Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA and NIST issue cloud identity token guidance

Public Sector Action
First reported
Last updated
Happening score
H score 35
1 unique sources, 1 articles

Summary

Hide ▲

CISA and NIST issued final guidance for protecting cloud identity tokens and assertions, setting a federal cybersecurity baseline for federal agencies, cloud service providers, and their customers. The guidance aims to reduce the risk that stolen or forged tokens can be used for lateral movement and access to sensitive data. It is voluntary, but it gives organizations concrete controls for token lifetime, key management, and validation.

Related Happenings

N0va phishing campaign targeting North America and Europe

Campaign
H score36 First: 16.09.2026 14:58 Last: 16.09.2026 14:58 Sources 1

About this happening: N0va is running phishing campaigns across North America and Europe that impersonate trusted services and abuse legitimate authentication flows, creating valid-accoun...

CISA and NIST release IR 8587 cloud identity guidance

Public Sector Action
H score27 First: 15.09.2026 15:00 Last: 15.09.2026 15:00 Sources 1

About this happening: CISA and NIST released IR 8587 to guide federal agencies and cloud service providers on protecting tokens and assertions from forgery, theft, and misuse. T...

U.S. frontier AI companies knowledge distillation mitigation advisory

Advisory/Mitigation
H score31 First: 08.09.2026 15:00 Last: 08.09.2026 15:00 Sources 1

About this happening: CISA, NSA, and FBI issued a joint advisory for U.S. frontier AI companies, warning that knowledge distillation campaigns can strip proprietary model capabiliti...

Greatness PhaaS expands into device code phishing and integrated token-theft operations

Threat Actor Meta
H score40 First: 04.08.2026 20:27 Last: 04.08.2026 20:27 Sources 1

About this happening: Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...

ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations

Campaign
H score34 First: 29.07.2026 20:54 Last: 29.07.2026 20:54 Sources 1

About this happening: The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover...

Timeline

  1. 16.09.2026 17:00 2 articles · 2h ago

    CISA and NIST issue final cloud identity token guidance

    Initial Disclosure

    CISA and NIST issued final guidance in Interagency Report 8587 to protect cloud identity tokens and assertions used for single sign-on (SSO), identity federation and API access. The voluntary guidance targets federal agencies, cloud service providers and the organizations that buy from them, and it recommends shorter token lifetimes, key rotation, isolated key storage, explicit audience fields and rejecting expired tokens to reduce token theft, forgery and misuse.

    Show sources