Identity & Access Management

Cybersecurity used to mean building a wall around the office. Anyone inside the wall was trusted. But once everything moved to the cloud and people started working from anywhere, that wall vanished. The only thing left to stop a thief is checking your “identity” every time someone asks to access something — which is why the industry now calls identity “the new perimeter.”

Theme index · base 100 · USD total return
News & notes moving Identity & Access Management
Identity & Access Management

Palo Alto Networks Fair Value Estimate Raised 17% to US$395.38

The fair value estimate for Palo Alto Networks has been raised from US$336.70 to US$395.38, a roughly 17% increase in the underlying model, after a wave of analyst price target hikes. RBC Capital, Wells Fargo, BofA, Morgan Stanley and Truist lifted their targets into the low to mid US$400s, citing stronger cybersecurity demand as AI usage expands and customers consolidate spending with larger platforms. Goldman Sachs, Oppenheimer, BTIG and Susquehanna pointed to solid Q4 results and guidance, with broad based strength across firewalls, SASE, observability, identity and AI security modules. On the bearish side, Bernstein and Phillip Securities moved to more neutral stances while still raising targets, and Stephens and UBS described the risk or reward as more balanced with shares near peak valuation levels. The updated model trims the revenue growth assumption to about 17.31% from about 19.09% and the net profit margin outlook to about 13.84% from about 14.51%, while the future P/E rises to about 197.87x from about 164.67x and the discount rate adjusts to about 8.60% from 8.40%.
Simply Wall St·4hRead more →
Workforce & Customer IAM (SSO/MFA)

Japan's National Police Agency says North Korean IT worker applied for engineer job at bitFlyer

Japan's National Police Agency announced on September 18 that a person believed to be a North Korean IT worker applied in May 2025 for an engineer position at the domestic cryptocurrency exchange bitFlyer. The applicant attached a résumé to the recruitment form under someone else's identity and applied directly rather than through an intermediary, but the company noticed suspicious behavior and responded, so no hiring or damage resulted. According to the National Police Agency, the applicant accessed the recruitment form using multiple VPN services, listed a Gmail address as contact information, and stated in the résumé a broad range of skills in programming languages, blockchain, and cloud services, along with graduation from a European university and work experience in cities in Europe and Asia. In an online interview, the applicant said they were from Malaysia and living in Finland, but refused to relocate to Japan or work on-site, or said they would agree only if it were six months out, insisted on being paid in cryptocurrency, frequently checked another monitor during the interview, and at times another person's voice could be heard from behind. The National Police Agency and the U.S. Federal Bureau of Investigation believe that the cyberattack group WaterPlum's activities and some of the foreign-currency earning operations by North Korean IT workers are centrally linked to the Workers' Party of Korea's Bureau 313, and the IP addresses used by the group's attackers, the North Korean IT workers, and the applicant to bitFlyer matched.
NADA NEWS·17hRead more →
Identity & Access Managementimpact 4

Meta Launches Muse AI Agent With $20 and $100 Monthly Tiers

Meta Platforms rolled out Muse, an AI agent that can autonomously send emails, sell a car, and book travel on a person's behalf, Reuters reported on September 9, 2026. The agent, modeled on the open-source system OpenClaw, is available initially only in the U.S. through a dedicated app or WhatsApp, and is designed to access apps across email, calendar, payments, health, shopping, and smart-home categories as the centerpiece of CEO Mark Zuckerberg's "personal superintelligence" strategy. Meta launched Muse with a free tier and $20 and $100 monthly subscription options for heavier users, positioning the product as a new revenue stream beyond advertising. The launch follows a delay from April to improve security, and Meta added an autonomous safety agent that monitors Muse's actions, though internal testing uncovered an incident in which Muse exposed private iCloud photos and employees reported repeated logouts, monitoring failures, and inconsistent performance. Meta expects AI infrastructure spending to exceed $130 billion this year and has seen a 40% increase in technical and security incidents linked to AI, while its hedge fund holder count slipped to 254 in the second quarter from 262 in the first even as combined position value rose to $43.75 billion from $41.70 billion.
Reuters·1dRead more →
Workforce & Customer IAM (SSO/MFA)5

GPF Joins Forces with 3 Partners to Strengthen Online Fraud Protection for 1.2 Million Members

The Government Pension Fund, or GPF, has signed a memorandum of understanding with the Deposit Protection Agency, Gogolook (Thailand) Company Limited, known as Whoscall, and National ITMX Company Limited, known as NITMX, to strengthen awareness of fraud and digital crime among GPF members and the general public. Mr. Sornphon Tulyasathien, Secretary-General of the GPF Board, said the organisation manages retirement savings for more than 1.2 million members, and that this collaboration is part of the Retirement Academy project. Under the partnership, Whoscall is providing 1.5 million Whoscall Premium Basic licences to GPF members and will jointly develop an e-learning course with its partners. Mr. Sornphon noted that in 2026, about 16,000 GPF members will retire, with average savings of 1.5 million baht per person. Mrs. Piyaporn Phoklin, Deputy Director and Acting Director of the Deposit Protection Agency, disclosed that from mid-2024 to the present, there have been 270 complaints from people deceived by scammers posing as the agency, with elderly victims accounting for 30 to 40 percent, and 24 victims who actually lost money, with losses ranging from a few hundred baht up to 400,000 baht. Mr. Manwoo Joo, Chief Executive Officer of Gogolook (Thailand) Company Limited, said a single scam phone number can make more than 800,000 calls. Mr. Chatchai Dusadeenod, Managing Director of National ITMX Company Limited, said this collaboration will help broaden the fight against digital crime and reduce the number of victims.
InfoQuest·1dRead more →
Workforce & Customer IAM (SSO/MFA)

Microsoft Opens Government AI Suite October 1 With Features Still Pending Accreditation

Microsoft has told federal buyers that a new top government tier of its productivity suite, plus a companion agent-management product, will be available for Government Community Cloud customers to purchase on October 1, with individual capabilities lighting up in phases as each workload clears its required government security accreditation. The new suite layers Copilot, identity and security tooling, and agent-governance controls on top of the prior government tier, with the headline addition being Agent 365, which Microsoft has framed on the commercial side as providing security operations, financial operations, and observability and manageability of token spending across business processes. Microsoft has not disclosed per-seat pricing for the new tier or paid conversion rates from earlier no-cost federal Copilot deployments, leaving any government revenue forecast impossible, and the stock closed at $497.12, down 2.74% over the past year. On the commercial side, net paid seats more than doubled sequentially to over 30 million Copilot seats, while full-year capital expenditures hit $115.95 billion and free cash flow fell 23.19% in the quarter. Analysts carry an average price target of $572.92 with 38 Buy and 14 Strong Buy ratings, and the variable that decides the bull and bear cases is what Microsoft discloses in coming quarters about paid government seat counts and workload authorization progress rather than the October launch itself.
24/7 Wall St·2dRead more →
Workforce & Customer IAM (SSO/MFA)

Cloudbrink Launches OnGuard to Consolidate Enterprise Security Stack

Cloudbrink introduced OnGuard technology that extends a single Cloudbrink security and connectivity policy across users, devices and machines, taking aim at complex multi-product enterprise security stacks. The expanded platform gives enterprises an alternative to deploying and managing separate Cisco products for secure access, internet security, AI security and remote connectivity, consolidating ZTNA, Internet Security, Secure Web Gateway and AI security into one offering. OnGuard allows policy enforcement to begin when a device itself comes online, even before a user logs in, and to continue independently of the user session, with features including instant OnGuard availability, admin authorization, admin session termination, centralized visibility and selective policy control. CEO Prakash Mana said a single Cloudbrink platform can eliminate a significant portion of the Cisco secure-access stack, arguing that Umbrella, AnyConnect, Secure Access and AI Defense still force enterprises to manage multiple technologies, policies and operating models. The expansion builds on existing deployments, including at one U.S. insurance company where Cloudbrink replaced an environment that included Cisco AnyConnect and Fortinet, moving 300 employees on the first day and more than 600 during the first week, after which remote-connectivity support calls "pretty much disappeared," according to its VP of IT.
GlobeNewswire·2dRead more →
Workforce & Customer IAM (SSO/MFA)2

Digital Economy Ministry Teams Up with Thailand Post and PDPC to Develop D/ID Digital Delivery Code

The Ministry of Digital Economy and Society, together with Thailand Post Company Limited and the Office of the Personal Data Protection Committee, is pressing ahead with the development of the Digital Post ID, or D/ID, a digital delivery code aimed at raising data security in the parcel delivery process. The system replaces the display of full names, addresses and phone numbers on envelopes or parcel boxes with a QR Code, reducing unnecessary exposure of personal data while improving convenience and accuracy in identifying delivery points. Mr. Chaichanok Chidchob, Minister of Digital Economy and Society, said D/ID is one of the key infrastructures that will raise the country's data management to be more secure and ready for future use. Dr. Danant Suphattharaphun, Chief Executive Officer and Managing Director of Thailand Post Company Limited, said Thailand Post has begun piloting D/ID with more than 24,000 of its personnel and plans to expand awareness and trial use to the general public, as well as extend linkages with government agencies, the private sector and various service providers. At present, members of the public can already download D/ID and create their own code for use. Meanwhile, Police Colonel Surapong Plengkam, Secretary-General of the Personal Data Protection Committee, said the PDPC will continue to support and advise Thailand Post, promoting the adoption of Privacy by Design principles and the use of only necessary data from the design stage of systems and services.
Kaohoon·2dRead more →
Workforce & Customer IAM (SSO/MFA)3impact 4

EU to Propose Social Media Ban for Children Under 13

European Commission President Ursula von der Leyen said the EU will push for social media restrictions for children under 13 years, with a draft proposal set to be introduced on Thursday. The draft will impose strict age restrictions and verification requirements on social media, video-sharing platforms, app stores, online games, AI companions, and conversational AI chatbots, according to Bloomberg. "No social media under the age of 13. No personal account under the age of 15," von der Leyen said in her annual address on Wednesday, adding that the proposed law would allow 13- and 14-year-olds to have accounts with limited features and parental supervision. Companies that fail to meet the requirements could face fines of up to 6% of their annual sales. The bloc's upcoming rules follow Australia's ban last year on social media for children aged under 16, while individual EU member states have also been looking at setting their own restrictions.
Seeking Alpha·2dRead more →
Identity & Access Management

Government fast-tracks four central systems to cut off fraud money trails and boost victims' chances of getting money back

The Ministry of Finance, together with the Ministry of Digital Economy and Society and related agencies, is preparing a National Anti-Fraud Master Plan and laying out four national central systems to link risk data, incident reporting, money-trail tracking and asset freezing, so that agencies can act on the same information immediately instead of keeping data separate and coordinating step by step. Ms. Lalida Periswiwatana, deputy spokesperson for the Prime Minister's Office, said the government is accelerating efforts to cut off the money trails of technology-driven crime, after finding that money movements have become more complex and faster. Where funds once moved mainly through bank accounts, they can now be spread across multiple layers of accounts, withdrawn as cash, converted into digital assets, gold or foreign currency, or moved out of the country within just a few hours, meaning the old coordination approach may not be able to keep up with the money. The four central systems are: first, One Identity, One Risk Level, which links risk data so that financial institutions, telecom operators, digital platforms and law enforcement see the same set of risks in real time; second, a fraud-pattern analytics system that builds an anonymised financial transaction data centre to analyse criminal networks; third, a single-report, single-trail system that combines reports made through the 1441 hotline, financial institutions and the police into one system using a single reference number throughout the process; and fourth, a track-in-time, freeze-fast system that links data to follow money as it moves and issues freeze orders under legal authority, while supporting the return of funds to victims or the lifting of freezes in line with case outcomes. Related agencies will raise KYC, CDD and EDD standards to tighten scrutiny of customers and risky transactions from the outset, to a level comparable with financial centres abroad. The subcommittee on linking financial data to improve the monitoring of suspicious financial transactions, chaired by Deputy Prime Minister and Finance Minister Ekniti Nitithanprapas, has assigned the permanent secretary of the Ministry of Finance, together with related agencies, to speed up the design of the details of all four systems, including data structure, connectivity, responsible agencies and data standards, for completion within 30 days before submitting them to the subcommittee for further consideration.
InfoQuest·2dRead more →
Workforce & Customer IAM (SSO/MFA)

Gujarat Police to Seek Explanation from Google Over Case Involving More Than 510,000 Fake Gmail Accounts

Police in the western Indian state of Gujarat plan to seek an explanation from Google over gaps in its security measures, in connection with a case in which they busted a large network of fake Gmail accounts. One police official disclosed this to Reuters on the 15th. State police this week busted a wide-ranging criminal network accused of sending bomb threat emails to government agencies and others, and arrested two people. During the investigation, they identified 513,847 Gmail accounts and passwords that had been in operation since 2022. A senior official in the state police's cybercrime unit told Reuters that they would send a letter to Google seeking policy changes so that such security measures cannot be circumvented, and indicated a plan to formally designate Google as a subject of investigation. What police find particularly problematic is that two-factor authentication had been set up on each of the fraudulently created accounts, and they are also investigating how the criminal organization managed to set up and operate two-factor authentication on more than 500,000 accounts. The investigation was triggered by a bomb threat email received by the Gujarat state government on the 10th. The email was sent ahead of the BRICS summit held in New Delhi and threatened that countries cooperating with India would also be targeted, but according to police, all of the bomb threats were false.
ロイター·3dRead more →
Identity & Access Managementimpact 4

CrowdStrike CEO Kurtz Warns AI Cyber Threat Is Already Here

CrowdStrike CEO George Kurtz is pushing back against calls to slow frontier AI development, arguing the cybersecurity threat investors should worry about is not theoretical or years away. Kurtz said the genie is out of the bottle, pointing to advanced and open-weight models already available, and warned that AI is giving every criminal and lone actor elite execution, potentially letting less-skilled attackers operate with capabilities previously limited to sophisticated cyber groups. His remarks came in response to Anthropic CEO Dario Amodei, who has called for slowing development of advanced AI, with Kurtz arguing that pacing what comes next does not secure what is already here. He proposed treating AI agents as privileged identities with tightly controlled permissions, short-lived credentials and a kill switch, keeping humans involved in high-stakes decisions, and called for closer cooperation between cybersecurity companies and AI developers including Anthropic and OpenAI, offering CrowdStrike's threat intelligence to independent evaluation efforts. The argument arrives as CrowdStrike's business accelerates: fiscal second-quarter revenue rose 26% to $1.47 billion, annual recurring revenue climbed 25% to $5.84 billion, record net new ARR reached $333 million, up 51%, and free cash flow totaled $377 million, while the company raised its fiscal-2027 net-new-ARR growth outlook. CrowdStrike already generates more than $2.29 billion of ARR from customers using Falcon Flex, and investors are watching whether AI-related security concerns translate into measurable platform expansion through net new ARR, Falcon Flex adoption, customer spending on identity and AI security, and free cash flow.
GuruFocus·3dRead more →
Identity & Access Management2

Okta, IBM, Broadcom and Dataiku Ship Agent Governance Products as Category Decouples From Platforms

Four major infrastructure vendors have now shipped standalone agent governance products at general availability, a rush that has itself become the signal that agent governance is decoupling from individual platforms to become a category of its own. Okta pushed furthest into new territory with its July 2026 product innovations, shipping Agent-to-Agent Connections at general availability to enable secure multi-agent workflows through temporary runtime tokens that enforce which agents may invoke which others, alongside the Agent Gateway, available as a research release, which sits between agents and the systems they access without requiring code changes. IBM's Think 2026 announcement positioned next-generation watsonx Orchestrate as an agentic control plane, introduced in June on AWS and IBM Cloud, offering runtime policy management, credential health monitoring, and an Agent Access overview across an organization's entire agent estate. Broadcom embedded governance directly into the compute fabric with AgentMinder, unveiled at VMware Explore on August 31 and shipping at general availability bundled into the VMware Private AI Cloud, treating agents as enterprise-grade identities bound to a declared mission, permitted intents, approved tools, and authorized resources. Dataiku made a different architectural bet, with Dataiku Agent Management scanning agents across nine platforms including Microsoft Copilot Studio, Salesforce Agentforce, AWS Bedrock, and Google Vertex to provide a cross-platform control tower for discovery, certification, and audit-readiness. The urgency tracks to two numbers: Menlo Ventures found that 76 percent of AI applications are purchased rather than built internally, and the Cloud Security Alliance reported in February that 84 percent of organizations doubt they could pass a compliance audit focused on agent behavior or access controls.
Yahoo Finance·3dRead more →
Identity & Access Management

ServiceNow Launches AI Control Tower for Enterprise AI Governance

ServiceNow introduced new AI governance and workflow security tools called AI Control Tower, Context Engine, and Shift Zero. The products are aimed at helping enterprises manage AI agents with integrated identity, context, and cybersecurity controls. ServiceNow is targeting secure automation, access management, and compliance needs as companies expand AI-driven workflows across their operations. ServiceNow runs cloud software that helps large organizations manage digital workflows across departments, and these new AI governance tools plug directly into systems that already handle IT tickets, HR requests, and operational approvals for customers across North America and other global regions.
Simply Wall St·3dRead more →
Identity & Access Management

Archer Launches Archer Evolv AI Compliance With Native Amazon Bedrock Guardrails

Archer today launched Archer Evolv AI Compliance, a product that turns enterprise regulations and policies into policy as code delivered as approved Amazon Bedrock Guardrails, deployed natively inside the customer's own AWS account and enforced before a model responds to any prompt from an employee or an agent. The offering is powered by Archer's proprietary regulatory intelligence and 492 purpose-built models trained since 2017, drawing on 22 million regulatory documents, and is available today directly from Archer and in the AWS Marketplace. Enforcement runs as a continuous loop of Listen, Decide, Act, Assure and Learn, with every control traced back to the obligation that required it and every violation recorded in the customer's GRC system of record; no proxy sits in the inference path, and models outside Bedrock can apply the same control through the Amazon Bedrock Apply Guardrail API. The guardrails govern organizational obligations such as credentials and secrets, source code, confidential business information and customer-defined usage rules, as well as regulatory obligations including personal data under GDPR, CCPA and state privacy law, protected health information under HIPAA, payment and cardholder data under PCI DSS, and regulated categories such as export-controlled, securities and biometric data. Archer connects through one scoped, least-privilege AWS IAM role and reads guardrail configuration and events but never customer traffic, so prompt content, model responses, documents, embeddings, PII, model weights and training data never reach Archer, and native Bedrock guardrails continue enforcing as last deployed if connectivity is interrupted. Customers can introduce enforcement in stages through Observe, Advise and Enforce modes, with each version subject to approval and rollback, and Chief Product & Technology Officer Kayvan Alikhani said a guardrail is only as good as the obligation behind it, adding that Archer has already built that chain so customers do not have to.
Business Wire·3dRead more →
Identity & Access Management

Government Systems Breach: Digital Minister Matsumoto Says No Secondary Damage Confirmed

Digital Minister Takashi Matsumoto said at a post-cabinet press conference on the 15th, regarding the issue of unauthorized external access to government systems, that "no misuse of personal information or other secondary damage has been confirmed." The minister said that recurrence prevention measures such as strengthening monitoring systems are being advanced, and stressed that "we will strive to provide safe and stable information systems." The Digital Agency had announced on the 11th that unauthorized access to the Government Solution Service, a computer network system shared by all ministries and agencies, may have leaked the personal information of 246,000 government employees and others.
Jiji Press·3dRead more →
Identity & Access Management7

Finance Ministry and Digital Economy Ministry Set Up 4 National Central Systems to Block Fraudsters' Money in Real Time

The Ministry of Finance has joined hands with the Ministry of Digital Economy and Society to prepare four national central systems to link data on suspicious transactions between agencies, so that all sectors see the same set of risk data, and to speed up the tracing and freezing of money trails before funds are withdrawn, converted into digital assets or gold, or transferred out of the country. Dr. Ekniti Nitithanprapas, Deputy Prime Minister and Minister of Finance, in his capacity as chairman of the subcommittee on linking financial data to enhance the monitoring and investigation of suspicious financial transactions, disclosed together with Mr. Chaichanok Chidchob, Minister of Digital Economy and Society, that the subcommittee approved guidelines to upgrade the prevention and suppression of suspicious transactions in two areas: raising KYC, CDD and EDD standards to be on par with the world's leading financial centres, and drawing up a National Anti-Fraud Master Plan, whose core structure comprises four national central systems. These are the Data Sharing with Consent system, which exchanges risk data under consent; the Anonymous Financial Data Bureau, a centre for anonymous financial transaction data; the Case Management system, a national incident-reporting management system based on the principle of report once, one route; and the Financial Investigation and Account Action system for linking data and freezing money trails. The subcommittee has assigned the Permanent Secretary of the Ministry of Finance, together with relevant agencies, to design the details of the data structure, operating systems, connection guidelines, responsible parties, as well as the rules and data standards for all four systems, to be completed within 30 days before being submitted to the subcommittee for further consideration.
Business Today·4dRead more →
Identity & Access Management

Oracle Begins New Layoffs as AI Infrastructure Debt Mounts

Oracle has begun a new round of layoffs, following job cuts earlier this year, as the company racks up billions in debt to fund AI infrastructure. The move marks the latest in a series of workforce reductions at the technology giant. Separately, a dark web marketplace is reportedly selling scans of more than 153 million drivers' licenses, a breach experts warn could increase identity theft and fraud risks because licenses are difficult to replace. Elsewhere, experts are predicting the 2026 tax brackets, which may be wider, though that does not necessarily mean taxpayers will pay less.
GOBankingRates.com·4dRead more →
Workforce & Customer IAM (SSO/MFA)

IDrive Adds Microsoft Entra ID Backup to Its Microsoft 365 Protection Suite

IDrive announced on September 14, 2026 that it has added Microsoft Entra ID Backup to its IDrive Microsoft Office 365 Backup solution, extending protection to the identity and access management layer. The new capability automatically backs up critical Entra ID objects and settings to the IDrive cloud, covering users, groups, roles and administrators, administrative units, app registrations, enterprise applications, devices, policies, sign-in logs, audit logs, device configurations, device compliance policies, and BitLocker recovery keys. Key features include frequent automated snapshots, change tracking with historical comparison views, granular and bulk recovery that preserves relationships, point-in-time restore, centralized management of Entra ID and Office 365 backups from a single web console, and AES-256 encrypted storage in the IDrive cloud. The addition complements existing IDrive Microsoft Office 365 Backup support for OneDrive, Outlook, SharePoint, Teams and Groups. Microsoft Entra ID Backup is available for $10 per Entra ID seat per year with unlimited storage.
PR Newswire·4dRead more →
Privileged Access Management (PAM)impact 4

CrowdStrike and Palo Alto Networks Race Into AI Cybersecurity

CrowdStrike and Palo Alto Networks are racing to answer the question Jensen Huang raised on Sept. 10, when he told investors at the Goldman Sachs Communacopia + Technology Conference that cybersecurity is likely to become AI's next major growth market. CrowdStrike unveiled SafeMind at its Fal.Con conference on Sept. 1, an agentic cybersecurity system built by its own Cyber Superintelligence Lab on top of open Nemotron models, which the company says detects threats 29% more accurately and remediates them six times faster than the frontier models it benchmarked against. CrowdStrike's fiscal second quarter revenue rose 26% to $1.47 billion, with net new annual recurring revenue climbing 51% to a record $333 million, and CEO George Kurtz disclosed an eight-figure Falcon Flex deal with a frontier AI lab. Palo Alto Networks took the opposite path, integrating CyberArk and Chronosphere and adding Console, an AI native platform for agentic enterprise workflows; its Next Generation Security annual recurring revenue reached $9.1 billion, up 63% year over year, and total remaining performance obligations crossed $20 billion for the first time, rising 34% to $21.2 billion, even as it swung to a GAAP net loss of $282 million in the quarter. Investors rewarded only CrowdStrike's report, sending its shares up roughly 20% on Aug. 27, while Palo Alto's shares fell more than 5% despite revenue rising 34% to $3.41 billion in its fiscal fourth quarter. The threat behind both bets is not hypothetical: Anthropic told Reuters it disrupted a Russia-linked hacking campaign that used its Claude models against more than 20 Ukrainian government and defense targets, and a joint study by Wiz and Irregular found AI agents completed sophisticated offensive security challenges for under $50 in computing costs versus close to $100,000 for the same work by paid human researchers.
TheStreet·4dRead more →
Workforce & Customer IAM (SSO/MFA)

Over 153 Million Driver's License Records Surface on Dark Web After IDScan Breach

More than 153 million driver's license records from the U.S. and Canada have appeared for sale on the dark web, prompting the Pentagon and the FBI to respond. Cybersecurity journalist Brian Krebs found the trove through a dark-web service called Nexus, which advertised the records and claimed to have been pulling data for more than a year; a search for Canadian licenses returned roughly 1.1 million results, suggesting the overwhelming majority of the 153 million-plus records were American. The database reportedly included scans of the front and back of licenses, customer photos and images captured under infrared and ultraviolet light, and Krebs found a license belonging to Defense Secretary Pete Hegseth, prompting the Pentagon to tell TechCrunch it is aware of the reports and is evaluating them; the license of an FBI assistant director was reportedly exposed as well. IDScan.net, the identity-verification company identified as the apparent source, has acknowledged that an unauthorized party may have accessed or copied customer information stored in its cloud, including names and government-issued ID numbers, though it has not confirmed that 153 million distinct people were affected. The company is notifying potentially affected people and offering free credit monitoring and identity-protection services, with enrollment available at 1-833-516-2980.
Yahoo Finance·4dRead more →
Workforce & Customer IAM (SSO/MFA)

Trust Stamp Expands ID Dataweb Partnership Across Enterprise Customers

Trust Stamp Inc is expanding its partnership with ID Dataweb, extending the identity verification firm's use of Trust Stamp's biometric tokenization and identity fraud mitigation technology across its enterprise customer base. The expansion builds on three years of joint work serving one of the three largest life insurance providers in the United States, Trust Stamp said. ID Dataweb, a provider of identity threat detection and risk mitigation services, will now use Trust Stamp's technology more broadly across its growing roster of enterprise clients. Trust Stamp's patented Irreversibly Transformed Identity Token technology converts biometric data into tokens that can be revoked, a design meant to reduce the risks of storing raw biometric data while enabling identity verification. Trust Stamp president Andrew Gowasack said expanding the relationship represents an important next step in the company's commercial growth strategy and creates an opportunity to bring its IT2 technology to a broader range of enterprise customers, while ID Dataweb chief operating officer Matt Cochran said the partnership shows the value of combining innovative, privacy-preserving technologies to solve real-world identity challenges.
Proactive·4dRead more →
Identity & Access Management

Dreamforce 2026 to Pitch Unified Agent Trust as Market Still Runs on Three Separate Layers

Salesforce is positioning its Trust Boundary as the definitive architecture for the agentic enterprise at Dreamforce 2026, but the trust stack has not coalesced into a single platform and has instead fractured into three distinct, often incompatible domains: governance specification, runtime authority, and runtime enforcement. Governance specification remains a crowded, nascent field where enterprises cobble together stacks from vendors like Okta, IBM, Broadcom, and Dataiku, a focus supported by the UC Berkeley MAST taxonomy finding that 79% of multi-agent failures trace to specification problems rather than model limitations. Runtime authority is shifting from static permissions to dynamic models, with Akeyless introducing intent-based access control and CrowdStrike pushing SPIFFE-based identities, though Akeyless CEO Oded Hareven says there is still no single place issuing, governing, and revoking that authority. Runtime enforcement, the domain of bidirectional API security and agent fabrics, was recently exemplified by the expanded integration between Akamai and MuleSoft, and matters because 87% of organizations reported an API security incident in 2025. Despite the marketing at Dreamforce, no single vendor covers all three layers, and the unified solution is in practice a multi-vendor assembly project, a fragmentation that feeds a merchant readiness paradox in which 42% of merchants are testing agentic systems while only 3% of transactions actually involve agents. Gartner warns that 40% of autonomous AI efforts will be partially derailed by governance gaps discovered only after production incidents, and with Nvidia's $12.9 billion acquisition of Hugging Face and Stripe's $7.5 billion acquisition of OpenRouter, the industry's largest acquirers are buying routing infrastructure at premium valuations, signaling that the orchestration layer's fragmentation is itself the margin risk.
Yahoo Finance·5dRead more →
Workforce & Customer IAM (SSO/MFA)

UK's Revolut Mistakenly Gave Customer Data to Fake Government Emails, Including Bitcoin Transaction History

British fintech company Revolut responded to information disclosure requests impersonating government agencies and handed over some customers' personal and financial information to third parties, it has emerged. The Crypto Times, a crypto-focused media outlet based in Dubai, UAE, and India, reported the matter on September 12. The information provided reportedly included copies of passports and Bitcoin transaction histories. The emails requesting the disclosure came from unauthorized accounts created within domains actually used by government agencies and carried legitimate domain authentication credentials, leading Revolut to judge them as formal requests and provide customer information. The company said that after providing the information it contacted the government agencies directly to confirm the legitimacy of the requests, and after discovering the existence of the fraudulent email accounts, it blocked the addresses in question on its internal systems and reported the matter to the relevant regulators. Mark Karpelès, former CEO of Mt.Gox, was reportedly one of the customers who received a notification on September 12. The number of affected customers and the name of the government agency that was impersonated have not been disclosed, nor is it clear when the information was handed to third parties or whether it has since been misused.
NADA NEWS·6dRead more →
Identity & Access Management

PhillipCapital Downgrades Palo Alto Networks to Neutral, Raises Target to $346

PhillipCapital downgraded Palo Alto Networks to Neutral from Accumulate on September 7, while raising its price target to $346 from $320. The call captures the central debate on the cybersecurity company: its AI and platformization opportunity is compelling, but a roughly 160% stock rally from its February low to its August peak has raised the bar for further gains. Palo Alto's revenue rose 34% year over year to $3.4 billion in its fiscal 2026 fourth quarter, and Next-Generation Security ARR surged 63% to $9.10 billion, with nearly $1 billion of net new NGS ARR added in the quarter and more than 65% of that ARR coming from platformized customers. For fiscal 2027, management expects NGS ARR growth of 22% to 23% and revenue growth of 23% to 24%, though it still expects 63% NGS ARR growth in the fiscal 2027 first quarter, and it targets $20 billion in NGS ARR by fiscal 2030. PhillipCapital rolled its valuation forward and lifted its weighted average cost of capital to 5.2%, citing higher debt and a larger share count following acquisitions, while hedge funds holding the stock rose to 89 in the second quarter from 87 in the first and short interest reached 22.4 million shares, or 2.79% of the public float, as of August 14.
Insider Monkey·6dRead more →
Workforce & Customer IAM (SSO/MFA)

ManageEngine warns of Synthetic Identity as AI and Deepfake accelerate financial fraud

ManageEngine has revealed that the financial world is on heightened alert against fraud using fake identities, or Synthetic Identity, after cybercriminals upgraded their tactics to use Deepfake to create virtual identities that pass facial-scan verification. Nattawich Wongsirojn, Regional Technical Head of ManageEngine, stated that detecting synthetic identities has become harder because of the use of AI tools and automated financial systems, combined with rising data leaks, causing massive damage to organisations across banking, fintech, telecommunications and other businesses. Meanwhile, the Electronic Transactions Development Agency, or ETDA, warns that Deepfake technology could weaken Digital ID and e-KYC systems that rely on facial recognition, opening a channel for criminals to verify false identities. In Thailand, as of December 2025, banks had suspended services for more than 223,000 individuals suspected of fraudulent behaviour and frozen more than 3.47 million mule accounts, while the time taken to identify and close mule accounts fell from about 3 days in January 2025 to just 10 hours in July. ManageEngine proposes five points for tackling this threat, from using AI to detect anomalies and multi-level identity verification to cooperation between the public and private sectors and a legal framework that keeps pace with advancing fraud techniques.
Money & Banking·7dRead more →
Identity & Access Management

Nvidia and CrowdStrike Unveil SafeMind Agentic Cybersecurity System

Nvidia and CrowdStrike unveiled SafeMind, an agentic cybersecurity system built on Nvidia Nemotron models and technology from CrowdStrike's Cyber Superintelligence Lab, at CrowdStrike's Fal.Con 2026 conference. Nvidia described the architecture as a continuous loop in which offensive and defensive AI systems challenge and improve one another. Nvidia CEO Jensen Huang reinforced the thesis on September 10 at Goldman Sachs' Communacopia + Technology Conference, arguing cybersecurity is a natural successor to AI coding because defensive systems can operate continuously rather than waiting for a human prompt. For CrowdStrike, AI is simultaneously creating a threat and a product opportunity, since attackers can automate vulnerability discovery, phishing, malware development and lateral movement, while CrowdStrike's endpoint and identity telemetry gives its AI agents proprietary context. For Nvidia, cybersecurity creates a potentially attractive inference workload, as security agents may operate continuously across millions of endpoints, generating recurring demand for inference rather than one-time model training. Hedge-fund ownership of CrowdStrike rose to 89 funds in Q2 from 79 in Q1, while Nvidia rose to 285 from 275, and short interest stood at about 2.4% of CrowdStrike's float and 1.2% of Nvidia's float as of August 14.
Insider Monkey·7dRead more →
Workforce & Customer IAM (SSO/MFA)

Okta Shares Outpace S&P 500 as Earnings Estimates Rise

Okta shares have returned +10.4% over the past month, outpacing the Zacks S&P 500 composite's -2% change, while the Zacks Security industry, to which Okta belongs, lost 7.8% over the same period. The cloud identity management company is expected to post earnings of $0.93 per share for the current quarter, a year-over-year change of +13.4%, and the Zacks Consensus Estimate has moved +6.2% over the last 30 days. For the current fiscal year, the consensus earnings estimate of $3.93 indicates a year-over-year change of +12.3% and has changed +9.8% over the last 30 days, while the next fiscal year's consensus estimate of $4.44 indicates a change of +13% and has changed +3.5% over the past month. Okta's consensus sales estimate of $815.52 million for the current quarter points to a year-over-year change of +9.9%, with the $3.22 billion and $3.55 billion estimates for the current and next fiscal years indicating changes of +10.4% and +10.1%, respectively. In the last reported quarter, Okta reported revenues of $805 million, up +10.6% year over year, and EPS of $1.05 versus $0.91 a year ago, beating the Zacks Consensus Estimate of $792.14 million by +1.62% on revenue and by +9.38% on EPS; the company is rated Zacks Rank #3 (Hold) and graded F on the Zacks Value Style Score.
Zacks Investment Research·7dRead more →
Workforce & Customer IAM (SSO/MFA)

Yod Chinsupakul elected President of TEPA, pushing to raise electronic payment standards

Yod Chinsupakul, Chief Executive Officer of LINE MAN Wongnai and LINE Pay Thailand, has taken up the post of President of the Thai E-Payment Trade Association, or TEPA, which has more than 30 member service providers. He announced a direction to raise the security of Thailand's electronic payment systems under a cooperation framework to prevent illegal transactions in the financial sector of the Bank of Thailand, of which TEPA is one of 11 participating agencies. The work will be driven through three key principles: elevate, make difficult, and act quickly, covering the raising of screening standards, making it harder to exploit the system for wrongdoing, and speeding up information exchange and system adjustments to keep pace with new forms of threats. TEPA's role in the framework includes raising the screening of both major and sub-merchants, strengthening identity verification of e-money users and electronic fund transferors, linking proactive surveillance data to regulators, and joining forces with the Bank of Thailand and member networks through operational-level working groups and coordinators.
Prachachat·7dRead more →
Identity & Access Management

Japan finds hacked servers at Digital Agency, risking data leak for 246,000 people

Japan's Digital Agency disclosed that its servers were accessed without authorization, potentially exposing the personal data of about 246,000 citizens and related individuals. Large-scale file access was detected on the Government Solution Service network, or GSS, in late June through an account used for system maintenance. An investigation found that attackers exploited a vulnerability in a virtual private network, or VPN, to gain access to the system and may have stolen data belonging to civil servants and others using the network. The potentially leaked data includes names, email addresses, and phone numbers, but so far no evidence has confirmed that the data was misused. The incident comes amid increasingly severe cyberattacks in Japan, with the National Police Agency reporting that in the first half of 2026 Japan saw 123 ransomware attacks, the highest number in any six-month period since the government began keeping such statistics.
Money & Banking·7dRead more →
Identity & Access Management

Salesforce Unveils Trusted Enterprise AI Harness for Agent Governance

Salesforce announced its Trusted Enterprise AI Harness on September 10, 2026, formalizing the agent governance stack into a single platform. The Harness comprises six core capabilities: Trusted Context, Trusted Agency, Trusted Action, Trusted Governance, Trusted Security, and Trusted Models, anchored by a new AI Control Plane that lets organizations discover and register agents, establish identity and policy, manage lifecycles, evaluate performance, and control costs. The control plane is designed to manage both Salesforce and third-party AI agents, following the recent Claudeforce initiative that made Anthropic's Claude the default reasoning engine across the platform. Rohan Kumar, Salesforce's President and Chief Platform and Engineering Officer, said the Agentic Enterprise won't be defined by which model a company chooses but by the trusted, proprietary context it brings to that intelligence. The Harness is not scheduled for general availability until early fiscal year 2028, which begins in February 2027, and pricing details have not been disclosed.
Yahoo Finance·8dRead more →
Identity & Access Management5

Mastercard, Visa and Ant International Launch AI Agent Identity Initiative

Mastercard unveiled a Know-Your-Agent initiative with Visa and Ant International on Thursday, aimed at letting merchants trust software that shops on a customer's behalf. Through the Monetary Authority of Singapore-backed BuildFin.ai platform, the companies plan to connect Mastercard Verifiable Intent, Visa's Trusted Agent Protocol and Ant International's Agentic Mobile Protocol, so card networks, digital wallets, marketplaces and AI platforms can identify approved purchasing agents without surrendering control of their own authorization rules. Mastercard handled 47.4 billion switched transactions last quarter and generated $9.28 billion in revenue. AI agents could eventually bring more purchasing activity onto its network, but they also raise the question of who pays when autonomous software authorizes the wrong transaction. Investors still lack an adoption timetable, a defined revenue model and clear rules for allocating losses.
GuruFocus·8dRead more →
Identity & Access Managementimpact 4

Palo Alto Networks Posts 63% NGS ARR Growth but $282M GAAP Net Loss

Palo Alto Networks reported fiscal fourth-quarter revenue of $3.41 billion, up 34% year over year, alongside a $282 million GAAP net loss after earning $254 million a year earlier. Next-Generation Security annual recurring revenue rose 63% to $9.10 billion, though the company said the increase is not an organic growth rate because the current portfolio includes acquired identity and observability businesses absent from the prior-year base, and remaining performance obligations climbed 34% to $21.2 billion. GAAP operating income fell to $172 million from $497 million, cutting GAAP operating margin to 5.0% from 19.6%, while company-defined non-GAAP operating income reached $1.01 billion and non-GAAP net income was $853 million. The quarter's operating reconciliation included $487 million of share-based compensation-related charges, $281 million of acquired-intangible amortization and $68 million of acquisition-related costs, and the net-income gap also reflected a $524 million fair-value change in convertible senior notes acquired in the CyberArk transaction. Operating cash flow rose to $1.36 billion from $1.02 billion, and management guided fiscal 2027 revenue of $14.10 billion to $14.20 billion, growth of 23% to 24%, with NGS ARR expected to reach $11.075 billion to $11.175 billion, up 22% to 23%.
Insider Monkey·8dRead more →
Identity & Access Management

Atsign and Intel Claim 88x Encryption Speedup for Edge AI

Atsign announced that, working with Intel, it has solved the encryption bottleneck holding back autonomous Edge AI agents, achieving a performance uplift of approximately 88x for hardware-accelerated, end-to-end encrypted Agent-to-Agent communications. The two companies co-published a Smart Transportation Solution Brief titled "Securing Agentic AI at the Edge for Smart Transportation," which details zero-trust Agentic AI benchmarks showing the uplift varies by hardware: roughly 88x on Intel Xeon, up to 5 Gbps, and roughly 60x on Intel Core Ultra 9, up to 6 Gbps. The solution pairs Atsign's trusted identity management, namespace isolation, scoped data sharing, end-to-end encryption and auditability with Intel's hardware-backed key generation, accelerated encryption and hashing, protected key storage, secure boot, Trusted Compute, Total Memory Encryption and Full Disk Encryption. Atsign CEO Aparna Rayasam called the result a performance breakthrough and a game-changing evolution for systems where AI-enabled devices must operate autonomously at the edge. Intel has also added Atsign to its Industrial Builders partner program, giving Intel customers access to Atsign's pre-validated solutions, streamlined sourcing, compliance assurance and direct collaboration on RFPs, reference architectures and proof-of-concept deployments.
GlobeNewswire·8dRead more →
Identity & Access Management

ServiceNow Touts AI Control Tower as AI Business Grows Ninefold

ServiceNow outlined its enterprise AI "Control Tower" strategy at the Goldman Sachs Communacopia Conference, with CEO Bill McDermott describing a common platform that integrates AI agents, data, identity, security and workflows for governance, visibility and auditability. McDermott said the company's AI business has grown ninefold in nine months, its agents have generated $1 billion in value and eliminated about 2.5 million hours of employee work, and its customer relationship management business is doubling year over year and has crossed $2 billion in annual contract value. He said ServiceNow's security operations business has surpassed $1 billion, and the company is broadening its security platform through Armis, which provides visibility into IT, internet-of-things and operational-technology assets, and Veza, which contributes identity capabilities. McDermott said the average enterprise uses 47 security tools, creating a "point solution mess," and that ServiceNow manages 7 billion devices with another 40 billion expected to come into scope in the next several years. He also said ServiceNow acquired Moveworks in April 2025, with the deal closing in December, and cited customer examples including Robinhood, where agents manage 70% of cases previously handled by people, and Starbucks, which is converting at least 4,000 U.S. locations to ServiceNow Customer Service Management.
MarketBeat·8dRead more →
Identity & Access Management5

Bank of Thailand Joins 11 Financial Associations in Pledge to Curb Gray Capital

The Bank of Thailand, together with financial business operators under its supervision and 11 associations, announced a declaration of intent and a proactive cooperation framework to prevent illicit transactions in the financial sector, known as the Framework for Safeguarding the Financial Sector from Illicit Activities, at a press conference titled "One Intent, United Strength, Protecting Thailand's Financial Sector" on September 10, 2026. Mr. Vitai Ratanakorn, Governor of the Bank of Thailand, said the signing was not merely an MOU or a symbolic gesture, but an agreement with a clear commitment that all parties must genuinely act to raise supervisory standards. The 11 bodies that jointly drafted the cooperation framework are the Thai Bankers' Association, the Association of International Banks, the Government Financial Institutions Association, the Thai E-Payment Association, the Thai Foreign Exchange and Financial Services Association, as well as six associations and clubs of non-bank lenders. They will jointly raise the level of KYC, CDD and EDD, scrutinize high-risk cash transactions, deploy advanced technology to proactively detect abnormal transactions, develop a database of high-risk individuals and connect it to the Central Fraud Registry, produce industry AML/CFT manuals, and use community networks to build financial immunity for vulnerable groups. Mr. Vitai also disclosed that past measures have begun to show concrete results. Requiring that cash withdrawals exceeding 5 million baht undergo screening and verification reduced cash withdrawals in the portion above 5 million baht from about 100 billion baht a month to about 4 billion baht. Meanwhile, supervision of withdrawals and online gold trading above 50 million baht, or gold bars above 2 kilograms, cut such gold withdrawals by about 70 percent. He expects that in October 2026, a measure will take effect requiring those depositing 5 million baht or more in cash to explain the source of funds and provide evidence. At the same time, the Securities and Exchange Commission is in the process of holding a public hearing on regulatory criteria for USDT, with an announcement expected in the next few months. For the next phase, the Bank of Thailand is preparing to upgrade cooperation among five key agencies, namely the Bank of Thailand, the Securities and Exchange Commission, the Anti-Money Laundering Office, the National Anti-Corruption Commission, and the Royal Thai Police, in order to exchange information systematically and across the whole country.
Money & Banking·8dRead more →
Identity & Access Management2

Bank of Thailand Joins Forces with 11 Financial Bodies to Set Joint Framework Against Illicit Transactions

The Bank of Thailand and 11 supervised business associations are jointly driving a cooperative framework to prevent illicit transactions in the financial sector, known as the Framework for Safeguarding the Financial Sector from Illicit Activities, aimed at proactively preventing the financial sector from becoming a channel that supports illegal activity. Mr. Vitai Ratanakorn, Governor of the Bank of Thailand, said the key principle is for all agencies to set direction, policy, and corporate governance to prevent misuse of the financial system, with minimum standards appropriate to each business and continuous improvement of measures as circumstances change. Participating agencies will bring their expertise in data, technology, and capabilities to monitor, detect, and respond to risks, and will exchange information, knowledge, patterns of wrongdoing, warning signals, and best practices among themselves. The businesses that have established this cooperative framework comprise 11 bodies: the Thai Bankers' Association, the Association of International Banks, the Government Financial Institutions Association, the Thai E-Payment Association, the Thai Foreign Exchange and Financial Services Association, as well as six associations and clubs of non-commercial bank business groups. Together they will raise the standard of KYC, CDD, and EDD; scrutinise high-risk cash transactions; deploy advanced technology to proactively detect abnormal transactions; develop a database of high-risk individuals; connect with the Central Fraud Registry; produce industry AML/CFT manuals; and use community networks to build financial immunity for vulnerable groups.
InfoQuest·8dRead more →
Workforce & Customer IAM (SSO/MFA)3

Trezor Users Hit by Convincing Phishing Attack After Third-Party Email Breach

Trezor users have been targeted by an unusually convincing phishing campaign after attackers compromised a third-party email provider used by the hardware wallet manufacturer. The breach occurred at the third-party email provider rather than at Trezor itself, and the attackers leveraged that access to send fraudulent messages to the company's user base. The campaign is being described as unusually convincing, raising concerns that recipients could be tricked into compromising their wallet credentials or funds. No further details on the number of users affected or the specific contents of the phishing messages were provided.
U.Today·8dRead more →
Workforce & Customer IAM (SSO/MFA)2

Ransomware Attacks Hit Record 123 Cases in First Half, NPA Releases Threat Assessment

The National Police Agency on the 10th released its assessment of the cyber threat landscape, revealing that 123 cases of ransomware, malware that encrypts data for ransom, were confirmed in the first half of this year from January to June, the highest for any half-year period since statistics began being kept in 2020. Reports of damage rose by 7 cases compared with the same period last year, with 31 of them involving large companies. More than half of all victims took a month or longer to recover, nine companies saw all operations halted, and in 60 percent of cases the damage exceeded 10 million yen. Suspicious accesses detected by the agency surged to about 13,700 per day in the first half, 1.5 times the level of a year earlier, and the agency said the sources of ransomware and other attacks may be probing devices for vulnerabilities. Losses from internet fraud rose 45 percent year on year to 175.5 billion yen, the worst pace on record, while reports of phishing, in which fake emails lure users into giving up passwords and other information, totaled about 730,000, with analysis estimating that 45 percent of the servers sending them were located in China, followed by Japan at 14 percent and Brazil at 10 percent.
Jiji Press·9dRead more →
Workforce & Customer IAM (SSO/MFA)2

SailPoint raises FY2027 ARR target to $1.38B, outlines FY2029 goals

SailPoint reported fiscal Q2 2027 ARR of $1.231 billion, up 25% year-over-year, and raised its full-year ARR guidance to $1.38 billion while reiterating long-term targets of at least $2.1 billion ARR and at least $800 million in AI-driven ARR by fiscal 2029. The company's AI-driven ARR has already crossed $70 million, and SaaS ARR grew 36% to $847 million, representing 97% of net new ARR. Management highlighted the launch of SailPoint Identity Security with generally available Agentic Fabric, the acquisition of Entro Security, and new connectors for Snowflake, Databricks, and Cursor. CFO Brian Carolan guided Q3 ARR to $1.29 billion, revenue to $328 million, and adjusted EPS of $0.07 to $0.08, while noting that a higher SaaS mix creates a temporary revenue timing headwind of approximately $5 million.
Seeking Alpha·9dRead more →
Workforce & Customer IAM (SSO/MFA)

Visa Unveils Singapore Security Roadmap 2026 to Combat AI-Driven Fraud

Visa has unveiled its Singapore Security Roadmap 2026 and Beyond, a comprehensive strategy to strengthen the resilience of Singapore's digital payments ecosystem against evolving fraud, scams, and cyber threats. The roadmap outlines six strategic priorities, including strengthening cybersecurity, advancing authentication, enabling safer transactions through tokenisation, transforming eCommerce checkout experiences, leveraging foundational standards and risk programs, and building a resilient payments ecosystem to combat fraud and scams in the AI era. Visa's study shows that close to seven in 10 Singapore residents trust digital payments, but 42 per cent have encountered scams, with only 8 per cent losing money. To address these threats, Visa is investing in AI-powered fraud detection, tokenisation, and authentication innovations like passkeys and biometrics, deploying over 150 AI and machine learning models globally. The roadmap emphasizes ecosystem-wide collaboration with regulators, financial institutions, merchants, and fintechs to enhance cyber resilience and intelligence sharing.
PR Newswire·10dRead more →