
NIST Finalizes Guidelines on Protecting Online Identity and Access Tokens From Misuse
NIST has finalized a publication offering guidelines to help organizations protect online identity and access tokens from misuse. The guidance is designed to help organizations take effective steps to avoid exposing tokens to attackers.
Sources and evidence
Summary last validated Sep 15, 2026
Reader actions
Report an issue
Use this for an incorrect summary, wrong source, duplicate story, or wrong category. Submissions are private and do not change the story automatically.
Related coverage
- security
Microsoft urges early testing of post-quantum certificate ecosystems
Microsoft published guidance urging organizations to begin testing certificate ecosystems for post-quantum authentication now, highlighting its PQC TLS Pilot Program as a way to advance future readiness. The post appeared on the Microsoft Security Blog.
- security
CISA: Chinese Government-linked Hackers Target US Critical Infrastructure
CISA published an advisory stating Chinese government-linked cyber threat actors, enabled by China-based Integrity Technology Group, combine automated scanning, botnets, and hands-on exploitation to steal sensitive data from organizations worldwide, including US critical infrastructure. Tactics include cross-site scripting and password spraying on Microsoft Exchange servers, VPN persistence, and email and credential exfiltration via scripts.
- research
NIST Study Maps How Toxic Adulterants in Fentanyl Vary Across US
NIST researchers analyzed fentanyl samples nationwide and found that the toxic substances mixed into the drug vary by region and shift over time. The study aims to help first responders and law enforcement identify dangerous adulterants in local supplies, which the agency says can help save lives.
- policy
NIST Joins White House Effort to Drive 'A New Golden Age of Science'
NIST announced it is joining a White House effort aimed at driving what is described as 'A New Golden Age of Science.' The agency said that as the nation's lead agency for measurement science and standards, it is uniquely positioned to bridge the distance between fundamental discovery and industrial capability.
- security
Cisco Talos Ties UAT-11985 to AI-Assisted Google AitM Phishing
Cisco Talos identified an APT spear-phishing campaign, tracked as UAT-11985, targeting individuals affiliated with Taiwan research organizations. The operation used legitimate public event themes and impersonated reputable academic and policy institutions, delivering real-time Google adversary-in-the-middle phishing.