NIST and CISA finalize playbook to stop token theft and forgery
NIST and CISA published NIST IR 8587 with recommendations to protect tokens and assertions from forgery, theft, and abuse. The guide covers signing key management, token validation, lifetime and revocation, and responsibility sharing between cloud providers and their customers.
- NIST IR 8587 covers signing key protection and token validation
- Attack example: over 60,000 emails stolen from one government agency's accounts
- Recommendations cover SSO, identity federation, and API access
- Token protection advised for AI agents too
Read next
Security