Sign in

FusionAuth

@fusionauth.io
177 followers 4 following 116 posts

The only Customer Identity and Access Management (CIAM) with hybrid, single-tenant deployment you can dev and test anywhere

PostsRepliesMedia
FusionAuth @fusionauth.io · 20h
Caching helps with product page spikes but doesn’t support authentication, which is more CPU-intensive. If your identity provider isn’t load-tested for peak traffic, it could halt your checkout flow. Benchmark your identity stack before traffic hits: fusionauth.io/blog/black-f...
fusionauth.io
Can Your Identity Platform Pass the Black Friday Test?
Vendor demos show you an identity platform working under ideal conditions. Retailers need to know where it breaks — at peak traffic, at scale, and against legacy systems.
001
FusionAuth @fusionauth.io · 25/09/2026
A forgotten federated login can make your account an easy target. This was the case for 5,000 Dropbox users, where a Lenovo ID flaw let attackers access accounts without passwords. @mooreds.com stresses the importance of verifying new login methods. Read more: hackread.com/hackers-acce...
hackread.com
Hackers Accessed 5,000 Dropbox Accounts Through Lenovo ID Flaw
A Lenovo ID email verification flaw let attackers access about 5,000 Dropbox accounts without using the victims’ Dropbox passwords.
001
FusionAuth @fusionauth.io · 24/09/2026
Proud to be featured in the Cyber Press 2026 CIAM buyer's guide! 🎉 Our CIAM solution is flexible—choose between self-hosted or cloud-based with transparent pricing from day one. Discover why unlimited-user self-hosting is a game changer! Read the full guide here: cyberpress.org/ciam-solutio...
cyberpress.org
8 Customer Identity & Access Management (CIAM) Solutions: Our Top Picks by Use Case (2026)
Choosing customer identity? Our CIAM guide maps 8 picks — Auth0 for developers, Ping for scale, Stytch for fraud-aware flows — to your product and industry.
000
FusionAuth @fusionauth.io · 23/09/2026
Add extra security to your SPA with DPoP and FusionAuth fusionauth.io/blog/sender-...
fusionauth.io
Add extra security to your SPA with DPoP and FusionAuth
Add extra security to your SPA with DPoP and FusionAuth - https://fusionauth.io/blog/sender-constrain-access-tokens-react-app-dpop
000
FusionAuth @fusionauth.io · 22/09/2026
Most breaches are transactional, but a data catalog breach? That's a whole different game. If compromised, attackers gain a complete view of your enterprise. Credential rotation doesn't work. Discover the fresh approach for catalog remediation: www.cybersecurity-insiders.com/why-a-data-c...
cybersecurity-insiders.com
Why a Data Catalog Breach Is Different — And Why You Can't Just Rotate Your Way Out of It
Alation disclosed a breach; catalog metadata can map sensitive fields, data flows and service accounts, guiding attacks for years to come.
000
FusionAuth @fusionauth.io · 21/09/2026
5 Warning Signs Your Company Has Outgrown Its Current Authentication Solution fusionauth.io/blog/5-warni...
fusionauth.io
5 Warning Signs Your Company Has Outgrown Its Current Authentication Solution
5 Warning Signs Your Company Has Outgrown Its Current Authentication Solution - https://fusionauth.io/blog/5-warning-signs-outgrown-auth
000
FusionAuth @fusionauth.io · 18/09/2026
AI Is Exposing the Limits of Your Identity Infrastructure fusionauth.io/blog/ai-expo...
fusionauth.io
AI Is Exposing the Limits of Your Identity Infrastructure
AI Is Exposing the Limits of Your Identity Infrastructure - https://fusionauth.io/blog/ai-exposing-limits-identity-infrastructure
000
FusionAuth @fusionauth.io · 17/09/2026
LLMjacking an emerging AI threat, stealing access to your paid models and running up bills. Dan Moore (FusionAuth) likens it to cryptojacking. Protect yourself with scoped credentials & least privilege. 💻🔒 Read more: www.itbrew.com/stories/what... #LLMjacking #Cybersecurity #Identity #AISecurity
itbrew.com
What is LLMjacking, and why should IT pros care?
As anybody who follows cybersecurity knows, when a new technology emerges, it’s usually followed by a threat actor trying to -jack it up. There’s clickjacking (tricking someone into hitting a disguised URL), sessionjacking (stealing a token to impersonate a user and gain their web access), and DNSjacking (redirecting someone to an attacker-controlled destination). And now, with attackers trying to take over large language models, we have…LLMjacking.
010
FusionAuth @fusionauth.io · 16/09/2026
The Convenience Trap in SaaS-Only Identity fusionauth.io/blog/conveni...
fusionauth.io
The Convenience Trap in SaaS-Only Identity
The Convenience Trap in SaaS-Only Identity - https://fusionauth.io/blog/convenience-trap-saas-only-identity
001
FusionAuth @fusionauth.io · 15/09/2026
In just 23 days, AWS's agent tools faced four CVEs due to a common security issue: giving models too much decision-making power. Our 2026 AI Identity Report shows 66% of organizations experienced an AI identity breach, but only 28% can link actions back to a human. tech.yahoo.com/cybersecurit...
tech.yahoo.com
AWS Strands Agents Tools Received Four CVEs in 23 Days — And They All Share the Same Root Cause
Between July 15 and August 6, 2026, AWS Strands Agents Tools — the first-party tool package for the Strands Agents SDK — received four distinct security advisories. The vulnerabilities range from credential disclosure to arbitrary command execution, but they share a singular root cause: security-sensitive parameters were exposed as LLM-controllable inputs in the tool schema. […]
000
FusionAuth @fusionauth.io · 14/09/2026
You Don't Own the Customer Experience If You Don't Control Identity fusionauth.io/blog/custome...
fusionauth.io
You Don't Own the Customer Experience If You Don't Control Identity
You Don't Own the Customer Experience If You Don't Control Identity - https://fusionauth.io/blog/customer-experience-control-identity
000
FusionAuth @fusionauth.io · 11/09/2026
Homegrown Auth Is a Business Continuity Risk, Not Just a Security Risk fusionauth.io/blog/homegro...
fusionauth.io
Homegrown Auth Is a Business Continuity Risk, Not Just a Security Risk
Homegrown Auth Is a Business Continuity Risk, Not Just a Security Risk - https://fusionauth.io/blog/homegrown-auth-business-continuity-risk
001
FusionAuth @fusionauth.io · 10/09/2026
Who Actually Owns Customer Identity in Your Organization? fusionauth.io/blog/who-own...
fusionauth.io
Who Actually Owns Customer Identity in Your Organization?
Who Actually Owns Customer Identity in Your Organization? - https://fusionauth.io/blog/who-owns-customer-identity
000
FusionAuth @fusionauth.io · 09/09/2026
MCP Client Registration: Dinner Party Or Nightclub? fusionauth.io/blog/cimd-vs...
fusionauth.io
MCP Client Registration: Dinner Party Or Nightclub?
MCP Client Registration: Dinner Party Or Nightclub? - https://fusionauth.io/blog/cimd-vs-dcr
000
FusionAuth @fusionauth.io · 08/09/2026
When engineers ignore the AI tools you've invested in, it’s not just a matter of adoption, it’s a procurement issue. Dan Moore points out that if you can’t pinpoint the problem your tool solves, measure its impact, and show improvements, you're just following trends. leaddev.com/ai/you-bough...
001
FusionAuth @fusionauth.io · 02/09/2026
Attackers are targeting US water systems by exploiting long-standing weaknesses, not AI. Essential defenses like patching, limiting internet exposure, strong access controls, and proper authentication are vital. Check out Dan Moore's insights in Route Fifty: www.route-fifty.com/cybersecurit...
route-fifty.com
States, feds scramble to prevent more water cyberattacks
In the weeks after nine states were hit, lawmakers at the federal and state levels have proposed new funding to harden infrastructure, but experts warned they remain vulnerable.
000
FusionAuth @fusionauth.io · 01/09/2026
A translation plugin on 400,000 WordPress sites exposed admin password-reset links via a public API. Two seemingly harmless features combined, allowing attackers access to admin accounts. Check out Dan Moore's insights on the TranslatePress flaw: itnerd.blog/2026/08/27/4...
itnerd.blog
400,000 WordPress Sites Impacted by Account Takeover Vuln in TranslatePress Plugin
Researchers have uncovered a critical vulnerability with a CVSS score of 9.8 in the TranslatePress WordPress plugin, with 400,000 active installations, that could allow unauthenticated attackers to…
000
FusionAuth @fusionauth.io · 31/08/2026
New episode of the Maintainable Software Podcast! 🎙️ Join David Hayes from FusionAuth as he discusses why boring software wins. Dive into topics like long-lasting API decisions and the impact of technical debt on customer outcomes. Listen here: maintainable.fm/episodes/dav...
maintainable.fm
David Hayes: Boring Software, Clear Incentives, and Better Checklists
David Hayes believes maintainable software starts with a simple idea: fitness for purpose.
000
FusionAuth @fusionauth.io · 30/08/2026
🚨 400k WordPress sites compromised due to weak API authentication! An attacker exploited this by requesting an admin password reset link. This breach emphasizes the importance of user context segregation for security. Full story and @mooreds.com quote at: itnerd.blog/2026/08/27/4...
000
FusionAuth @fusionauth.io · 28/08/2026
A rogue app hits a wall and stops. An AI agent? It finds a way around it. Dave Hayes, VP of Product, dives into the shift in shadow AI: unsanctioned apps connect to one system, while agents connect to many, pushing past obstacles. Read more from Tech News Vision: technewsvision.co.uk/invisible-ai...
technewsvision.co.uk
Invisible AI Agents Creating New Enterprise Security Risks | Tech News Vision
Lurking in many business environments are AI agents that pose serious security risks but, for the most part, remain out of sight of security teams, according
000
FusionAuth @fusionauth.io · 26/08/2026
Release 1.69.0 fusionauth.io/docs/release...
fusionauth.io
Release 1.69.0
Release 1.69.0 - https://fusionauth.io/docs/release-notes#version-1-69-0
000
FusionAuth @fusionauth.io · 26/08/2026
AI didn't create the identity problem. It removed the speed limit fusionauth.io/blog/announc...
fusionauth.io
AI didn't create the identity problem. It removed the speed limit
AI didn't create the identity problem. It removed the speed limit - https://fusionauth.io/blog/announcing-fusionauth-1-69
000
FusionAuth @fusionauth.io · 21/08/2026
Valid provenance can still lead to malware. In the AsyncAPI attack, attackers exploited trusted pipelines to deliver backdoored packages. @mooreds.com from FusionAuth explains that malicious code activates upon library import, not installation. Read more: www.reversinglabs.com/blog/why-sof...
reversinglabs.com
Why software delivery cannot depend on trust alone | RL Blog
Attackers turned the trusted AsyncAPI CI/CD publishing pipeline against its users, and the provenance checks all came back clean.
001
FusionAuth @fusionauth.io · 18/08/2026
You wouldn’t hand a contractor a master key, so why let AI agents access your infrastructure without oversight? Join Dan Moore on the Security Strategist Podcast to discover why unique identities for AI agents are vital for security. Listen: em360tech.com/podcasts/why...
010
FusionAuth @fusionauth.io · 17/08/2026
Attackers are logging in, not breaking through firewalls. Ensure AI agents use short-lived identity rules to prevent insider threats. Service accounts aren’t enough—opt for scoped tokens! Check out this report by TechnologyAdvice, sponsored by FusionAuth: fusionauth.io/ebooks/insid...
010
FusionAuth @fusionauth.io · 14/08/2026
Fake accounts are exploiting free credits to resell cheap AI tokens. To combat this, decouple credits from signup. Insights from Dave Hayes, VP of Product at FusionAuth: itnerd.blog/2026/08/08/p...
itnerd.blog
Poison Claude Selling Discounted AI Tokens Built on Fake Accounts and Free Credits
Researchers have found online service Poison Claude reselling access to Anthropic’s premium AI models at a significant discount with suspicions that these discounts are coming from fraudulently reg…
000
FusionAuth @fusionauth.io · 13/08/2026
AI adoption is skyrocketing, but 68% of teams lack clear metrics on its impact. Costs are rising too, with concerns jumping from 35% to 62%. Join @mooreds.com at LeadDev for insights on the AI Impact Report 2026. Details & registration: leaddev.com/event/how-ai... #AI #Engineering #LeadDev
001
FusionAuth @fusionauth.io · 11/08/2026
Black Hat 2026 felt like #CES! While vendors splurged on flashy booths, the truth remains: attackers are logging in, not breaking in. We focused on real identity infrastructure with our '90s-themed booth instead of gimmicks. Let's chat auth—DM us for a fluff-free sync! #BlackHat2026
001
FusionAuth @fusionauth.io · 10/08/2026
Two-thirds of breaches stem from login issues, highlighting the importance of identity management. In Episode 127 of the SourceForge Podcast, we discuss how in-house customer auth can pose silent security risks. Full episode: www.youtube.com/watch
001
FusionAuth @fusionauth.io · 05/08/2026
MFA isn’t foolproof—it’s just a hurdle attackers know how to leap. If your identity pipeline views MFA as a simple pass/fail, you’re overlooking 10 risk signals that can bypass basic 2FA. See them all at fusionauth.io/lp/10-attack...
000
FusionAuth @fusionauth.io · 04/08/2026
We're live at Black Hat USA! Come find the FusionAuth team at Booth #5642 at Mandalay Bay. Spin to Win kicks off at 4:30pm today. Bingo at 6pm. Come say hello! fusionauth.io/event/blackh... #BlackHat2026 #BHUSA #FusionAuth #CIAM
000
FusionAuth @fusionauth.io · 03/08/2026
Ever feel like your auth setup is a ticking time bomb? 💣 Join us at Black Hat Booth #5642, Aug 4–6, Mandalay Bay, Vegas! FusionAuth gives you control with a CIAM platform that's self-hosted or cloud-based. No surprises! fusionauth.io/event/blackh... #BHUSA #CIAM #AppSec #FusionAuth #Auth
000
FusionAuth @fusionauth.io · 30/07/2026
We're at #BlackHat2026. Booth #5642, August 4–6 in Las Vegas. CIAM that you actually control. No lock-in. Deploy anywhere. Come talk auth or just spin to win. fusionauth.io/event/blackh... #BHUSA
fusionauth.io
BlackHat USA 2026 - FusionAuth Event
Meet the FusionAuth Crew at Booth #5642
000
FusionAuth @fusionauth.io · 29/07/2026
Over 24,000 servers are leaking password hashes due to a 20-year-old flaw in their BMC interfaces. Researchers cracked HPE factory passwords in just a day! Dan Moore from FusionAuth discusses why simply rotating passwords isn't enough: itnerd.blog/2026/07/29/t... 🔒💻
itnerd.blog
Thousands of Servers Leak Authentication Password Hashes via 20 Year-Old Vuln in BMC Interface
Researchers have uncovered more than 24,000 servers leaking authentication password hashes from a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface.  Lava HQ has a …
000
FusionAuth @fusionauth.io · 23/07/2026
FusionAuth Appoints Jamey Miller as SVP of Engineering and Technology fusionauth.io/blog/jamey-m...
fusionauth.io
FusionAuth Appoints Jamey Miller as SVP of Engineering and Technology
FusionAuth Appoints Jamey Miller as SVP of Engineering and Technology - https://fusionauth.io/blog/jamey-miller-svp-engineering
000
FusionAuth @fusionauth.io · 23/07/2026
Credential stuffing is still a threat in 2026. @mooreds.com details the Chick-fil-A breach at itnerd.blog/2026/07/22/c...
001
FusionAuth @fusionauth.io · 23/07/2026
Credential stuffing continues as users often don't change compromised passwords. @mooreds.com details the Chick-fil-A breach where attackers used new devices and IPs for thousands of rapid attempts. Stronger identity verification could have helped. Read more: itnerd.blog/2026/07/22/c...
000
FusionAuth @fusionauth.io · 22/07/2026
Service accounts and hardcoded keys aren't enough for thousands of autonomous AI agents needing API access. 🤖🔐 In Ep. 72 of Cyber Security Matters, FusionAuth CEO Brian Bell discusses non-human identity security and the shift in CIAM. Listen here: fusionauth.io/podcast/ai-a... #AI #IdentitySecurity
000
FusionAuth @fusionauth.io · 21/07/2026
New research: 88% of organizations running AI in production have already had a confirmed or near-miss identity security incident. We walked through the data — nonhuman identities, the confidence paradox, deployment architecture as a risk variable.
000
FusionAuth @fusionauth.io · 17/07/2026
Build vs. buy for authentication isn't a straightforward answer. It depends on your team size, timeline, and how you factor in compliance overhead. FusionAuth’s Build vs. Buy calculator lets you plug in your actual numbers and see where things land. fusionauth.io/buildvsbuy
000
FusionAuth @fusionauth.io · 16/07/2026
FusionAuth Launches Intelligent MFA in Latest Release as Demand Surges for Identity Infrastructure Customers Can Control fusionauth.io/blog/fusiona...
fusionauth.io
FusionAuth Launches Intelligent MFA in Latest Release as Demand Surges for Identity Infrastructure Customers Can Control
FusionAuth Launches Intelligent MFA in Latest Release as Demand Surges for Identity Infrastructure Customers Can Control - https://fusionauth.io/blog/fusionauth-intelligent-mfa-pr
000
FusionAuth @fusionauth.io · 16/07/2026
AI agents don't click password reset links or respond to MFA prompts. But most teams are still authenticating them like humans. Dan Moore from FusionAuth on what that's costing you: scworld.com/perspective/...
scworld.com
Your AI agent can't be authenticated by a password reset email
AI agents expose identity gaps as machine accounts outpace governance.
000
FusionAuth @fusionauth.io · 15/07/2026
84% of the most AI-security-confident organizations in our survey had a confirmed breach. The faster you move, the bigger the gap between what your policies say and what your infrastructure actually enforces. Full report: fusionauth.io/ebooks/the-2...
000
FusionAuth @fusionauth.io · 14/07/2026
Most MFA runs in a vendor's cloud. Challenge or pass. No explainability, no paper trail. FusionAuth 1.68 runs the scoring inside your own instance. 10 deterministic signals, full webhook logs to your SIEM, and no black box. Included in every paid plan. fusionauth.io/blog/intelli...
000
FusionAuth @fusionauth.io · 13/07/2026
SaaS identity deployments report over double the confirmed AI security incidents of self-hosted environments (83% vs 38%). Tomorrow at 10:30 AM MT / 12:30 PM ET, Dayna Rothman outlines the architectural choices that determine your AI blast radius. Register: fusionauth.io/webinar/the-...
001
FusionAuth @fusionauth.io · 10/07/2026
Announcing FusionAuth 1.68 - Intelligent Kamfa fusionauth.io/blog/announc...
fusionauth.io
Announcing FusionAuth 1.68 - Intelligent Kamfa
Announcing FusionAuth 1.68 - Intelligent Kamfa - https://fusionauth.io/blog/announcing-fusionauth-1-68
001
FusionAuth @fusionauth.io · 09/07/2026
Intelligent MFA Should Challenge Risk, Not Loyal Customers fusionauth.io/blog/intelli...
fusionauth.io
Intelligent MFA Should Challenge Risk, Not Loyal Customers
Intelligent MFA Should Challenge Risk, Not Loyal Customers - https://fusionauth.io/blog/intelligent-mfa
000
FusionAuth @fusionauth.io · 09/07/2026
Jim McDonald (IDAC) chats with Dan Moore from FusionAuth about the future of customer identity management. Discover insights on authentication, risk-based MFA, and the role of AI. Watch the full episode: youtu.be/aaHEajBFAbI #CIAM
youtu.be
#433 - Sponsor Spotlight - FusionAuth
Jim McDonald sits down with Dan Moore, Senior Director of CIAM Strategy and Identity Standards at FusionAuth, for an in-depth conversation on customer identity and access management. Dan explains how FusionAuth views authentication as the front door to any application and why control, deployment flexibility, and developer ownership are central to their approach. The discussion covers progressive registration, friction vs. usability, customization options, identity standards, the build vs. buy debate, risk-based MFA, and how AI agents will shape the future of customer identity. This episode and others is made possible with support from FusionAuth. Learn more at fusionauth.io/idac. Connect with Dan: https://www.linkedin.com/in/mooreds/ Learn more about FusionAuth: https://fusionauth.io/idac Blog article mentioned: https://bobdahacker.com/blog/fifa-hack Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com 00:00:00 Introduction 00:01:18 What is FusionAuth? 00:03:15 Dan's identity origin story 00:04:19 Developer focus and ethos 00:06:54 Authentication as the front door 00:10:00 Balancing friction and usability 00:15:24 Customization in CIAM 00:18:10 What sets FusionAuth apart 00:20:33 FusionAuth's customer sweet spot 00:25:48 Deployment flexibility and the control spectrum 00:30:19 Common challenges in CIAM 00:33:06 Build vs. buy for authentication 00:36:00 Omni-channel authentication 00:40:27 Why identity standards matter 00:42:07 Risk-based MFA and intelligent challenges 00:45:00 AI agents and the future of CIAM 00:49:23 Closing thoughts 00:51:35 Vacation roundup Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Dan Moore, FusionAuth, CIAM, customer identity, authentication, access management, IAM, identity standards, MFA, risk-based authentication, progressive registration, OAuth, OIDC, SAML, AI agents, deployment flexibility, build vs buy, Sponsor Spotlight
001
FusionAuth @fusionauth.io · 07/07/2026
Meta's AI support chatbot recently gave attackers access to Instagram accounts by misinterpreting customer support requests. It even sent a confirmation code to the attacker's email. Read the full exploit breakdown here: itnerd.blog/2026/06/02/h...
itnerd.blog
Hackers hijacked Instagram accounts by tricking Meta AI support chatbot into granting access
Instagram has resolved a security issue that allowed several users’ accounts to get hacked. The attack appeared to rely on tricking Meta’s own AI-powered support chatbot into granting access to a v…
001
FusionAuth @fusionauth.io · 07/07/2026
85% of security leaders labeled "well prepared" for AI faced identity incidents last year. Why? Policies on paper don’t ensure runtime enforcement. Join CMO Dayna Rothman on July 14th at 10:30 AM MT/12:30 PM ET to learn why! Register: fusionauth.io/webinar/the-...
000