< ciso
brief />
Tag Banner

All news with #iam tag

261 articles

Security professionals still rely on passwords often

๐Ÿ” A Yubico and Okta study finds 48% of cybersecurity professionals use usernames and passwords for personal accounts and 43% for work accounts, despite rating them as among the least secure methods. Device-bound passkeys were viewed as most secure but used by only 25% at work and 20% personally, while password managers saw 24% workplace adoption. The report highlights fragmented authentication practices, limited MFA mandates, and legacy onboarding defaults as factors driving insecure choices.
read more โ†’

AWS Identity Store adds network access controls

๐Ÿ”’ IAM Identity Center now supports network access controls for the Identity Store and SCIM APIs, letting you restrict API requests by VPC endpoints, source VPCs, or IP ranges. You can apply different restrictions per API and exempt AWS service requests; controls are optional and disabled by default. Configuration is done via the Identity Store API using AWS SDKs or AWS CLI and is available in all Regions where IAM Identity Center is offered.
read more โ†’

AWS Private CA adds detailed issuance logs

๐Ÿ“œ The new AWS Private CA CloudTrail IssueCertificateDetails event records full certificate content, issuing CA data, requester identity, and signing status for every issuance. It captures the complete TBS certificate with X.509 fields and convenience fields like subject, issuer, serial, validity, template, and algorithm. Events include both successful and failed issuances and identify the requester (account/IAM principal or service principal). Delivered automatically as a CloudTrail management event in supported Regions, it can be consumed in real time via EventBridge or queried with Athena at standard CloudTrail cost.
read more โ†’

DTU Breach Exposes Data of Up to 200,000 People

๐Ÿ”’ The Technical University of Denmark (DTU) reports that hackers used compromised credentials to access its identity and access management system, DTUBasen, potentially exposing information of up to 200,000 people. The breach may include Danish civil registration numbers (CPR), names, addresses, profile pictures, work emails, job titles, and next-of-kin contact details for active users. DTU is notifying affected current and former employees via e-Boks and urging caution against phishing and identity fraud.
read more โ†’

IAM Identity Center adds multi-region replication

๐Ÿ” IAM Identity Center can now be replicated to opt-in AWS Regions and between Regions inside AWS GovCloud (US) and AWS China, extending prior multi-Region coverage beyond enabled-by-default commercial Regions. When enabled, the service automatically replicates identities, entitlements, and related data from a primary Region to additional Regions, allowing users to retain access during primary Region disruptions. Multi-Region support works with external identity providers or the IAM Identity Center directory and requires a multi-Region customer managed KMS key (CMK); new instances can enable the feature with one click, while existing instances must create and configure a CMK. Standard AWS KMS charges apply; IAM Identity Center itself has no extra fee.
read more โ†’

IAM Identity Center Identity Store adds ARN support

๐Ÿ”’ AWS IAM Identity Center's Identity Store APIs now accept ARNs for users, groups, group memberships, and identity stores wherever resource IDs were previously required. This additive change means existing integrations keep working while allowing callers to supply either resource IDs or full ARNs directly. Responses still return resource IDs and malformed or wrong-type ARNs result in a ValidationException. The feature is available in all Regions where IAM Identity Center is offered at no extra cost.
read more โ†’

ElastiCache Serverless adds public endpoints

๐Ÿ”’ Amazon ElastiCache Serverless for Valkey now supports public endpoints, enabling direct connections from laptops, serverless functions, or external applications without VPNs or bastion hosts. A public endpoint creates a managed, internet-reachable cache with no VPC configuration and can be provisioned in under a minute. Connections use IAM authentication over TLS 1.3, eliminating stored passwords; clients use Valkey GLIDE 2.2+ or the Developer Toolkit for token management. Public endpoints are available in all commercial and China AWS Regions with standard pricing.
read more โ†’

Controlling AI Agents Before They Become Privileged Insiders

๐Ÿ”’ AI agents are evolving into autonomous enterprise workers that do more than generate content: they read email, access SaaS, call APIs, modify records and execute workflows. This shift introduces insider-like risk because agents can act with high autonomy and broad access. Leaders must move beyond traditional IAM to enforce action-level and runtime controls, assign human owners, and apply lifecycle governance to ensure agents are discovered, monitored, and constrained.
read more โ†’

UK shifts to service-led cybersecurity governance

๐Ÿ”’ The UK government is moving from top-down mandates to centrally built, user-focused cybersecurity services for its federated civil service. Breandรกn Knowlton-Hung, Deputy CISO, described how a 2025 NAO report revealed weak implementation of the 2022 strategy and capacity shortfalls, prompting a pivot to polycentric governance. The approach prioritizes useful central services, cheaper adoption, and reserved central authority for systemic risks.
read more โ†’

Most Organizations Face Microsoft 365 Governance Incidents

๐Ÿ“Š ShareGate's State of Microsoft 365 report found 77% of global organizations experienced at least one Microsoft 365 governance incident in the past year. The survey of nearly 1,800 IT professionals across nine countries highlights failures such as lingering access for former users, audit and compliance gaps, and sensitive data reaching unintended recipients. Rapid AI adoption and overconfidence in AI controls, plus limited proactive monitoring, are cited as key drivers of increased risk.
read more โ†’

Identity Visibility Foundation for Modern IAM

๐Ÿ” This article defines identity visibility in IAM as the continuous ability to discover every identity, map its entitlements, and observe runtime access usage. It explains why cloud and multicloud environments, machine identities, and application-local accounts create an expanding identity attack surface. The piece surveys identity visibility tool capabilities and vendor approaches, and outlines how visibility complements IAM, IGA, PAM, and zero trust efforts.
read more โ†’

Strengthen Fundamentals to Enable Nextโ€‘Gen Security

๐Ÿ”’ Effective cyber defense hinges on strong fundamentals rather than constantly chasing the latest tools. The author, a CISO with large-enterprise experience, argues that visibility, identity management, riskโ€‘based prioritization, resilience and a common security language are core. Embracing AI and other innovations is valuable but only when built on these basics. Organizations should inventory assets, scale identity controls like MFA and passkeys, focus on crown-jewel protections, rehearse recovery plans, and translate technical risk into business terms.
read more โ†’

AWS HealthOmics adds IAM session policy support

๐Ÿ” AWS HealthOmics now supports IAM session policies, allowing you to restrict permissions for individual runs without creating and managing multiple IAM roles. An IAM session policy is an inline policy that limits the maximum permissions of a run by intersecting with the underlying identity-based policy. This enables per-run scopingโ€”such as restricting access to a tenant's S3 buckets or specific S3 objectsโ€”without provisioning separate roles. Support is available in all Regions where HealthOmics is offered.
read more โ†’

Amazon Connect Customer adds tag-based access control

๐Ÿ” Amazon Connect Customer now supports tag-based access control for custom metrics, enabling administrators to govern who can view, create, or modify each metric. This lets teams tag metrics and assign permissions so they retain full control over their own metrics, have view-only access to other teamsโ€™ metrics, or are prevented from seeing restricted metrics. Search results respect these access controls. The feature is available in all Regions where Amazon Connect Customer is offered.
read more โ†’

NIST and CISA guidance leaves AI agent authorization gap

๐Ÿ” NISTโ€™s new report, Protecting Tokens and Assertions from Forgery, Theft, and Misuse (IR 8587), gives guidance for securing digitally signed tokens used in SSO and API access, but leaves agent authority questions unresolved. The guidance recommends continuous monitoring, lifecycle controls, and token hardening, while noting AI agents introduce additional IAM challenges. Organizations should inventory agents, use short-lived credentials, and treat agents as low-trust non-human identities that require constrained, task-limited access.
read more โ†’

CISA and NIST Issue Final Cloud Token Guidance

๐Ÿ” The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST) published Interagency Report 8587 on September 15 to protect cloud identity tokens and assertions used in SSO, identity federation and API access. The guidance, which is voluntary, warns that adversaries are increasingly targeting tokens to move laterally and access sensitive data. It prescribes short token lifetimes, scoped key usage, hardware-backed key storage for moderate impact and above, and strict logging and audience validation rules.
read more โ†’

AWS STS enforces unified 4,096-byte session limit

๐Ÿ”’ AWS Security Token Service (STS) now enforces a single 4,096-byte size limit for session tokens, replacing separate limits for tokens and passed-in parameters. This change lets you combine larger session policies and session tags more flexibly. STS also returns token size and percentage utilization in responses, logs those values to AWS CloudTrail, and publishes metrics to Amazon CloudWatch. An optional API parameter lets you request larger tokens for testing, and the features are available in all commercial, GovCloud (US), and European Sovereign Cloud Regions.
read more โ†’

Architecting resilient authentication with Cognito MRR

๐Ÿ”’ Amazon Cognito now supports multi-Region replication (MRR) to automatically replicate user pools across AWS Regions with near-real-time synchronization, built-in failover, and interoperable JWT sessions. Replica user pools support sign-in and token operations but are read-only for configuration and attribute writes, which must be performed in the primary Region. To use MRR you must configure a symmetric multi-Region AWS KMS customer managed key and consider adopting the updated multi-Region OIDC issuer to ensure consistent discovery and JWKS endpoints. Cognito supports automatic domain and OAuth failover via Route 53 health checks and recommends using infrastructure-as-code and JWKS caching strategies for smooth migration and operational continuity.
read more โ†’

Automating IAM least-privilege remediation via CI/CD

๐Ÿ”’ This post describes an automated workflow that turns AWS IAM Access Analyzer findings into actionable remediation artifacts. It classifies roles by originโ€”IaC-managed, manually created, or unusedโ€”and produces either a production-ready CDK pull request, a migration issue with recommended policies, or a soft-disable decommission plan. The automation integrates Access Analyzer, CloudTrail, Amazon Bedrock, and your CI/CD pipeline to create reviewable, deployable changes instead of accumulating tickets.
read more โ†’

Cloudflare Workers add resource-level authorization

๐Ÿ” Cloudflare now supports Worker-level access controls and four new roles so teammates and agents can be granted access to a single Worker instead of an entire account. Roles range from Metadata Read-Only and Content Read-Only to Editor and Admin, enabling observability, code review, deployment, or full management without excessive privileges. Permissions can be assigned to users, API tokens, or groups via the dashboard, API, or Terraform.
read more โ†’