Skip to content
Braincap
← All articles

Blog

Email & identity

Illustration: a phishing email posing as a 1Password security alert, with the signs that give it away, luring the victim to a fake page that harvests the master password

Phishing that impersonates 1Password: the password vault has become a target

A phishing email impersonating 1Password, with a fake "new browser detected" alert, landed in an inbox. It is not a 1Password breach, it is impersonation, and it is part of a real wave confirmed by 1Password itself and documented by researchers. Why password managers have become targets, how to recognize the lure, and how to protect your vault.

Read the article
Illustration: a SOC 2 audit with every control ticked green, while an AI agent passes through it wearing a human's borrowed identity, with no known owner

SOC 2 and AI agents: an audit built for humans does not see autonomous actors

SOC 2 assumes a human is behind every action: someone approves the account, the account has an owner, the name in the log is the actor. An autonomous AI agent breaks every assumption and can pass the controls with no owner and no attribution. What breaks, what the CSA numbers say (68% cannot tell agent from human), and what to do now, including why ISO 27001 is affected too.

Read the article
Illustration: an identity card with every field redacted except a cryptographically signed proof that the holder is over 18

How digital identity actually helps privacy: selective disclosure and the EUDI wallet

Digital identity can increase privacy rather than erode it, if it uses the right cryptography: you prove one attribute, for example that you are over 18, without revealing your identity. What selective disclosure is, how the EUDI wallet works (mandatory across the EU and Romania by the end of 2026) and where it is not magic: SD-JWT is not unlinkability.

Read the article
Illustration: the Azure cloud stays intact, with a check mark, while a customer tenant's padlock is opened with a key stolen from outside — not a platform breach, but compromised credentials

A 3.6-million "Azure records" theft: not a Microsoft breach, but tenant credential theft

An attacker is selling 3.64 million employee records "stolen from Azure" belonging to McDonald's, Vodafone, TCS and others. But it is not a breach of the Microsoft platform: it is credential theft (password spray + MFA fatigue + infostealers) against customers' tenants. That is why Microsoft stays silent, and why push-only MFA is the weak link.

Read the article