Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Candidate verification: Stop fraud before it enters your workforce

Sophisticated fraudsters are now targeting the recruiting process. Whether it's a "fake" candidate built on synthetic data, an interviewee hiding behind a deepfake, or a candidate getting a friend to take their technical test, hiring teams are facing a fraud crisis.

New pattern analysis techniques to defend against fraud

Sophisticated fraudsters scale systems to increase their ROI. But it’s also a weakness that you can exploit to shut down fraud rings and keep attacks from scaling. In this discussion, fraud experts Nisreen Hussain, Irfan Faizullabhoy, and Ashley Fang show off how pattern and link analysis stop AI-powered fraud, account takeovers, and large fraud rings.

What is CEN/TS 18099? A guide to the injection attack detection standard

For years, the dominant threat against remote identity verification was the presentation attack: someone holding a printed photo up to a camera, wearing a mask, or playing a pre-recorded video on a phone screen. The industry responded with increasingly sophisticated anti-spoofing technology and vision-based detection models, and the standards to test their effectiveness followed. But many of today’s most sophisticated fraudsters don’t bother with the camera at all.

OAuth vs. API Keys for AI Agents: Why Static Credentials Break in Production Systems

How do you ensure AI agents authenticate when they interact with your entire enterprise ecosystem when you aren’t there to watch their every move? Today, AI agents can do many things autonomously. They can update CRM records, create tickets, trigger workflows, modify data, and just about anything. The importance of authentication increases as they become more autonomous day by day. For years, API keys were the easy default for connecting applications to APIs.

NIST Privileged Access Management: Complying with the NIST Requirements

Privileged accounts are the crown jewels of any IT environment. Admin credentials, root access, service accounts. These are what attackers go after first, because compromising one can hand them the entire organization. Forrester puts the number at 80% of security breaches involving privileged accounts. NIST frameworks, particularly SP 800-53, exist to make sure you're not leaving that door unlocked.

5 Best Mobile Device Management (MDM) Tools in 2026

Mobile devices have become the backbone of the modern workplace. Employees use smartphones to access business applications, tablets to support customer interactions, rugged devices to manage field operations, and laptops to stay productive from virtually anywhere. With remote work, hybrid teams, and BYOD policies becoming standard practice, organizations now rely on a growing mix of devices to keep business operations running.

Introducing Code-First: Ship identity flows the same way you ship everything else

If you're shipping software these days, there's a good chance an agent is in your development workflow. In fact, 84% of software developers say they use AI to write code, open pull requests, and push to production regularly; that number is only expected to grow. Some teams have gone further: they're designing loops, or recurring systems that direct agents continuously, without a human writing a new prompt at each step.

Project Havoc: Breaking Identity Trust with Real-Time Synthetic Media

Under normal conditions, experiencing our digital reflection can feel surreal or even uncomfortable. So first off, we commend our participating execs for allowing us to use their publicly available personal data to create live audio/visual doppelgangers – as we found out just how advanced, believable, and potentially malicious our identity cloning tools currently are.

Using 100+ Signals to Capture 100M Fraudsters

Over 100 behavioral and technical risk signals can be captured in every verification. But knowing which ones to use and combine can be difficult. In this webinar, three fraud and identity practitioners break down how to stack signals to catch synthetic IDs and GenAI-driven fraud without blocking legitimate users.