1. Executive Summary (TL;DR)


2. Top IAM & Security News

ADT Confirms 5.5M-Record Breach After Vishing → Okta SSO → Salesforce Chain

CISA Adds cPanel/WHM Authentication Bypass (CVE-2026-41940) to KEV Catalog

CISA, FBI, DOE, DOS, and DoW Publish Joint Zero Trust Guidance for OT

Microsoft Begins Rolling Entra Passkeys to All Windows Devices

Microsoft Sentinel UEBA Expands to AWS, GCP, and Okta

Vercel Incident Traced to Context.ai OAuth Supply Chain


3. AI, Identity & Emerging Tech

AI Agents Get First-Class Identity Treatment From Hyperscalers

Non-Human Identities Outnumber Humans by 40:1 to 100:1

AI-Powered Vishing Becomes a Repeatable Breach Pattern


4. Cyber Threats & Attack Trends

Vishing → Federated SSO Takeover (ADT pattern)

Pre-Auth Bypass for Privileged Hosting Identity (cPanel CVE-2026-41940)

OAuth Supply Chain Pivoting

Infostealer-Fueled Identity Takeover


5. Product Updates & Vendor News

Microsoft Entra

Microsoft Sentinel

Okta

cPanel (WebPros)

Google Cloud / Wiz


6. Notable Research & Reports

CISA Joint Guide — "Adapting Zero Trust Principles to Operational Technology" (April 30, 2026)

Verizon 2026 DBIR — Identity-Centric Findings

State of NHI and AI Security (referenced this week)


7. Practical Security Takeaways

  1. Treat the help desk as Tier 0 identity infrastructure. Mandate phishing-resistant, out-of-band proof (FIDO2/passkey or video-call with verified ID) before any MFA reset, password reset, or SSO recovery. The ADT attack chain dies at this control.
  2. Patch CVE-2026-41940 today. If you run cPanel/WHM directly or via a hosting provider, confirm the April 28 patch is applied, audit for indicators of compromise back to late February, and rotate any administrative credentials and API tokens that traversed those hosts.
  3. Inventory and prune third-party OAuth grants. Pull the list of SaaS-to-SaaS OAuth grants in Microsoft 365, Google Workspace, Salesforce, Snowflake, and your code/CI platforms. Revoke anything unused, scope down anything broader than needed, and add OAuth grant changes to your monitoring.
  4. Roll passkeys to Windows now, not "later this year." Microsoft has removed the last excuses by extending Entra passkeys to shared and unmanaged Windows devices. Stage rollout to high-risk roles (admins, finance, exec assistants, help desk) first.
  5. Fold Okta (and any non-Microsoft IdP) into your UEBA. Sentinel UEBA now ingests Okta; if you use a different SIEM/XDR, ensure Okta system logs feed it with the same anomaly rules you run on Entra. Cross-IdP correlation is what would have flagged the ADT session takeover earlier.
  6. Establish an AI-agent identity policy before agents proliferate. Define how agents get created, who owns them, what scopes they can hold, how their actions are logged, and how they are revoked. 78% of organizations have no such policy — do not be one of them.
  7. Assume infostealer compromise of contractors and small SaaS vendors. Vercel/Context.ai shows that a Lumma infection on a vendor's laptop two months ago can become your incident this week. Require that vendors with OAuth into your tenant maintain endpoint detection and rotate refresh tokens regularly.
  8. Apply CISA's Zero Trust OT guidance to your OT roadmap. Even if you are not directly mandated, the document is now the reference text — adopting it preempts insurer and regulator pressure.
  9. Monitor for vishing precursors. Pretexting reconnaissance against help desks and finance often precedes the actual call. Detect rising volumes of failed verification questions, repeated callback requests, and out-of-hours HR/IT impersonation attempts.
  10. Reduce overprivileged Okta admin and Salesforce profile counts. ADT lost 5.5M records because a single SSO identity could reach the customer dataset in Salesforce. Apply least-privilege at the IdP and within each major SaaS app simultaneously.

8. Trends to Watch


9. Tool / Resource of the Week

CISA — "Adapting Zero Trust Principles to Operational Technology" (joint guidance, April 30, 2026)


10. Sources