Trust Is Necessary. Permanent Trust Isn’t.
One of the more interesting cybersecurity stories this week wasn’t interesting because an attacker got in. It was interesting because of what happened after they did.
ReliaQuest disclosed that an employee was targeted in a social engineering attack that temporarily exposed a single identity session. The attacker was able to see an identity dashboard, but the activity was detected and contained before they could access company applications, backend systems, or customer data.
That’s an important distinction.
For the longest time, cybersecurity operated around fairly static ideas of trust. If you were inside the corporate network, using a managed device, and authenticated with valid credentials, there was a reasonable assumption that you belonged there. We built networks, applications, and access controls around that assumption, but we know now that authentication isn’t the same thing as trust.
Credentials get stolen. Sessions get hijacked. Devices get compromised. Vendors get breached. People get fooled. This week’s headlines provide examples across nearly all of those categories.
That’s why I think the underlying idea behind Zero Trust remains so important. Zero Trust was never really about trusting nothing. Businesses can’t operate that way. It’s about recognizing that trust should be earned, limited, and continuously evaluated.
Authentication can establish identity, but it shouldn’t establish unlimited or permanent trust.
That distinction becomes even more important as identity increasingly becomes the control plane for modern technology. Our applications are distributed across cloud providers and SaaS platforms. Employees work from everywhere. Systems communicate through APIs. Workloads authenticate to other workloads. Access that once depended heavily on where something was located now depends much more on who or what is requesting access, what they’re allowed to do, and whether their behavior still makes sense.
We’re also approaching another interesting evolution in that model.
The identity requesting access won’t always represent a person sitting at a keyboard.
It may be an application, an automated process, or increasingly an AI agent acting on someone’s behalf. Those agents may read email, query databases, write code, create tickets, interact with business systems, and eventually communicate with other agents.
That creates some fascinating questions for Security teams.
Who authorized the agent? What should it be allowed to access? How long should that authorization exist? Can it delegate authority to something else? What happens when its behavior changes? And how quickly can we remove that access when something doesn’t look right?
Those may sound like new questions created by AI, but they’re really extensions of a problem we’ve been working on for years.
Trust.
The technologies will continue to change. The entities requesting access will change with them. The architecture underneath our Security programs needs to be capable of making increasingly dynamic decisions about both.
The goal isn’t to eliminate trust. It’s to become much better at deciding who and what deserves it, how much they should receive, and when that trust should end.
🔒 Security Tip of the Week:
Choose one privileged identity in your environment and look beyond whether it uses MFA. Ask what it can access after authentication, whether that access is actually necessary, what behavior you’re monitoring, and how quickly you could revoke its active sessions if it were compromised.
📌 This Week’s Outlook in a Shareable Statement:
A valid identity doesn’t automatically represent a trusted action. As identities expand from people to workloads, services, applications, and AI agents, Security architectures will increasingly need to evaluate trust continuously rather than grant it permanently.
Trust is necessary. Permanent trust isn’t.
— Stephen Nelson
CEO, Pinpoint Security
CEO, Pinpoint Security
📰 Weekly News Roundup:
🛡️ ReliaQuest Thwarts ShinyHunters Social Engineering Intrusion
ReliaQuest disclosed a targeted social engineering attack that temporarily exposed a single employee identity session. The attacker gained limited visibility into an identity dashboard, but the activity was contained before company applications, backend systems, or customer data were accessed.
ReliaQuest disclosed a targeted social engineering attack that temporarily exposed a single employee identity session. The attacker gained limited visibility into an identity dashboard, but the activity was contained before company applications, backend systems, or customer data were accessed.
🤖 CISA and FBI Warn of AI-Generated Exploits Targeting Siemens Industrial Systems
U.S. cybersecurity agencies warned critical infrastructure operators that attackers are using AI-generated exploitation scripts against exposed Siemens S7 programmable logic controllers. The activity demonstrates how AI can reduce the time and expertise required to develop attacks against operational technology.
U.S. cybersecurity agencies warned critical infrastructure operators that attackers are using AI-generated exploitation scripts against exposed Siemens S7 programmable logic controllers. The activity demonstrates how AI can reduce the time and expertise required to develop attacks against operational technology.
🔑 Microsoft Discloses Critical Entra ID Vulnerability
Microsoft disclosed CVE-2026-69836, a maximum-severity remote code execution vulnerability in Entra ID caused by unsafe deserialization. Microsoft says the cloud-hosted vulnerability has been mitigated and subsequently clarified that it was not exploited in the wild.
Microsoft disclosed CVE-2026-69836, a maximum-severity remote code execution vulnerability in Entra ID caused by unsafe deserialization. Microsoft says the cloud-hosted vulnerability has been mitigated and subsequently clarified that it was not exploited in the wild.
☁️ Threat Actor Claims 3.6 Million Azure Employee Records Stolen from Major Corporations
A threat actor using the name “TheHatman” claimed to have stolen millions of employee records from Azure environments associated with several major companies after obtaining initial access through compromised credentials.
A threat actor using the name “TheHatman” claimed to have stolen millions of employee records from Azure environments associated with several major companies after obtaining initial access through compromised credentials.
💳 SafePal Crypto Wallet Discloses Order Tracking Breach Affecting 40,000 Users
SafePal disclosed an authorization flaw in an order-tracking plugin that exposed names, shipping addresses, email addresses, and phone numbers belonging to nearly 40,000 customers. The company said wallet private keys, seed phrases, and financial credentials were not affected.
SafePal disclosed an authorization flaw in an order-tracking plugin that exposed names, shipping addresses, email addresses, and phone numbers belonging to nearly 40,000 customers. The company said wallet private keys, seed phrases, and financial credentials were not affected.
|
|