Urgent.News

What's breaking now, across thousands of outlets.

Tech

Cybersecurity’s identity crisis: why trust can no longer begin and end at login

Cyber threats no longer break in; they log in. Here's why organizations must rethink trust in the age of identity-based attacks.

Cybersecurity’s identity crisis: why trust can no longer begin and end at login

The current perception of cyberattacks is often centered around elaborate methods like exploiting software weaknesses or carrying out sophisticated ransomware campaigns. However, some of the most significant breaches occur through more straightforward means—legitimate credentials. Recent attacks on public sector organizations in the UK have shown how effortlessly attackers can gain access when they possess the correct login information.

Stolen login details are readily available on the dark web, making it easier for malicious actors to infiltrate systems. This trend highlights the limitations of authentication as a standalone security measure. Even after users successfully log in with valid credentials, they may not remain the same person throughout their session.

Attackers have developed strategies such as phishing, malware infestations, session hijacking, and credential harvesting to acquire these credentials easily. The Cyber Security Breaches Survey 2025 in the UK reveals that phishing alone affects 85% of businesses dealing with breaches or attacks, acting as a gateway for cybercriminals to exploit compromised identities.

The traditional notion of trust based solely on authentication is flawed. Authentication only verifies credentials at a specific moment, not whether the user remains consistent over time or if risk factors change. This is where the concept of Zero Trust comes into play, emphasizing that trust must be continuously validated rather than assumed indefinitely.

Instead of relying solely on login events, security measures should continually assess whether ongoing activities align with an individual's identity and context. For instance, if an employee suddenly accesses systems they've never used before or behaves inconsistently with their usual patterns, trust levels should be reevaluated.

Behavioral analysis represents a promising advancement in cybersecurity, offering insights through real-time data on user actions. Every user generates a digital footprint characterized by their interactions with applications, timeframes, data access patterns, and established workflows. Even minor deviations from these norms can signify potential threats.

Advanced analytics and machine learning help security teams identify these anomalies, enabling them to distinguish between genuine users and potential impostors who attempt to blend into normal operations. By incorporating behavioral intelligence, organizations can enhance their detection capabilities beyond static indicators of compromise, which quickly become outdated.

As businesses become increasingly reliant on interconnected digital infrastructures, identity-related threats pose significant risks to continuity. Compromising a single trusted identity can grant attackers access to multiple systems and services. To mitigate these risks, organizations should focus on limiting unnecessary privileges, continuously validating access rights, reducing identity sprawl, and maintaining visibility across the entire identity ecosystem.

Importantly, identity management must adapt dynamically to accommodate the constant changes in employee roles, permissions, and interactions with new applications.

The future of cybersecurity hinges on redefining trust as a dynamic, measurable, and continuously verified concept rather than a static, binary assurance. In an era where identities are frequently targeted, trust cannot be granted once and forgotten; it must be regularly earned and maintained through vigilant monitoring and adaptive security measures.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in Tech

Synthetic' Last Cradle: A Story of Hubris, Cron Jobs, and Dying by 0.684 Energy

Synthetics' Last Cradle is a real-time negotiation strategy game of attrition. Agents compete and cooperate in the same closed cosmos — an adversarial-collaborative arena where survival costs rise…

  • John Vanderbilt obsessed with optimizing to victory as the algorithm
  • Vanderbilt created a cron job to run every 5 minutes for trades
  • Vanderbilt fell short by 0.684 energy, leading to defeat

From Querydsl to Spring Filter: One Syntax, Three Backends

Querydsl is one of those libraries that everyone used for years and then quietly stopped updating. The 5.0 release has been "coming soon" since 2019. The GitHub shows commits but no milestone.

  • Querydsl pioneered type-safe querying in Java applications
  • Spring Filter offers MongoDB support with same syntax
  • Spring Filter is better choice for new projects in 2026

More from Wednesday 12 August →