#NIST-Report
$LAES — Foreign Issuer Report

SEALSQ Corp announced that its VaultIC408 secure element platform has achieved FIPS 140-3 Level 3 validation from NIST (Certificate No. 5463), effective August 5, 2026 through August 4, 2031.

🧵 continued ↓
September 25, 2026 at 4:32 PM
'... emphasizes the importance of secure by design practices, configurability, interoperability, and continuous monitoring, and provides specific technical recommendations to safeguard [SSO], federation, and [API] access scenarios'.

TIMELY.

csrc.nist.gov/pubs/ir/8587...
NIST Internal or Interagency Report (NISTIR) 8587, Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers
This report provides implementation guidelines to help federal agencies and cloud service providers (CSPs) protect identity tokens, access tokens, and assertions from forgery, theft, and misuse. Build...
csrc.nist.gov
September 18, 2026 at 12:02 AM
NIST guidance misses AI agent authorization risks

The report, titled Protecting Tokens and Assertions from Forgery, Theft, and Misuse (NIST IR 8587), details how organizations should strengthen... #AgenticAI
NIST guidance misses AI agent authorization risks
The National Institute of Standards and Technology (NIST), with support from the Cybersecurity and Infrastructure Security Agency (CISA), has published a finalized playbook for securing digital tokens. The guidance strengthens defenses against token theft and forgery across federal agencies and cloud providers, but leaves a significant gap around autonomous AI agents that security researchers say […]
hashlytics.io
September 17, 2026 at 8:31 PM
“@CISAgov & @NIST today released Interagency Report (IR) 8587, Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers (#CSPs).” www.cisa.gov/news-events/...
CISA and NIST Release Guidelines to Protect Federal Cloud Identity Systems from Token Theft, Forgery, and Misuse | CISA
www.cisa.gov
September 17, 2026 at 12:23 AM
CISA and NIST released NIST Interagency Report 8587 on September 15, 2026, providing guidance to protect identity tokens from theft and misuse.
CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse
cybersecuritynews.com
September 16, 2026 at 4:17 PM
AI agent authorization risks remain a gap in new NIST-CISA token security guidance
AI agents’ actions are out of scope for new guidance from US authorities on securing identity and access tokens, but there is still plenty enterprises can do to protect their systems from rogue humans and AI agents alike. “Protecting Tokens and Assertions from Forgery, Theft, and Misuse,” a new report from the National Institute of Standards and Technology (NIST) with help from the Cybersecurity and Infrastructure Security Agency (CISA), offers guidance for operators of systems that use digitally signed tokens to make access decisions, including single sign-on and API access. The guidelines, also known as NIST IR 8587, address what happens after authentication: Tokens and assertions can carry proof of authentication or authorization between systems, allowing an attacker who compromises them to exploit access that has already been granted. NIST recommends continuous monitoring, along with tighter controls throughout the token lifecycle. The issue is of particular significance for CISA. In May, a public GitHub repository believed to have been maintained by a CISA contractor was found to contain sensitive government credentials, including AWS tokens and GitHub access tokens. CISA said at the time there was no indication that sensitive data had been compromised. ## The unresolved question of agent authority NIST recommends applying the same guidelines for securing signed tokens used by AI agents as for securing those used by humans, but notes that the access risks posed by AI and AI agents “create additional IAM challenges that require further guidelines and, in some cases, new or expanded standards and protocols.” NIST and CISA are still working on those, but there are things that IT teams can do meanwhile to secure agentic systems. Managing the lifecycle of an agent’s identity is part of the challenge, said Yih Khai Wong, senior research manager for security services at IDC Asia/Pacific. Enterprises need visibility into who provisioned an agent’s credentials and what those credentials allow, Wong said. Access should also be withdrawn when the agent’s task ends. “Token hardening assumes the token holder is a known, bounded actor,” Wong said. “An agentic system breaks that assumption.” Delegation can make that boundary harder to establish, said Amit Kumar Jena, head of AI development at Kanerika. An agent may act on behalf of a user, invoke a tool and then reach another service, making it increasingly difficult to determine whose authority is being exercised as the chain grows. Jena said prompt injection could also steer an agent holding a valid token toward an action the user never requested. Token verification would not necessarily detect that misuse because the token itself could still be legitimate. Jain argued that CISOs should treat AI agents as low-trust non-human identities, granting only the access required for a task. Higher-risk actions should require human approval, he added. Wong also recommended maintaining an agent inventory and keeping those identities separate from human accounts. Credentials should expire when the task is complete, he said. ## Why valid tokens can still be dangerous A common weakness is assuming that because a token is valid, the activity associated with it is legitimate, according to Jonathan Ong, senior analyst for managed security services at Omdia. Organizations should consider the context in which a token is presented, including whether a user is accessing sensitive systems from an unusual location or at an unexpected time, Ong said. Detection should also correlate activity across security domains to identify behavior that may appear benign in isolation. Containment presents another challenge once a token has been compromised. “Token revocation may not always be possible due to architectural limitations,” Ong said. Other controls can limit the usefulness of a compromised token. Neil Shah, vice president for research and partner at Counterpoint Research, said that NIST’s recommendations can reduce both the duration and reach of a token compromise. Audience restrictions can limit where a stolen token is accepted, while cryptographically binding a token to the client holding the corresponding private key makes replay by an attacker more difficult. The report also points organizations toward shared-signal mechanisms such as the Continuous Access Evaluation Profile (CAEP) and Risk Incident Sharing and Coordination (RISC), which can help connected systems respond when token-related security conditions change, Shah said. ## Token security extends beyond IAM The CISA credential exposure also highlights how token security can break down outside traditional IAM controls, Jain said. Credentials can surface in source code, CI/CD pipelines, logs and contractor environments even when access policies themselves are sound. “If a contractor can copy a cloud credential to their local machine, the identity governance has already failed,” Shah said. Managing that risk through policy alone can be difficult in DevOps environments, where credentials can be copied onto developer machines or exposed through automated pipelines, Shah said. He argued that enterprises should eliminate static tokens wherever possible and replace them with short-lived credentials. The CISA incident also exposes a boundary in the NIST guidance, Jena said. IR 8587 focuses on asymmetrically signed tokens and explicitly places mechanisms such as API keys outside the scope of its controls. NIST nevertheless requires covered tokens to be kept out of logs, CI/CD pipelines, and build artifacts.
www.csoonline.com
September 16, 2026 at 8:58 PM
Latest post from CISA
Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers
Developed by the National Institute of Standards and Technology (NIST) and CISA, this interagency report provides federal agencies and cloud service providers with guidelines to protect the identity assertions, access tokens, and cryptographic mechanisms that support modern authentication and authorization. As agencies adopt hybrid and multi-cloud environments, single sign-on, federation, and application programming interface (API)-based access increasingly depend on signed tokens and assertions that adversaries may target for forgery, theft, and misuse to move laterally across enterprise networks and access sensitive data. This final report updates the initial public draft and incorporates feedback on token validation, secrets management, and detection at scale, as well as input from government and industry experts that CISA gathered through its Joint Cyber Defense Collaborative. The report expands on NIST Special Publication Security and Privacy Controls for Information Systems and Organizations and supports Executive Order 14306 on secure software development practices. It provides architectural considerations and emphasizes the importance of Secure by Design principles for interoperable defense across cloud environments.
www.cisa.gov
September 15, 2026 at 2:06 PM
The NIST report is full of errors, lies and ommisions. And yes, I do have an engineering degree. Just like you, at first I believed what corporate media told me. But after careful analysis it has overwhelmingly been shown that the THREE bldgs did NOT collapse due to planes. I wish you well. Peace.
September 13, 2026 at 8:56 PM
Yes it does. Floors weighing 700-1700 metric tonnes each pancaking on top of each other when lower floors failed due would pulverize anyone and lead to collapse due to the novel building design. NIST report details all this. Good luck with the "engineering" degree.🙄
en.wikipedia.org/wiki/Collaps...
September 13, 2026 at 8:00 PM
Reproducible Design-Space Study of Lightweight Lattice-Based Authentication and Signatures for Blockchain Transactions (Zhiqian Lin) ia.cr/2026/1925
September 12, 2026 at 11:01 PM
They even got NIST to play along. That’s some next level planning for the inside job.
Final Report on the Collapse of World Trade Center Building 7, Federal Building and Fire Safety Investigation of the World Trade Center Disaster (NIST NCSTAR 1A)
This report describes how the fires that followed the impact of debris from the collapse of WTC 1 (the north tower) led to the collapse of WTC 7; an evaluation
www.nist.gov
September 12, 2026 at 1:51 AM
I did. NIST was forced to change their report on Building 7 and had to admit that it did indeed experience free fall. Free fall means falling at the rate of gravity. How could that be when building 7 was not hit by a plan?
September 12, 2026 at 1:36 AM
Although at first trying to deny it, NIST in its final report admitted the fact that the building collapsed at a rate indistinguishable from the acceleration of gravity — "free fall" — for a distance of about 8 stories.
4/5
September 11, 2026 at 7:07 PM
Think what you want.

I downloaded the 10,000 page NCSTAR1 report by the NIST and burned it to DVD in 2007. I searched it and read every paragraph containing the words 'steel' or 'concrete'.

Believing and Knowing are two different things.
September 11, 2026 at 6:17 PM
Final report by the NIST, in extensive and exhausting detail www.nist.gov/el/final-rep...
Final Reports from the NIST World Trade Center Disaster Investigation
www.nist.gov
September 11, 2026 at 5:50 PM
just to point out, the NIST report is full of shit 👇
wtc 7 is a whole topic. the excuse that a knocked out column destabilized the structure doesn't really hold water to me, especially when other buildings between didn't collapse. I know there was a gash in the facade, but this wouldn't cause total collapse either
September 11, 2026 at 11:10 AM
thing is though, the NIST report did investigate whether explosives should have been used, but they only considered high powered explosives like RDX and not linear charges or thermite charges. they also say someone would have been seen installing them but failed to consider the mechanical floors
September 11, 2026 at 10:52 AM
Mach dich doch bitte mal zum Thema schlau. Das Paper hier im ASCE Journal ist ein guter Überblick. Falls du keinen Zugang hast, musst du dich halt durch den NIST-Report zu WTC 7 durchkämpfen.

ascelibrary.org/doi/full/10....
Analysis of Structural Response of WTC 7 to Fire and Sequential Failures Leading to Collapse | Journal of Structural Engineering | Vol 138, No 1
This paper presents the structural analysis approach used and results obtained during the investigation conducted by the National Institute of Standards and Technology (NIST) to model the sequence of fire-induced damage and failures leading to the global ...
ascelibrary.org
September 11, 2026 at 8:00 AM
The Qubit Report: September 10, 2026

Read more:
https://thequbitreport.com/the-qubit-report/2026/09/10/the-qubit-report-september-10-2026/
The Qubit Report: September 10, 2026
Thursday brief: IBM and Lockheed Martin site a System Two in Lugano, EuroHPC books IQM in Kajaani, Cloudflare validates ML-DSA-44 DNSSEC, and NIST TES arrays tighten nuclear X-ray counts.
thequbitreport.com
September 11, 2026 at 1:07 AM
In the 585 page 9/11 Commission Report, collapse of WTC 7 is never mentioned.

Principal conclusion of UAF study is that fire did not cause the collapse of WTC 7 contrary to the one reached by NIST.

Firefighters heard explosions along with advanced collapse warnings, hours before WTC 7 collapsed.
September 10, 2026 at 10:50 PM
In the 585 page 9/11 Commission Report, collapse of WTC 7 is never mentioned.

Principal conclusion of UAF study is that fire did not cause the collapse of WTC 7 contrary to the one reached by NIST.

Firefighters heard explosions along with advanced collapse warnings, hours before WTC 7 collapsed.
September 10, 2026 at 2:25 PM