morphhats-logomorphhats-logomorphhats-logomorphhats-logo
  • Home
  • About me
  • Services
  • My works
  • Contact
  • MorphHats InfoSecure
  • Blog
Blog
✕

Identity

  • Home
  • Blog
  • Identity
  • Filter by
  • Categories
  • Tags
  • Authors
  • Show all
  • All
  • AI & Security
  • Announcements
  • Cloud Security
  • DFIR
  • Digital Forensics & Incident Response
  • Governance & Compliance
  • Security Awareness
  • Threats & Attacks
  • Tools & Techniques
  • Vulnerabilities & Patching
  • Zero Trust
  • All
  • Access Control
  • Agentic AI
  • AI Adoption
  • AI Governance
  • AI Security
  • Artificial Intelligence
  • Attack Surface
  • Attack Techniques
  • Authentication
  • Automation
  • Automotive
  • Awareness
  • Backups
  • BEC
  • Bill C-26
  • Bill C-8
  • Blue Team
  • Business Continuity
  • Canada
  • CCCS
  • CISA Advisory
  • Cl0p
  • Clop
  • Cloud
  • Cloud Security
  • Compliance
  • Conditional Access
  • Configuration
  • Credential Stuffing
  • Credential Theft
  • Critical Infrastructure
  • Culture
  • Data Breach
  • Data Brokers
  • Data Loss
  • Data Privacy
  • Data Protection
  • DDoS
  • Defensible Architecture
  • Detection
  • Detection Engineering
  • DevSecOps
  • DFIR
  • Digital Forensics
  • Double Extortion
  • Edge Devices
  • Education
  • Encrypted Messaging
  • Endpoint
  • Espionage
  • Extortion
  • F5
  • Forensics
  • FortiOS
  • Fraud
  • Governance
  • Government
  • Hardening
  • Help Desk
  • IAM
  • Identity
  • Identity & Access Management
  • Identity Theft
  • Incident Reporting
  • Incident Response
  • Least Privilege
  • Linux
  • LLM
  • Logging
  • Machine Learning
  • Managed File Transfer
  • MFA
  • MICCMAC
  • Microsoft
  • Misconfiguration
  • Misconfigurations
  • MITRE ATTACK
  • MorphHats
  • Multi-Cloud
  • Nation-State
  • Network Security
  • North Korea
  • npm
  • OpenSSH
  • Passkeys
  • Patch Management
  • Patching
  • Persistence
  • Personal Security
  • Phishing
  • Phishing-Resistant
  • PIPEDA
  • Policy
  • Preparedness
  • Prioritization
  • Privacy
  • Prompt Injection
  • Purple Team
  • Ransomware
  • RCE
  • Recovery
  • Regulation
  • Resilience
  • Risk
  • Risk Management
  • Roadmap
  • SaaS
  • Salt Typhoon
  • Scattered Spider
  • Security Architecture
  • Security Automation
  • Security Awareness
  • Segmentation
  • Shadow AI
  • Shared Responsibility
  • SharePoint
  • SIEM
  • Sigma
  • Signing
  • SMB
  • Social Engineering
  • Supply Chain
  • Tabletop
  • Tabletop Exercises
  • Telecom
  • Third-Party Risk
  • Threat Actors
  • Threat Detection
  • Threat Hunting
  • Threat Intelligence
  • Threats
  • Training
  • Validation
  • Vendor Risk
  • Visibility
  • VPN
  • Vulnerability Management
  • Windows
  • Zero Trust
  • Zero-Day
  • All
  • oga
March 10, 2026
March 10, 2026
Categories
  • Zero Trust

Zero Trust in Plain Terms: Verify, Then Trust

Beyond the buzzword Zero Trust has been marketed heavily enough that many people assume it is a product you buy. It is not. It is a […]
Do you like it?0
Read more
February 18, 2026
February 18, 2026
Categories
  • Cloud Security

Cloud Misconfiguration: The Quiet Cause of Loud Breaches

The cloud rarely fails; the settings do Most cloud incidents we investigate do not come from an exotic exploit. They come from a setting that was […]
Do you like it?0
Read more
December 3, 2025
December 3, 2025
Categories
  • Cloud Security

Your SaaS Is Not Secure by Default: Locking Down the Cloud Control Plane

By the end of 2025, a clear pattern held across the breaches we investigated: attackers increasingly did not break into networks, they logged into clouds. Stolen […]
Do you like it?0
Read more
August 27, 2025
August 27, 2025
Categories
  • Zero Trust

Beyond MFA: Moving Canadian Organizations Toward Phishing-Resistant Identity

Multi-factor authentication is now table stakes, and that is exactly the problem. Attackers have adapted. The 2025 wave of identity-driven intrusions, from help-desk social engineering to […]
Do you like it?0
Read more
July 15, 2025
July 15, 2025
Categories
  • Threats & Attacks

Scattered Spider and the Help Desk: When Social Engineering Beats Your Firewall

Through the first half of 2025, a loose collective often tracked as Scattered Spider ran a highly effective campaign against retail, aviation, insurance, and hospitality organizations. […]
Do you like it?0
Read more
June 10, 2025
June 10, 2025
Categories
  • Zero Trust

Identity Is the New Perimeter: Locking Down Access in the Cloud Era

Ask incident responders where modern breaches begin and the answer is remarkably consistent: identity. Across the first half of 2025, from credential-driven SaaS breaches to ransomware […]
Do you like it?0
Read more
February 12, 2025
February 12, 2025
Categories
  • Zero Trust

Zero Trust for the Rest of Us: A Starting Point for SMBs

Zero Trust has been marketed so heavily that many small and mid-sized Canadian businesses assume it is a costly enterprise project reserved for organizations with large […]
Do you like it?0
Read more
November 5, 2024
November 5, 2024
Categories
  • Cloud Security

An Arrest in Ontario: The Human Story Behind the Cloud Breaches

In early November 2024, it emerged that a suspect linked to the wave of cloud data-theft and extortion campaigns tied to Snowflake customer accounts had been […]
Do you like it?0
Read more
July 15, 2024
July 15, 2024
Categories
  • Zero Trust

After Snowflake and AT&T: Make Identity the Perimeter

By mid-July 2024, the scope of the attacks against Snowflake customer accounts had grown, with more organizations disclosing that data had been exported from cloud environments […]
Do you like it?0
Read more
12
Next page
Contact us

+1 (548) 333-2276


oga@morphhats.com


The Blue Team Jedi, aka Morpheus.

Localization

MorphHats InfoSecure
251, Northfield Dr E
Waterloo N2K 0G9
Ontario, Canada

© 2026 MorphHats InfoSecure
    Blog

      Powered by
      ►
      Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
      None
      ►
      Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
      None
      ►
      Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
      None
      ►
      Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
      None
      ►
      Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
      None
      Powered by