CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

What the identity attack surface looks like when trust becomes the target

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3237

As cited

Copy frozen at (site build).

identity access

What the identity attack surface looks like when trust becomes the target

Joel Moses of F5 discusses how attackers exploit identity systems by leveraging trust mechanisms rather than breaking through them, including MFA fatigue attacks, session token theft, and malicious application consent. The video covers trust relationships between cloud and on-premises environments that create lateral paths, and recommends mitigations such as number matching, FIDO2 keys, and periodic audits of third-party application access.

Why it matters: Security practitioners should understand that identity attacks bypass technical defenses through trust exploitation, making identity governance and MFA implementation critical controls for protecting against this expanding attack surface.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

identity access

What the identity attack surface looks like when trust becomes the target

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

identity access

What the identity attack surface looks like when trust becomes the target

A Help Net Security video featuring F5's VP of Strategic Engineering discusses how attackers exploit identity trust relationships rather than attempting direct breaches. The discussion covers multifactor authentication (MFA) fatigue, session token theft, malicious application consent, and cloud-to-on-premises trust paths, using the 2022 Uber breach as a case study. Mitigation approaches include number matching, FIDO2 keys, periodic access reviews, and monitoring of third-party application permissions.

Why it matters: Security teams and identity administrators need to recognize that attackers can bypass strong authentication by exploiting trust relationships and user fatigue, making identity governance and MFA design critical controls today.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

identity access

What the identity attack surface looks like when trust becomes the target

A Help Net Security video featuring F5's VP of Strategic Engineering discusses how attackers exploit identity trust relationships rather than attempting direct breaches. The discussion covers multifactor authentication (MFA) fatigue, session token theft, malicious application consent, and cloud-to-on-premises trust paths, using the 2022 Uber breach as a case study. Mitigation approaches include number matching, FIDO2 keys, periodic access reviews, and monitoring of third-party application permissions.

Why it matters: Security teams and identity administrators need to recognize that attackers can bypass strong authentication by exploiting trust relationships and user fatigue, making identity governance and MFA design critical controls today.

VendorsF5
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary