CISA and NIST issue cloud identity token guidance
Public Sector Action
Summary
Hide ▲
Show ▼
CISA and NIST issued final guidance for protecting cloud identity tokens and assertions, setting a federal cybersecurity baseline for federal agencies, cloud service providers, and their customers. The guidance aims to reduce the risk that stolen or forged tokens can be used for lateral movement and access to sensitive data. It is voluntary, but it gives organizations concrete controls for token lifetime, key management, and validation.
Related Happenings
N0va phishing campaign targeting North America and Europe
Campaign
H score36
First: 16.09.2026 14:58
Last: 16.09.2026 14:58
Sources 1
About this happening:
N0va is running phishing campaigns across North America and Europe that impersonate trusted services and abuse legitimate authentication flows, creating valid-accoun...
N0va phishing campaign targeting North America and Europe
CampaignAbout this happening: N0va is running phishing campaigns across North America and Europe that impersonate trusted services and abuse legitimate authentication flows, creating valid-accoun...
CISA and NIST release IR 8587 cloud identity guidance
Public Sector Action
H score27
First: 15.09.2026 15:00
Last: 15.09.2026 15:00
Sources 1
About this happening:
CISA and NIST released IR 8587 to guide federal agencies and cloud service providers on protecting tokens and assertions from forgery, theft, and misuse. T...
CISA and NIST release IR 8587 cloud identity guidance
Public Sector ActionAbout this happening: CISA and NIST released IR 8587 to guide federal agencies and cloud service providers on protecting tokens and assertions from forgery, theft, and misuse. T...
U.S. frontier AI companies knowledge distillation mitigation advisory
Advisory/Mitigation
H score31
First: 08.09.2026 15:00
Last: 08.09.2026 15:00
Sources 1
About this happening:
CISA, NSA, and FBI issued a joint advisory for U.S. frontier AI companies, warning that knowledge distillation campaigns can strip proprietary model capabiliti...
U.S. frontier AI companies knowledge distillation mitigation advisory
Advisory/MitigationAbout this happening: CISA, NSA, and FBI issued a joint advisory for U.S. frontier AI companies, warning that knowledge distillation campaigns can strip proprietary model capabiliti...
Greatness PhaaS expands into device code phishing and integrated token-theft operations
Threat Actor Meta
H score40
First: 04.08.2026 20:27
Last: 04.08.2026 20:27
Sources 1
About this happening:
Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...
Greatness PhaaS expands into device code phishing and integrated token-theft operations
Threat Actor MetaAbout this happening: Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...
ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations
Campaign
H score34
First: 29.07.2026 20:54
Last: 29.07.2026 20:54
Sources 1
About this happening:
The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover...
ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations
CampaignAbout this happening: The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover...
Timeline
-
16.09.2026 17:00 2 articles · 2h ago
CISA and NIST issue final cloud identity token guidance
Initial DisclosureCISA and NIST issued final guidance in Interagency Report 8587 to protect cloud identity tokens and assertions used for single sign-on (SSO), identity federation and API access. The voluntary guidance targets federal agencies, cloud service providers and the organizations that buy from them, and it recommends shorter token lifetimes, key rotation, isolated key storage, explicit audience fields and rejecting expired tokens to reduce token theft, forgery and misuse.
Show sources
- CISA and NIST Issue Guidance to Protect Cloud Identity Tokens — www.infosecurity-magazine.com — 16.09.2026 17:00
- CISA and NIST Issue Guidance to Protect Cloud Identity Tokens — www.infosecurity-magazine.com — 16.09.2026 17:00