FusionAuth
banner
fusionauth.io
FusionAuth
@fusionauth.io
The only Customer Identity and Access Management (CIAM) with hybrid, single-tenant deployment you can dev and test anywhere
The Convenience Trap in SaaS-Only Identity fusionauth.io/blog/conveni...
The Convenience Trap in SaaS-Only Identity
The Convenience Trap in SaaS-Only Identity - https://fusionauth.io/blog/convenience-trap-saas-only-identity
fusionauth.io
September 16, 2026 at 6:10 PM
In just 23 days, AWS's agent tools faced four CVEs due to a common security issue: giving models too much decision-making power. Our 2026 AI Identity Report shows 66% of organizations experienced an AI identity breach, but only 28% can link actions back to a human.

tech.yahoo.com/cybersecurit...
AWS Strands Agents Tools Received Four CVEs in 23 Days — And They All Share the Same Root Cause
Between July 15 and August 6, 2026, AWS Strands Agents Tools — the first-party tool package for the Strands Agents SDK — received four distinct security advisories. The vulnerabilities range from credential disclosure to arbitrary command execution, but they share a singular root cause: security-sensitive parameters were exposed as LLM-controllable inputs in the tool schema. […]
tech.yahoo.com
September 15, 2026 at 7:36 PM
You Don't Own the Customer Experience If You Don't Control Identity fusionauth.io/blog/custome...
You Don't Own the Customer Experience If You Don't Control Identity
You Don't Own the Customer Experience If You Don't Control Identity - https://fusionauth.io/blog/customer-experience-control-identity
fusionauth.io
September 14, 2026 at 6:10 PM
Homegrown Auth Is a Business Continuity Risk, Not Just a Security Risk fusionauth.io/blog/homegro...
Homegrown Auth Is a Business Continuity Risk, Not Just a Security Risk
Homegrown Auth Is a Business Continuity Risk, Not Just a Security Risk - https://fusionauth.io/blog/homegrown-auth-business-continuity-risk
fusionauth.io
September 11, 2026 at 6:09 PM
Who Actually Owns Customer Identity in Your Organization? fusionauth.io/blog/who-own...
Who Actually Owns Customer Identity in Your Organization?
Who Actually Owns Customer Identity in Your Organization? - https://fusionauth.io/blog/who-owns-customer-identity
fusionauth.io
September 10, 2026 at 2:33 PM
MCP Client Registration: Dinner Party Or Nightclub? fusionauth.io/blog/cimd-vs...
MCP Client Registration: Dinner Party Or Nightclub?
MCP Client Registration: Dinner Party Or Nightclub? - https://fusionauth.io/blog/cimd-vs-dcr
fusionauth.io
September 9, 2026 at 9:39 PM
When engineers ignore the AI tools you've invested in, it’s not just a matter of adoption, it’s a procurement issue.

Dan Moore points out that if you can’t pinpoint the problem your tool solves, measure its impact, and show improvements, you're just following trends.

leaddev.com/ai/you-bough...
September 8, 2026 at 8:38 PM
Attackers are targeting US water systems by exploiting long-standing weaknesses, not AI. Essential defenses like patching, limiting internet exposure, strong access controls, and proper authentication are vital. Check out Dan Moore's insights in Route Fifty: www.route-fifty.com/cybersecurit...
States, feds scramble to prevent more water cyberattacks
In the weeks after nine states were hit, lawmakers at the federal and state levels have proposed new funding to harden infrastructure, but experts warned they remain vulnerable.
www.route-fifty.com
September 2, 2026 at 5:10 PM
A translation plugin on 400,000 WordPress sites exposed admin password-reset links via a public API. Two seemingly harmless features combined, allowing attackers access to admin accounts. Check out Dan Moore's insights on the TranslatePress flaw: itnerd.blog/2026/08/27/4...
400,000 WordPress Sites Impacted by Account Takeover Vuln in TranslatePress Plugin
Researchers have uncovered a critical vulnerability with a CVSS score of 9.8 in the TranslatePress WordPress plugin, with 400,000 active installations, that could allow unauthenticated attackers to…
itnerd.blog
September 1, 2026 at 5:10 PM
New episode of the Maintainable Software Podcast! 🎙️ Join David Hayes from FusionAuth as he discusses why boring software wins. Dive into topics like long-lasting API decisions and the impact of technical debt on customer outcomes.

Listen here: maintainable.fm/episodes/dav...
David Hayes: Boring Software, Clear Incentives, and Better Checklists
David Hayes believes maintainable software starts with a simple idea: fitness for purpose.
maintainable.fm
August 31, 2026 at 10:55 PM
🚨 400k WordPress sites compromised due to weak API authentication! An attacker exploited this by requesting an admin password reset link. This breach emphasizes the importance of user context segregation for security.

Full story and @mooreds.com quote at: itnerd.blog/2026/08/27/4...
August 30, 2026 at 10:50 PM
A rogue app hits a wall and stops. An AI agent? It finds a way around it. Dave Hayes, VP of Product, dives into the shift in shadow AI: unsanctioned apps connect to one system, while agents connect to many, pushing past obstacles. Read more from Tech News Vision: technewsvision.co.uk/invisible-ai...
Invisible AI Agents Creating New Enterprise Security Risks | Tech News Vision
Lurking in many business environments are AI agents that pose serious security risks but, for the most part, remain out of sight of security teams, according
technewsvision.co.uk
August 28, 2026 at 5:45 PM
Release 1.69.0
Release 1.69.0 - https://fusionauth.io/docs/release-notes#version-1-69-0
fusionauth.io
August 26, 2026 at 8:01 PM
AI didn't create the identity problem. It removed the speed limit fusionauth.io/blog/announc...
AI didn't create the identity problem. It removed the speed limit
AI didn't create the identity problem. It removed the speed limit - https://fusionauth.io/blog/announcing-fusionauth-1-69
fusionauth.io
August 26, 2026 at 2:20 PM
Valid provenance can still lead to malware. In the AsyncAPI attack, attackers exploited trusted pipelines to deliver backdoored packages. @mooreds.com from FusionAuth explains that malicious code activates upon library import, not installation.

Read more: www.reversinglabs.com/blog/why-sof...
Why software delivery cannot depend on trust alone | RL Blog
Attackers turned the trusted AsyncAPI CI/CD publishing pipeline against its users, and the provenance checks all came back clean.
www.reversinglabs.com
August 21, 2026 at 6:00 PM
You wouldn’t hand a contractor a master key, so why let AI agents access your infrastructure without oversight?

Join Dan Moore on the Security Strategist Podcast to discover why unique identities for AI agents are vital for security.

Listen: em360tech.com/podcasts/why...
August 18, 2026 at 4:03 PM
Attackers are logging in, not breaking through firewalls. Ensure AI agents use short-lived identity rules to prevent insider threats. Service accounts aren’t enough—opt for scoped tokens!

Check out this report by TechnologyAdvice, sponsored by FusionAuth: fusionauth.io/ebooks/insid...
August 17, 2026 at 10:20 PM
Fake accounts are exploiting free credits to resell cheap AI tokens. To combat this, decouple credits from signup. Insights from Dave Hayes, VP of Product at FusionAuth: itnerd.blog/2026/08/08/p...
Poison Claude Selling Discounted AI Tokens Built on Fake Accounts and Free Credits
Researchers have found online service Poison Claude reselling access to Anthropic’s premium AI models at a significant discount with suspicions that these discounts are coming from fraudulently reg…
itnerd.blog
August 14, 2026 at 6:00 PM
AI adoption is skyrocketing, but 68% of teams lack clear metrics on its impact. Costs are rising too, with concerns jumping from 35% to 62%. Join @mooreds.com at LeadDev for insights on the AI Impact Report 2026.

Details & registration: leaddev.com/event/how-ai...

#AI #Engineering #LeadDev
August 13, 2026 at 3:40 PM
Black Hat 2026 felt like #CES! While vendors splurged on flashy booths, the truth remains: attackers are logging in, not breaking in. We focused on real identity infrastructure with our '90s-themed booth instead of gimmicks. Let's chat auth—DM us for a fluff-free sync!

#BlackHat2026
August 11, 2026 at 6:27 PM
Two-thirds of breaches stem from login issues, highlighting the importance of identity management.

In Episode 127 of the SourceForge Podcast, we discuss how in-house customer auth can pose silent security risks.

Full episode: www.youtube.com/watch
August 10, 2026 at 5:15 PM
MFA isn’t foolproof—it’s just a hurdle attackers know how to leap.

If your identity pipeline views MFA as a simple pass/fail, you’re overlooking 10 risk signals that can bypass basic 2FA. See them all at fusionauth.io/lp/10-attack...
August 5, 2026 at 8:28 PM
We're live at Black Hat USA! Come find the FusionAuth team at Booth #5642 at Mandalay Bay.

Spin to Win kicks off at 4:30pm today. Bingo at 6pm.

Come say hello!

fusionauth.io/event/blackh...

#BlackHat2026 #BHUSA #FusionAuth #CIAM
August 4, 2026 at 7:05 PM
Ever feel like your auth setup is a ticking time bomb? 💣 Join us at Black Hat Booth #5642, Aug 4–6, Mandalay Bay, Vegas!

FusionAuth gives you control with a CIAM platform that's self-hosted or cloud-based. No surprises!

fusionauth.io/event/blackh...

#BHUSA #CIAM #AppSec #FusionAuth #Auth
August 3, 2026 at 5:00 PM
We're at #BlackHat2026. Booth #5642, August 4–6 in Las Vegas.

CIAM that you actually control. No lock-in. Deploy anywhere.

Come talk auth or just spin to win.

fusionauth.io/event/blackh...

#BHUSA
BlackHat USA 2026 - FusionAuth Event
Meet the FusionAuth Crew at Booth #5642
fusionauth.io
July 30, 2026 at 10:22 PM