1. Executive Summary (TL;DR)


2. Top IAM & Security News

1. ShinyHunters extorts Instructure / Canvas — 275M education records via SSO + Salesforce

On May 1 Instructure detected unauthorized activity on its Canvas LMS; by mid-week, ShinyHunters (UNC6040) had added Instructure to its leak site claiming exfiltration of 3.65 TB covering ~275M students, teachers, and staff at ~8,800 institutions. Reporting through the week (CNN, NPR, Bitdefender) confirmed exposure of names, school email addresses, student IDs, and private message content, plus a compromised Salesforce tenant. Initial access reportedly came via vishing of help-desk staff to abuse an Okta SSO account.

2. Cisco to acquire Astrix Security (~$400M) — first major Tier-1 bet on agentic identity

Announced May 4. Astrix specializes in discovery and governance of NHIs — service accounts, API keys, OAuth tokens, and AI agents. Cisco will fold it into Cisco Identity Intelligence and extend the capabilities into Cisco Secure Access and Duo IAM, covering agent lifecycle, just-in-time access, secrets management, and runtime threat detection.

3. CVE-2026-0300: PAN-OS User-ID Authentication Portal — unauth RCE, exploited in the wild

On May 6 Palo Alto Networks PSIRT disclosed a buffer-overflow flaw in the User-ID / Captive Portal of PA-Series and VM-Series firewalls (CVSS 9.3) that allows unauthenticated root RCE via crafted packets. CISA added it to KEV the same day. Patches are scheduled to roll out starting May 13 through May 28.

4. MuddyWater (Iran) weaponizes Microsoft Teams external chat for credential & MFA theft

Rapid7 published a write-up this week describing an intrusion at a US-based victim that masqueraded as a Chaos ransomware affiliate but had no encryption payload. The kill chain: external Microsoft Teams chat request → screen-share session → coached "support" walkthrough → credential and MFA-code capture → DWAgent / AnyDesk persistence → lateral movement → data exfil. Attribution tied to MuddyWater via a "Donald Gay" code-signing certificate.

5. ShinyHunters threatens Cushman & Wakefield — 500K+ Salesforce records, May 6 deadline

Continuing the UNC6040 streak, ShinyHunters posted a final-warning leak countdown against Cushman & Wakefield, claiming over 500,000 Salesforce records (PII + internal corporate data) and demanding payment by May 6, 2026. Reported initial access mirrors the Instructure pattern: vishing → compromised SaaS SSO → Salesforce exfil.

6. World Passkey Day 2026 (May 7) — ~5B passkeys in circulation; Microsoft retires legacy password fallback

FIDO Alliance's State of Passkeys 2026 (research across 11,000 consumers and 1,400 enterprise decision-makers in 10 countries) puts global passkeys at ~5 billion, with 75% of consumers having enabled at least one, 68% of organizations deploying for workforce, and 82% naming fully passwordless workforce sign-in as a goal. Microsoft used the day to declare passwords a security risk and roll Entra passkeys onto Windows (GA mid-June). The FIDO Alliance separately announced a workstream on "trusted AI agent interaction" standards.

7. Okta unveils the "2026 Identity 25" — identity reframed as the control plane

On May 4 Okta Ventures published the third edition of its Identity 25, themed identity is the control plane. The report names the 25 builders shaping post-AI-agent identity and bluntly states that authentication alone — even strong MFA — is no longer enough as agentic AI and deepfake-driven impersonation scale.

8. CISA KEV additions: Ivanti EPMM RCE (May 7)

CISA added an Ivanti Endpoint Manager Mobile (EPMM) improper-input-validation vulnerability to the Known Exploited Vulnerabilities catalog on May 7. The flaw lets a remotely authenticated admin achieve RCE on the EPMM server — a high-impact secondary path once an admin credential is phished. Federal agencies have the standard 21-day remediation clock.


3. AI, Identity & Emerging Tech

Cisco–Astrix and the formalization of "agent identity"

The Cisco/Astrix deal (above) cleanly maps onto a new product category: discover every AI agent, map its NHIs and excessive scopes, govern its lifecycle (creation → rotation → decommission), and detect runtime drift like out-of-policy actions or compromised credentials. Expect the language of agent identity to start showing up in Gartner Magic Quadrants and federal procurement.

FIDO Alliance to develop "Trusted AI Agent Interaction" standards

Announced April 27 but the workstream officially picked up momentum on World Passkey Day. FIDO is positioning to define how AI agents authenticate to APIs and SaaS the way it defined how humans authenticate to phones and laptops.

Google Cloud + Wiz: AI-aware extension threat detection and shadow-AI reporting (preview)

Google Cloud Next '26 messaging extended into the week with previews of AI-aware extension threat detection in Security Command Center and shadow AI reporting surfacing unsanctioned employee AI/SaaS use. Wiz announced agent-platform coverage for AWS Agentcore, Gemini Enterprise Agent Platform, Azure Copilot Studio, and Salesforce Agentforce.

Keeper Security: 89% of IT leaders losing the identity-footprint race

Identity Security at Machine Speed (released this week) surveyed global IT/security leaders. Headline numbers: 89% report difficulty managing the growing identity footprint as AI expands; 72% can't detect credential misuse in real time; 46% say AI-powered tools have access to critical systems and 76% of those identities are not consistently governed under PAM policies.


4. Cyber Threats & Attack Trends

a) Vishing → SSO → SaaS data plane (UNC6040 / ShinyHunters)

The Instructure and Cushman & Wakefield breaches share an identity-centric kill chain: voice-phishing of help-desk or support staff → password / MFA reset of an SSO account (most often Okta) → privileged Salesforce or LMS access via OAuth → mass data exfil → leak-site extortion. Vishing now accounts for ~23% of cloud-related initial compromises, ahead of stolen credentials, email phishing, and exploits.

b) Microsoft Teams external-chat social engineering (MuddyWater + Storm-1811 lineage)

Adversaries are moving social engineering off email and into Teams because it bypasses the bulk of email security and inherits Microsoft's trust UI. The MuddyWater intrusion (above) used external chat → screen share → live coaching to defeat MFA — same pattern Storm-1811 used in 2024–25.

c) Identity-edge appliance exploitation (PAN-OS, Ivanti EPMM)

Two KEV additions this week target the very appliances enterprises trust to enforce identity at the perimeter and on mobile devices. Both fit a longer pattern of edge-device privilege escalation that, once chained, yields persistent identity-context access (User-ID mappings, MDM policy push, certificate stores).

d) Signed-installer supply chain attacks (DAEMON Tools)

DAEMON Tools Lite installers signed with the vendor's legitimate certificate distributed backdoors from April 8 through early May 2026. Telemetry across 100+ countries; targeting included government and scientific entities. Code signing failed as a trust anchor because the signing key itself was the compromised identity.

e) Stolen-token persistence after SSO compromise

The Bitdefender and Sentra writeups on Instructure both flagged that even after detecting unauthorized SSO activity on May 1, Instructure's incident timeline shows attackers continuing to operate via valid OAuth tokens — a reminder that revocation must include OAuth/refresh tokens, not just user sessions.


5. Product Updates & Vendor News


6. Notable Research & Reports

FIDO Alliance — State of Passkeys 2026 (May 7)

Surveys of 11,000 consumers + 1,400 enterprise decision-makers across 10 countries. Headline stats: 90% passkey awareness, 75% of consumers enabled at least one, 49% use regularly when available, 68% of orgs deploying for workforce, 82% naming fully passwordless as a goal. Strategic implication: passkey adoption is no longer the question — workforce and agent passkey strategy is.

Keeper Security — Identity Security at Machine Speed (May 2026)

89% of IT leaders struggling with identity-footprint expansion under AI. 72% can't detect credential misuse in real time. 43% globally (51% in US) name AI-related NHI management as a top identity governance gap. 46% of respondents report AI tools have access to critical systems; 76% of those identities not consistently governed.

Okta — 2026 Identity 25 (May 4)

Theme: identity is the control plane. Frames deepfakes and agentic AI as the new dominant threat model and pushes "continuous identity verification" past static MFA.

IBM — X-Force Threat Intelligence Index 2026 (most-cited carryover)

Public-facing app exploitation surged 44%, overtaking stolen credentials as the top entry vector (40% vs 32%) — but stealer-driven credential theft and infostealer logs remain a foundational secondary path (300K+ ChatGPT credentials observed on dark web markets). 109 extortion groups tracked in 2025 (up from 73).


7. Practical Security Takeaways

  1. Patch / mitigate CVE-2026-0300 today. No PAN-OS fix until May 13. Until then: restrict User-ID Authentication Portal to trusted internal IPs only, or disable it where not strictly required.
  2. Disable Microsoft Teams external chat by default (or restrict to allow-listed domains). The MuddyWater intrusion proves the Teams attack pattern is now nation-state grade — not just eCrime.
  3. Treat help-desk identity reset as a critical attack path. Require callback to verified channels + at least one out-of-band factor before resetting MFA or SSO credentials; ban screen-shared MFA workflows; deploy verifiable caller-ID for IT/help-desk reset calls.
  4. Inventory and revoke OAuth tokens after any SSO compromise. Session revocation is not enough — Instructure's timeline shows attackers running on valid OAuth tokens after the user account was already flagged. Build a runbook that revokes app-grant + refresh tokens, not just the session.
  5. Pin and rotate code-signing keys; verify reproducible builds for installers. The DAEMON Tools attack used a valid signature — codesign on its own is no longer a trust anchor.
  6. Build a single NHI / agent identity inventory. Discover every API key, service account, OAuth grant, and AI agent; tag with owner, scope, last-used, and last-rotated. Cisco/Astrix, Okta, and Microsoft will all be selling this in Q3 — but you can start with a spreadsheet now.
  7. Start the Entra passkeys on Windows pilot before June. Phishing-resistant workforce sign-in is the highest-leverage control against the Teams-vishing + Salesforce-vishing pattern dominating Q2 2026 — and the GA window is six weeks away.
  8. Adopt phishing-resistant MFA, not just "any MFA." Per CISA/NSA guidance: FIDO2/WebAuthn / passkeys or PIV/CAC. Push-based MFA and OTP are now actively defeated by vishing + screen-share coaching.
  9. Patch Ivanti EPMM immediately and audit admin sign-in events for the last 14 days for any unusual geos / impossible travel.
  10. Add a SaaS-tenant "blast radius" exercise to your tabletop. Specifically: "if our help desk gets vished and a single Okta admin is compromised, what data — across every SaaS app — is reachable in 60 minutes?" This is now a board-level question.

8. Trends to Watch


9. Tool / Resource of the Week

**CISA + NIST IR 8597 — *Protecting Tokens and Assertions from Forgery, Theft, and Misuse*** (initial public draft).


10. Sources