Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA and NIST release IR 8587 cloud identity guidance

Public Sector Action
First reported
Last updated
Happening score
H score 27
1 unique sources, 1 articles

Summary

Hide ▲

CISA and NIST released IR 8587 to guide federal agencies and cloud service providers on protecting tokens and assertions from forgery, theft, and misuse. The guidance targets SSO, federation, and API-based access, where compromised identity material can enable lateral movement into sensitive systems. The report is intended to harden cloud identity controls across government-operated and commercial cloud services.

Related Happenings

ShinyHunters and Helix passkey-themed Microsoft 365 account compromise campaign

Campaign
H score34 First: 11.09.2026 20:26 Last: 11.09.2026 20:26 Sources 1

About this happening: A ShinyHunters- and Helix-linked campaign is using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts, exposing Microsoft 3...

ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations

Campaign
H score34 First: 29.07.2026 20:54 Last: 29.07.2026 20:54 Sources 1

About this happening: The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover...

CISA recommends continuous secrets scanning and stronger key management after GitHub leak

Defensive Guidance
H score26 First: 13.07.2026 18:03 Last: 13.07.2026 18:03 Sources 1

About this happening: CISA now recommends continuous secrets scanning and stronger key management after a contractor left internal credentials in a public GitHub repository for nearly *...

CISA zero-trust SASE guidance for TIC 3.0

Public Sector Action
H score30 First: 25.06.2026 14:30 Last: 25.06.2026 14:30 Sources 1

About this happening: CISA published new guidance on June 24 for federal civilian executive branch agencies to replace legacy internet gateways with SASE as part of the move from TIC...

CISA warning on FortiBleed for FortiGate customers

Public Sector Action
H score89 First: 19.06.2026 17:00 Last: 19.06.2026 17:00 Sources 1

About this happening: CISA warned Fortinet customers with FortiGate appliances to secure exposed systems against ongoing malicious activity tied to FortiBleed. The activity had reached...

Timeline

  1. 15.09.2026 15:00 2 articles · 5h ago

    CISA and NIST release IR 8587 for cloud identity token protection

    Initial Disclosure

    CISA and NIST released IR 8587, Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers, to guide federal agencies and cloud service providers in defending identity tokens and assertions used for SSO, federation, and API access. The report expands on NIST SP 800-53 and IA-13 control and recommends stronger token issuance, verification, key management, and lifecycle controls after June 2025 technical exchanges, a January 2026 webinar, and meetings with cloud providers including Google, HashiCorp, IBM, Microsoft, Okta, OpenID Foundation, Oracle, Amazon Web Services, and Wiz.

    Show sources