1. Executive Summary (TL;DR)


2. Top IAM & Security News

1. FBI warns of "Kali365" PhaaS hijacking Microsoft 365 via OAuth device-code flow

The FBI's IC3 issued a public service announcement on the Kali365 phishing-as-a-service platform — distributed via Telegram (~$250/month per tenant), first seen April 2026 — that abuses Microsoft's legitimate OAuth 2.0 device-code authorization flow. Victims are lured (fake Adobe Acrobat Sign, DocuSign, SharePoint emails) into entering an attacker-supplied device code on an authentic Microsoft verification page; MFA fires on the victim's own device while the attacker captures the resulting access and refresh tokens. The kit ships AI-generated lures, automated campaign templates, and real-time victim dashboards, and has hit manufacturing, education, insurance, financial, healthcare, and government targets across North America, Europe, the Middle East, and Africa.

2. Palo Alto GlobalProtect auth-bypass (CVE-2026-0257) exploited, added to CISA KEV

CVE-2026-0257 is an authentication bypass in PAN-OS GlobalProtect portals/gateways. When a device reuses the same certificate for HTTPS and authentication-override cookies, an attacker can extract the public key and forge valid override cookies for any user account — establishing an unauthorized VPN session with no credentials. Rapid7 observed successful exploitation across multiple customers beginning May 17, 2026, with follow-on waves on May 18 and May 21. CISA added the flaw to its Known Exploited Vulnerabilities catalog on May 29, with a June 1 federal remediation deadline, and the severity was raised from Medium to High once exploitation began.

3. Carnival breach exposes ~6M people after social-engineered employee account

Carnival Corporation began notifying roughly 5.99M individuals that their data was stolen in an incident identified April 14, 2026. Attackers gained access to an employee's account via social engineering, pivoted into company systems, and exfiltrated files containing names, addresses, dates of birth, email addresses, phone numbers, and government-issued ID numbers. The extortion group ShinyHunters claimed responsibility, alleging theft of 8.7M records; Carnival is offering 24 months of credit monitoring.

4. CrowdStrike: "Mutant Spider" dominates financial services with reset-MFA vishing

Analysis of CrowdStrike's 2026 Financial Services Threat Landscape Report identified Mutant Spider as the sector's most active threat actor, with its primary technique being voice phishing over Microsoft Teams — operators impersonate internal IT support, convince employees to reset credentials and MFA, then register their own devices on the corporate network. The coverage pairs this with the FBI's Kali365 warning, framing the two dominant patterns as "remove MFA via social engineering" and "capture the post-auth token."

5. MFA prompt bombing: why a second factor alone isn't saving you

A widely-shared analysis dissected MFA prompt bombing (push fatigue): attackers who already hold valid credentials spam push prompts and pair them with vishing calls posing as IT support to coerce approval. Push notifications carry no context about request origin, device, or legitimacy, making errant approval likely — the same technique behind the 2022 Cisco breach. Recommended defenses: replace push with phishing-resistant factors (FIDO2 keys, hardware tokens, number matching), screen Active Directory against breached-password datasets, and apply Conditional Access on geography, device posture, and login timing.

6. "OnlyFans" 340M-record leak shows identity exposure is cumulative

A threat actor advertised ~340M "OnlyFans" user records (usernames, emails, phone numbers, follower counts, linked social profiles) for ~$76,000 in Bitcoin. The seller admitted the data was not exfiltrated from OnlyFans but assembled by cross-referencing older breaches (Twitter, Instagram, Spotify) and matching them to profiles; OnlyFans denied any breach and payment-card claims were unverified.

7. New infosec products of the month surface NHI and agentic-AI access governance

Help Net Security's May product roundup highlighted identity-relevant launches: XM Cyber Continuous Exposure Management for Identities (credential security and IAM attack-surface reduction tuned for AI-enabled attackers), Trust3 AI MCP Security (a unified trust layer governing non-human/agentic AI identity access to business data and systems), and LastPass Mobile Smart Scanner (OCR of credentials into the vault).


3. AI, Identity & Emerging Tech

CSA State of AI Cybersecurity 2026: agents must be governed as identities

CSA's research found 92% of security professionals concerned about AI agents' workforce impact, with 61% naming sensitive-data exposure their top worry — yet only 37% report having formal AI policies in place (down year over year). The report's framing is the headline for IAM teams: agents frequently receive broad cross-system permissions and "must be governed as identities, with least-privilege access and ongoing monitoring."

Orchid Security targets "Agent AI Authority Gap" with delegation-chain visibility

Orchid launched three agent-focused capabilities — Agentic Enrichment (maps agents to originating identities, owners, applications, and inherited permissions), Agentic Observability (tracks the full delegation chain behind each agent action), and Agentic Guardrails (enforces least privilege and identity hygiene). Orchid frames the core risk as the gap between what enterprises think is governed and what agents can actually execute, citing that two-thirds of enterprises already run agents in production while 67% of non-human accounts are locally managed and invisible to central IAM.

MASQ framework extends agent governance to MCP servers and context windows

Integrated Cyber Solutions (d/b/a Integrated Quantum Technologies) announced MASQ (Machine Action Security Quotient), a governance framework for autonomous agents, and began a patent process. MASQ governs four areas: what actions an agent is authorized to perform, what systems and data it can reach, how it interacts with APIs, external tools, and MCP servers, and how sensitive data inside an agent's context window and reasoning environment is protected during machine-to-machine interaction.

Didit raises $6M for AI-native identity infrastructure

Didit raised a $6M seed (total $7.5M, with Y Combinator, Pioneer Fund, and Orange Collective participating) to build programmable identity infrastructure that verifies people, businesses, and digital actions taken by AI agents via developer APIs analyzing 200+ signals across 220+ countries — working toward an identity wallet supporting both human and agent identities.

Trends crystallizing this week: non-human identities (NHIs) outnumbering and outpacing human ones; autonomous agents acquiring delegated authority faster than governance; identity sprawl into application-local accounts invisible to central IAM; and a shift toward behavioral/continuous identity models (ITDR) to watch what agents and humans actually do post-authentication.


4. Cyber Threats & Attack Trends

1. OAuth device-code token theft (Kali365)

2. Reset-MFA-via-vishing (Mutant Spider)

3. Credential-less VPN authentication bypass (CVE-2026-0257)

4. Social-engineered employee account → mass data exfiltration (Carnival / ShinyHunters)

5. MFA prompt bombing / push fatigue


5. Product Updates & Vendor News

Salesforce — phishing-resistant MFA mandated for privileged users

Salesforce confirmed all privileged users (System Administrators and holders of Modify All Data, View All Data, Customize Application, or Author Apex) must authenticate with phishing-resistant MFA starting June 22, 2026 in sandboxes and July 1, 2026 in production. Only FIDO2/WebAuthn built-in authenticators (Touch ID, Face ID, Windows Hello) and hardware security keys qualify; authenticator apps, push, and TOTP no longer count for these roles. The setting is locked so it can't be disabled, and unregistered admins are blocked at login.

Yubico — YubiKey 5 FIPS Series achieves FIPS 140-3 validation

Yubico's next-gen YubiKey 5 FIPS Series received FIPS 140-3 validation (Certificate #5291) on 5.7.4 firmware, with expanded algorithm support (RSA-3072, RSA-4096, Ed25519). It remains the only authenticator recognized in U.S. DoD guidance authorized to hold both DoD PKI/PIV credentials and FIDO2 passkeys on a single device, alongside OpenPGP and OATH OTP.

CrowdStrike — named Leader and Fast Mover in 2026 GigaOm Radar for ITDR

CrowdStrike was named Leader and Fast Mover in the 2026 GigaOm Radar for Identity Threat Detection and Response (ITDR), with perfect scores in non-human identity security, risk-adaptive access controls, AI-enhanced SecOps, and automated incident response. GigaOm highlighted cross-domain correlation — enriching identity telemetry with endpoint, cloud, and SaaS data via Falcon and Next-Gen SIEM.

Orchid Security, XM Cyber, Trust3 AI, LastPass — NHI & agentic-AI launches

Beyond Orchid's agent identity-governance suite (Section 3), the May product cycle brought XM Cyber Continuous Exposure Management for Identities, Trust3 AI MCP Security (governing non-human/agentic access to business data), and LastPass Mobile Smart Scanner.


6. Notable Research & Reports

Verizon 2026 Data Breach Investigations Report (DBIR)

In-window analysis of the new DBIR (31,000+ incidents, 22,000+ confirmed breaches across 145 countries). Identity-relevant findings: humans involved in 62% of breaches; stolen credentials fell to 13% as an initial-access vector while vulnerability exploitation rose to 31% (now the leader); 67% of users accessed AI services with non-corporate accounts on work devices (shadow AI); third-party breaches featured in 48% of breaches (supply-chain breaches up 60%); ransomware in 48% of breaches.

CSA State of AI Cybersecurity 2026

Survey-backed report (see Section 3): 92% concerned about AI agents, 61% worried about sensitive-data exposure, only 37% with formal AI policies — a widening preparedness gap as agents acquire cross-system permissions.

Weekly threat-intel digest — infostealers, DBIR, exploited edge flaws

Help Net Security's May 24 "week in review" curated the period's identity-adjacent research: the DBIR's initial-access shift, a PureLogs infostealer phishing campaign (credential harvesting feeding account takeover), and actively-exploited Microsoft Defender and NGINX vulnerabilities — plus a GitHub compromise via a poisoned VS Code extension (a supply-chain/identity-trust angle on developer tooling).


7. Practical Security Takeaways

  1. Lock down the OAuth device-code flow. Use Conditional Access to block or tightly scope device-code authentication (exclude only break-glass accounts). This is the single highest-leverage control against the Kali365 pattern.
  2. Hunt for stolen tokens, not just bad logins. Inventory OAuth grants, monitor for anomalous refresh-token use, and revoke/rotate sessions on suspicion — MFA at login does nothing for an already-issued token.
  3. Harden the help desk against vishing. Require strong, out-of-band identity verification before any credential or MFA reset, and add friction/alerting to new device registration. This is the control that stops Mutant Spider and Scattered Spider-style intrusions.
  4. Move privileged users to phishing-resistant MFA now. Salesforce's mandate is a preview of the direction — migrate admins and high-risk roles to FIDO2/passkeys or hardware keys ahead of being forced to.
  5. Patch internet-facing identity/edge devices on a KEV clock. Apply the Palo Alto GlobalProtect (CVE-2026-0257) fix and rotate affected certificates; treat VPN/SSO gateway auth bypasses as emergency change.
  6. Govern AI agents as identities. Assign every agent an owner, scope least-privilege access, map its delegation chain, and monitor behavior — don't let agents live as ungoverned service accounts.
  7. Audit and rotate non-human identities. Find application-local accounts invisible to central IAM, assign human ownership per credential, and automate rotation — NHIs are now the fastest-growing and least-governed identity class.
  8. Bring shadow AI under access governance. With ~2/3 of users reaching AI services via personal accounts on work devices, add AI apps to your SSO/CASB inventory and Conditional Access scope.
  9. Screen credentials against breach data and assume cumulative exposure. Check AD against breached-password datasets and treat aggregated-leak risk (e.g., the OnlyFans dataset) as live ammunition for credential stuffing and targeted phishing.
  10. Deploy or mature ITDR. Correlate identity telemetry with endpoint, cloud, and SaaS signals to catch post-authentication attack chains that login-time controls miss.

8. Trends to Watch


9. Tool / Resource of the Week

Microsoft Entra Conditional Access — device-code flow restriction


10. Sources