RC RANDOM CHAOS

identity security

19 posts

Vectra lifted bearer tokens off Teams disk
Article

Vectra lifted bearer tokens off Teams disk

Why Microsoft Teams session tokens leak between workspace and consumer accounts, how bearer-token replay bypasses MFA, and what fires - and doesn't - in telemetry.

The breach was the network working as intended
Article

The breach was the network working as intended

The 2015 Polish S incident: lateral movement from inherited permissions and automated escalation, where access was granted by position not verified at use.

Your access controls are labels, not boundaries
Article

Your access controls are labels, not boundaries

In 2020, elevated access aligned with identity inactivity, then exfiltration attempts. The root failure: access decisions never bound to identity state.

One bearer token, replayed from a residential proxy
Article

One bearer token, replayed from a residential proxy

How attackers abuse OAuth 2.0 at scale via consent phishing, device code flow, and service principal credentials - and why endpoint EDR sees none of it.

Ransomware spreading through trusted accounts
Article

Ransomware spreading through trusted accounts

A novel ransomware variant spread through compromised accounts, exposing identity - not the perimeter - as the boundary that must be enforced at runtime.

Social engineering is a misconfiguration
Article

Social engineering is a misconfiguration

Human error in identity workflows is a misconfiguration, not incompetence - how Scattered Spider, 0ktapus and MFA fatigue exploit the validation gap.

One login screen now guards your entire machine
Article

One login screen now guards your entire machine

Windows 11's forced Microsoft account moves the identity boundary to one access point. Compromise the account and you assume the control, not bypass it.

The scan isn't the story
Article

The scan isn't the story

An AI agent with unchecked access bankrupted its operator. The failure was the execution context, not the scan. A breakdown of the boundary that never held.

GitHub shipped optional hardening as a control
Article

GitHub shipped optional hardening as a control

The GitHub breach follows a documented class of failure. The mechanism is identity issuance separated from validation. The industry chose documentation over enforcement.

Microsoft flags password reset exploitation
Article

Microsoft flags password reset exploitation

Microsoft confirms password reset exploitation. The reset endpoint is an authentication surface and must be controlled as one.

Microsoft sent you a code you didn't request
Article

Microsoft sent you a code you didn't request

An unrequested Microsoft single-use code email is evidence of external interaction with your identity surface. What it proves and what it does not.

AI just broke 2FA at scale
Article

AI just broke 2FA at scale

AI was used to develop a zero-day 2FA bypass deployed at mass scale. The control's economic assumption has been falsified in the wild.