New Guidance Aims to Stop Attackers Forging Login Tokens in Cloud Systems
As more businesses rely on cloud services, single sign-on and app-to-app connections, security increasingly depends on digital tokens and identity assertions that prove who a user or system is. These tokens are becoming a prime target for attackers, who can forge, steal or misuse them to move around a network undetected and reach sensitive data without needing a password.
A new joint report from the US National Institute of Standards and Technology (NIST) and the Cybersecurity and Infrastructure Security Agency (CISA) sets out recommendations for protecting these authentication mechanisms. While aimed primarily at government agencies and cloud providers, the guidance reflects issues relevant to any organisation using cloud platforms, covering how to properly validate tokens, manage secrets such as keys and credentials, and detect misuse at scale. It builds on established security control frameworks and promotes 'Secure by Design' principles so that systems are built to resist these attacks from the ground up.
Although written with US federal requirements in mind, the underlying risks apply to any Australian business using cloud identity systems such as single sign-on, Microsoft 365, Google Workspace or API-connected services.