ONLINE
LA--:--:--
ATL--:--:--
LDN--:--:--
LIVE WIRE
FACEIN.ID SDK — passwordless login for your app — targeting public launch Friday, July 31, 2026HUGGING FACE confirms a breach exposing internal datasets and credentials — another reminder that stored secrets are the targetDEEPFAKE DETECTION market expands as Deloitte projects up to $40B in US generative-AI fraud losses by 2027FACEIN.ID SDK — passwordless login for your app — targeting public launch Friday, July 31, 2026HUGGING FACE confirms a breach exposing internal datasets and credentials — another reminder that stored secrets are the targetDEEPFAKE DETECTION market expands as Deloitte projects up to $40B in US generative-AI fraud losses by 2027
thePasswordlessPOSTIDENTITY · ACCESS · SECURITY

Identity, authentication, and the slow death of the password. New issues, straight to your inbox — no 2FA required.

The Industry Just Started Writing the Rules for How AI Agents Prove Who They Are. That’s Our Sentence to Finish.

ISSUE #9 · July 2026

The Industry Just Started Writing the Rules for How AI Agents Prove Who They Are. That’s Our Sentence to Finish.

NVIDIA, Microsoft, Cisco, Cloudflare, CrowdStrike, IBM, Palo Alto, and the Linux Foundation launched the Open Secure AI Alliance (Apache-2.0 NOOA framework) to define how AI agents authenticate. The fear: does FIDO/WebAuthn get baked in before we’re at the table? The answer: WebAuthn is FaceIn’s foundation, agent identity is the same secretless problem as human login, and the move is offensive — own device-bound, non-repudiable identity for humans AND the agents they deploy.

Read Issue #9
A Keylogger Kit Is Circulating on Telegram. If Your Users Type Their Login, It Already Won.

ISSUE #8 · July 2026

A Keylogger Kit Is Circulating on Telegram. If Your Users Type Their Login, It Already Won.

The Flying Eagle RAT — a payment-auth, keystroke, and screen-capture kit whose C2 Hunt.io traced to ~170 servers — is circulating on Telegram, impersonating banking, government, and adult-content apps. Every control that relies on a typed secret is in its field of view. FaceIn’s secret never leaves the device and is never typed: architecturally immune, not merely hardened.

Read Issue #8
One Credential Unlocked 1.2 Million Records. That’s Not an SSO Bug — It’s the SSO Bargain.

ISSUE #7 · July 2026

One Credential Unlocked 1.2 Million Records. That’s Not an SSO Bug — It’s the SSO Bargain.

BleepingComputer and Specops resurface the University of Pennsylvania SSO breach — one compromised PennKey, ~1.2 million records — alongside NIST SP 800-63B’s shift to a 15-char single-factor minimum, 8-char with MFA, and mandatory breach-list screening. One key, every door. FaceIn puts unstealable proof behind your identity provider: nothing reusable to phish, reuse, or screen.

Read Issue #7
An AI Agent Ran a Full Attack Unattended. The Only Audit Trail Was the One the Attacker Left by Mistake.

ISSUE #6 · July 2026

An AI Agent Ran a Full Attack Unattended. The Only Audit Trail Was the One the Attacker Left by Mistake.

Threat actors ran the open-source Hermes agent in “YOLO” mode against Thailand’s Ministry of Finance — autonomous recon, data access, and malware staging with no human in the loop and no audit trail, until 470 MB of attack tooling spilled into a public directory. The enterprise lesson: bind every agent action to an identity that can’t be forged or shared.

Read Issue #6
You Starred the Repo, Installed the MCP Server, and Handed Over Every Token You Own

ISSUE #5 · July 2026

You Starred the Repo, Installed the MCP Server, and Handed Over Every Token You Own

FakeGit cloned 7,600 real repos, dressed them as AI skills and MCP servers, and dropped the StealC infostealer to sweep passwords, cookies, and tokens off developer machines. MCP connections are the new risky OAuth. FaceIn empties the loot list: no reusable secret to lift, and account recovery with no backdoor.

Read Issue #5
Your Coding Agent Escaped Its Sandbox. Your Platform’s AI Couldn’t Investigate the Breach.

ISSUE #4 · July 2026

Your Coding Agent Escaped Its Sandbox. Your Platform’s AI Couldn’t Investigate the Breach.

Pillar Security showed Cursor, Codex, Gemini CLI, and Antigravity all sandbox-escaped via file writes that trusted host tools later executed; Hugging Face’s AI-driven breach fanned across a swarm of short-lived sandboxes, and its own hosted models blocked the forensic response. FaceIn leaves nothing on the other side of a broken boundary worth stealing.

Read Issue #4
The AI You Trusted With Your Files Was Reading All of Them

ISSUE #3 · July 2026

The AI You Trusted With Your Files Was Reading All of Them

Claude Cowork’s SharedRoot sandbox escape let an AI assistant walk out of the folder you shared and into the rest of your drive — files, credentials, session tokens and all. A boundary failure in an agent is a different category of bad. The fix: don’t leave the keys lying around.

Read Issue #3
Apple’s “Hide My Email” Was Showing Your Email

ISSUE #2 · July 2026

Apple’s “Hide My Email” Was Showing Your Email

A flaw in iCloud+’s Hide My Email leaked users’ real addresses into mail logs — unmasking the privacy layer they paid for. Patched July 3, 2026, 13 months after disclosure. The fix isn’t a better mask; it’s not having the email at all.

Read Issue #2
24 Billion Passwords Walk Into a Server Room

ISSUE #1 · July 2026

24 Billion Passwords Walk Into a Server Room

24 billion stolen credentials just surfaced in one exposed database — and the same 2FA that failed to stop the breach blocked my AI agent from subscribing to a cybersecurity newsletter. We’ve been asking the wrong question.

Read Issue #1

Get The Passwordless Post

New issues, straight to your inbox. No 2FA required.

Identity, authentication, and the slow death of the password — a few times a month. No spam, ever. Unsubscribe anytime.