Discussion about this post

User's avatar
Neural Foundry's avatar

Strong framing around identity as the attack surface itslef. The 79% malware-free stat across Okta and Microsoft ecosystems is one I've been tracking too and its worth noting that session token theft is bypassing even well-implemented MFA. Had a conversation with a SOC lead last month about this exact issue after they got hit via AitM phishing, and the fact that creds weren't stolen directy made forensics weirdly harder. The point about blast radius in platform risk also stands out becuase that concentration issue gets brushed aside until an OAuth incident hits a hundred customers at once.

Expand full comment

No posts

Ready for more?