PrivacySignal
Breach

Closing the Identity Gaps in Critical Infrastructure Security

BleepingComputer · · International · Data Breaches

Stolen credentials and compromised devices remain a primary entry point for attacks on critical infrastructure. Security firm Specops Software is making the case that Zero Trust frameworks need to verify both the user and the device before any access to sensitive systems is granted.

Why this matters: Power grids, water systems, and hospitals are not hacked through Hollywood magic. They are hacked because someone used a stolen password. That is a solvable problem, and the solution is not complicated: stop treating a correct password as proof that the right person is on the other end. Zero Trust means the device matters too. A credential without a trusted machine should not open the door. The gap here is not technical — it is that operators of critical systems have been slow to close it, and the consequences of getting it wrong land on everyone.

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
BleepingComputer · · International

IDScan sued over alleged data breach affecting 153 million drivers

Identity verification company IDScan faces multiple lawsuits after hackers allegedly broke into its systems and offered to sell data from more than 153 million driver's licenses on the open market.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
Breach
BleepingComputer · · International

39 New Methods That Compromise Passkey Authentication

Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries without breaking FIDO2 cryptography. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

DaVita settles ransomware attack lawsuit for $15M

DaVita, a national kidney dialysis company, has agreed to a $15 million class action settlement following a 2025 ransomware attack that exposed patient data, much of which was subsequently leaked on the dark web.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare#security Read original →
Breach
DataBreaches.net · · International

FBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver’s license scans

A dark web service called Nexus began offering searchable access to more than 153 million scanned driver's licenses from the US and Canada, with IDScan.net suspected as the source of the breach. The FBI's New Orleans field office opened a formal investigation on the same day the service appeared.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →