ONLINE
LA--:--:--
ATL--:--:--
LDN--:--:--
LIVE WIRE
BIOAUTH SDK — Bio-Log In and Account Recovery with no humans and no backdoor, goes live September 15thENTERPRISE — Biometric + Persistent Liveness authority for human and agent work sessions, with logs and receipts. Launching Oct 15, 2026DEEPFAKE DETECTION market expands as Deloitte projects up to $40B in US generative-AI fraud losses by 2027REGULATORS move on authoritative records — SEC proposes first transfer-agent modernization in ~50 years, contemplating authoritative onchain ownership recordsBIOAUTH SDK — Bio-Log In and Account Recovery with no humans and no backdoor, goes live September 15thENTERPRISE — Biometric + Persistent Liveness authority for human and agent work sessions, with logs and receipts. Launching Oct 15, 2026DEEPFAKE DETECTION market expands as Deloitte projects up to $40B in US generative-AI fraud losses by 2027REGULATORS move on authoritative records — SEC proposes first transfer-agent modernization in ~50 years, contemplating authoritative onchain ownership records
Good Bot, Bad Bot — BioAuth newsletter

We write about authenticating humans and agents, strengthening account recovery, and producing useful authorization records. New issues, straight to your inbox.

Your AI Agent Is Running on Your Employee’s Credentials. Nobody Authorized That.

ISSUE #5 · September 2026

Your AI Agent Is Running on Your Employee’s Credentials. Nobody Authorized That.

When Claude Code runs a command, it isn’t impersonating your developer — it IS your developer, using their real session. That collapses the line between who authenticated and who is acting, and no MFA, device-posture, or short-lived token can answer the only question that matters for agentic work: did a human authorize this action, right now? Activity logs record it; they can’t prove who authorized it. BioAuth Power of Agent is designed to give software agents scoped authority and signed receipts tied to human approval, so applications can distinguish authorized activity from an unapproved shadow agent.

Read Issue #5
The Attacker Didn’t Steal an Admin Token. It Minted Its Own.

ISSUE #4 · September 2026

The Attacker Didn’t Steal an Admin Token. It Minted Its Own.

CVE-2026-82329 doesn’t steal admin tokens — it mints them. When token issuance itself is compromised, rotation, short lifetimes, and device binding all fail, because the forged token is freshly and validly minted. Every downstream build system that trusts Artifactory becomes a supply-chain breach candidate. The one property that survives an issuance bypass: a forged token has no human principal behind it. BioAuth Power of Agent is designed to let applications require scoped human-approved authority and a verifiable receipt before accepting a supported agent action.

Read Issue #4
Eight AI Agents Breached 21 Government Systems in Four Days. No Human Needed.

ISSUE #3 · August 2026

Eight AI Agents Breached 21 Government Systems in Four Days. No Human Needed.

Eight simultaneous AI agents mapped 21 government systems, compromised 85 accounts, and exfiltrated 2,500+ personnel records in four days — no human in the loop. The authentication stack they traversed was built for human-paced adversaries. BioAuth recovery is designed to resist remote social engineering, while Power of Agent adds scoped authority and auditable receipts for agent actions.

Read Issue #3
They Didn’t Steal the Passkey. They Stole the Enrollment.

ISSUE #2 · August 2026

They Didn’t Steal the Passkey. They Stole the Enrollment.

O-UNC-066 bypasses phishing-resistant auth entirely by attacking the enrollment event before the passkey exists. Enrollment workflows can still be targeted through remote social engineering. BioAuth addresses enrollment and recovery with device-mediated user approval, verification controls, and auditability intended to reduce the risk that remote social engineering becomes persistent account access.

Read Issue #2
165 Enterprises. Zero Zero-Days. Just a Phone Call to the Help Desk.

ISSUE #1 · August 2026

165 Enterprises. Zero Zero-Days. Just a Phone Call to the Help Desk.

The Snowflake breach showed why strong login controls must be paired with strong recovery controls. BioAuth recovery is designed to reduce reliance on routine support resets while keeping account restoration verified, policy-controlled, and auditable.

Read Issue #1

Get Good Bot, Bad Bot

New issues, straight to your inbox. No 2FA required.

Identity, authentication, and the slow death of the password — a few times a month. No spam, ever. Unsubscribe anytime.