Identity: The Third Phase of Security Operations
ID: 56672751-8a27-515a-859a-c1e901853d9a
STIX ID: report--56672751-8a27-515a-859a-c1e901853d9a
Feed Name: Huntress Blog
This report argues that identity has emerged as a standalone security domain in cloud-first operations, showing how adversaries—from BEC actors to state-linked groups like Storm-0558—are subverting authentication and abusing third‑party identity platforms. It highlights provider-side blind spots (e.g., Azure cross-tenant exposures) and tactics like MFA token theft, urging organizations to demand greater visibility, ingest available identity telemetry, and evolve beyond the traditional host-network paradigm to secure identity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
