Skip to main content
Identity Has Become the Only Perimeter That Matters

The Red Queen Is Real: Identity Has Become the Only Perimeter That Matters

Attackers are accelerating. AI tooling has lowered the cost of sophisticated campaigns to near zero, while the scale of attacks has expanded across every phase of the attack chain — reconnaissance, initial access, lateral movement. The 2025 Tidal Cyber Threat Led Defense Report confirms what security leaders already understand: defenders no longer hold an inherent speed advantage. This is the Red Queen dynamic. Running harder sustains position. It does not advance it. But there is a more precise problem underneath the noise. Phishing and social engineering have changed structurally. Training-based defenses, however disciplined, are now insufficient by design. The architecture of the threat has shifted. The architecture of the response must follow.

Kevin Surace
3 minute read
The Authentication Architecture Problem

Wynn Resorts Breach: The Authentication Architecture Problem

Cybercriminals claiming affiliation with the ShinyHunters group have reportedly breached Wynn Resorts, demanding $1.5 million to prevent the release of stolen data. If accurate, the intrusion follows a pattern that has now repeated itself across hospitality, retail, insurance, and aviation. (Read the full article on Casino.org) The method is consistent. The attackers did not defeat network defenses. They authenticated.

Kevin Surace
2 minute read
Tycoon 2FA is down but the attack model is not

Tycoon 2FA Is Down. The Attack Model Is Not

Microsoft, Europol, Trend Micro, and a global coalition just disrupted Tycoon 2FA — one of the most prolific phishing-as-a-service platforms ever documented. That is a meaningful outcome. It is not safety. Tycoon 2FA is offline. The attack model that made it successful is not.

Kevin Surace
2 minute read
Stryker cyberattack was an identity failure

They Didn't Hack Stryker. They Became Stryker's Admin

What happened at Stryker today isn't a malware story. It's an identity story. And it's one the industry has seen before — the Sony hack, twelve years ago, followed a similar path. A dozen years later, the attack surface has changed. The fundamental failure hasn't.

Kevin Surace
2 minute read

The Cybersecurity Industry Has a Terrifying Problem

A new summary of the MITRE ATT&CK Enterprise Round 7 evaluation reveals that the highest protection score any tested vendor achieved was a mere 31 percent — meaning that 69% of attacks went entirely undetected by even the best-performing vendor in the field. But the more significant finding was buried beneath that number. Across every identity-specific attack scenario in the evaluation, all vendors scored zero blocking — not partial detection, not near misses, but zero. The tools enterprises invest in to stop modern attacks did not intercept a single identity attack, which is precisely the class of threat that now defines the modern threat landscape.

Kevin Surace
4 minute read

The FBI Just Said It: Phishing-Resistant Authentication Is Job One

For years, security leaders have debated frameworks, tools, awareness programs, and incremental improvements to authentication workflows, while attackers continued to succeed through the same predictable path: logging in with stolen or relayed credentials rather than breaking through hardened infrastructure.

Kevin Surace
2 minute read

The Betterment Data Breach Should Have Ended the Debate

The Betterment breach should not have surprised anyone paying attention, and it certainly should have ended the long-running argument about whether modern MFA is sufficient against today’s attacks. Instead, it became just another entry in a growing list of incidents that organizations explain away as bad luck, poor training, or unfortunate human error.

Kevin Surace
3 minute read

Password Security Risks for Business

Passwords are the single most exploited element in enterprise security. Attackers do not need to break through perimeter defences. They obtain a valid credential and log in. Breach investigation reports confirm this year after year. Stolen or weak passwords are the starting point for the majority of enterprise incidents.

Kevin Surace
1 minute read

Your MFA Is Costing You Millions. It Doesn't Have To.

Most organizations still think of authentication as a cost of doing business.

Kevin Surace
1 minute read

AI Deepfakes Are Fueling Identity Fraud

Device-based biometrics are the Only Way to Restore It.

Kevin Surace
2 minute read

How Phishing Relay Attacks Bypass MFA

How a Phishing Relay Attack Works Phishing relay attacks do not break authentication. They sit in the middle of it. A phishing relay attack inserts an attacker-controlled proxy between the victim and the legitimate login portal. The victim believes they are on the real site. Every credential they enter goes to the attacker first. The sequence is predictable. The victim receives a phishing email linking to a page that looks identical to the real login portal. They enter their username and password. The attacker’s proxy forwards these to the real site immediately. The real site triggers an MFA challenge. The proxy mirrors that challenge back to the victim. The victim enters their six-digit code or approves a push notification. The attacker forwards the response. The real site authenticates the session. The exchange takes seconds. The victim has logged in. The attacker has the session.

Kevin Surace
2 minute read

The DoorDash Data Breach and the Legacy MFA Failure

Another Preventable Breach Another week. Another preventable breach. This time it is DoorDash, confirming that a social engineering scam gave attackers access to sensitive customer and driver information. But the real story is not the scam. The real story is the failure behind it.

Kevin Surace
2 minute read

Stay Identity Assured

Subscribe to The Assured Identity Brief for sharp insights on identity security, authentication, and the threats security leaders must stay ahead of.