Back Issues/Search Home → Calendar → Archive → Current Issue → Popular →

All issuesVolume 335, Issue 1IT Vendor NewsCyberArk

Contain The Sso Blast Radius: Identity Security Beyond MFA

CyberArk, Wednesday, February 4th, 2026

Over the past week, multiple research teams have documented a renewed wave of voice-led social engineering (vishing) targeting identity providers and federated access. The entry point is not through malware or a zero-day exploit.

The goal is simple. Persuade a user to help complete authentication in real time, then use that trusted session to move through SaaS applications and exfiltrate data.

Security leaders already know the fundamentals. Multi-factor authentication (MFA) can be socially engineered. Single sign-on (SSO) concentrates trust. Uncontrolled privilege can turn one compromised identity into a broader incident.

more →  ·  More from CyberArk →