Identity Security Insights 26.08

🆕 New features

Device code phishing detections

Device code phishing is hard to spot from the inside: a legitimate Microsoft prompt, a real user, and a clean successful sign-in. Six new detections match your Entra ID sign-in activity against the infrastructure behind four active token-theft campaigns, and flag the accounts caught in them along with the device registrations and token replay attackers use to maintain access.

Connect Entra ID to surface compromised users with the attacker IPs, user agents, and timeline you need to start revoking access.

  • Named campaign attribution on compromised accounts. Sign-ins are matched against infrastructure tied to Tycoon 2FA, DEBULL, and the EvilTokens/Railway operation, plus a fourth variant that Phantom Labs™, the BeyondTrust research team, surfaced independently and tracks in-house. Each finding names the campaign that hit the account and states whether access succeeded or every attempt was blocked, so you can tell at a glance whether a genuine compromise occurred.
  • Persistence that survives a password reset. Rogue device registrations from automated tooling and FOCI token replay are flagged in their own right. These are the moves attackers use to hold a Primary Refresh Token and pivot into Exchange Online and Microsoft Graph long after the original phish, and neither one clears when you reset the password.
  • What the first hour of response needs. Findings carry attacker IPs and ASNs, user agents, targeted applications, sign-in counts split by success and failure, and first- and last-seen timestamps. Each is paired with ordered remediation covering session revocation, MFA re-registration, removal of unrecognized devices, and the Exchange audit trail to check for inbox rules and forwarding.
Claude Platform API key findings

Long-term API keys for Claude Platform on AWS now sit alongside existing Bedrock key coverage. Six new findings are split evenly between detections that fire the moment a key is created or used, and recommendations that stand for as long as the key is still there.

Together, they flag:

  • Long-term keys created or sitting with an expiration date, and keys with no expiration date at all
  • Calls made with a bearer key instead of IAM credentials or temporary session tokens
  • The IAM users AWS auto-provisions during key generation that outlive the keys themselves

Bedrock key usage tracking extends to an additional endpoint at the same time, so both platforms report through one lens.

✨ Enhancements

True Privilege Graph on the identity side panel

Many identities are meant to hold high privilege. What's harder to see is whether they arrived there the way you intended, or picked it up through a nested group, an owned application, or an account nobody was tracking.

The True Privilege Graph now appears on the Overview tab of the identity side panel, drawing every route from a person to everything they can reach.

  • One graph for the whole person. The graph roots at the identity and fans out across every account tied to them, so you see one individual's full reach instead of assembling it account by account. Grouping, expanding, and fullscreen work the same as they do on your other graphs.
  • Opens focused on the privilege worth your attention. The graph starts filtered to High and Highest paths, and you can adjust the filter to widen or narrow what's drawn. Each level you select is drawn on its own rather than as a "this level and above" threshold, so Moderate shows Moderate paths specifically. Privilege escalation paths stay on the canvas whatever you select, so a route that elevates access is never hidden.
  • Learn what a path means. Select a path and click Explain Path for a written breakdown: what the path grants in practice, a risk assessment, a worked exploitation scenario showing how the chain could be abused, and a walkthrough of each node and edge with the permissions involved and what to do about them.
  • Details on hover. Node tooltips show provider, type, direct and true privilege, and the permissions behind the node, with a link through to that entity's own side panel.
ℹ️

Explain Path is available in the US region only.

©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.