export current role assignments, flag stale accounts from departed staff, and scope down over-provisioned roles (e.g. helpdesk accounts holding Global Admin) to least-privilege equivalents.
  • SOC/IR — Learn: Useful framing for why excessive Entra admin roles expand blast radius during identity-based intrusions, but no new TTPs, IOCs, or detection content here.
  • Leader — Plan: Excess admin accounts are a recurring audit finding (CIS Control 4); scheduling a formal privileged-access review and documenting results strengthens posture for SOC 2 / ISO 27001 auditors asking exactly this question.
  • Engineer — Skip
  • SOC/IR — Learn: Unit 42’s analysis of identity-based attack patterns offers context for triage judgment and detection prioritization, though no specific IOCs or new TTPs are surfaced in the summary.
  • Leader — Learn: The 90% statistic is a potential board-deck data point, but without independent corroboration of the underlying methodology this is vendor-sourced framing rather than actionable risk input.
2026-07-17 · Microsoft Security Blog · source ↗ #ai-security#identity#least-privilege
  • Engineer — Learn: Useful design guidance for teams building or deploying AI agents with access to cloud APIs and tools; no vulnerability or patch involved, but relevant for scoping agent permissions and auditing.
  • SOC/IR — Skip
  • Leader — Plan: As AI agents proliferate in enterprise environments, this signals a need to establish an access-control and identity policy for agents before deployments outpace governance — add AI agent privilege review to the quarter roadmap.
2026-07-14 · Microsoft Security Blog · source ↗ #identity#passkeys#entra-id
  • Engineer — Plan: This is a breaking change to default authentication behavior in Entra ID — audit your tenant’s authentication policy, test passkey rollout for user flows, and review the updated SMS/voice auth model before it affects production sign-ins.
  • SOC/IR — Learn: Passkey adoption changes the phishing-resistant auth landscape and may affect credential-based attack detections; no immediate hunt or detection work required, but worth understanding how login telemetry shifts.
  • Leader — Plan: A platform-level auth default change from a major identity provider warrants a quarter-horizon review of helpdesk readiness, user communication plans, and any compliance attestations tied to MFA method specifics.
2026-07-10 · BleepingComputer · source ↗ #ai-security#identity#non-human-identities
  • Engineer — Learn: Useful framing for designing IAM controls around service accounts and API tokens used by AI agents, but no specific vulnerability or action required today.
  • SOC/IR — Learn: Relevant background on how non-human identities complicate visibility and scope of compromise, but no IOCs or detection guidance to act on.
  • Leader — Plan: As AI agents proliferate in the enterprise, schedule an inventory and governance review of non-human identities this quarter to close ownership and access visibility gaps before they become audit findings.