NIST and CISA Release Interagency Report on Protecting Tokens and Assertions from Forgery and Misuse
Guidance issued for federal agencies and cloud service providers to secure identity assertions and access tokens in hybrid and multi-cloud environments.
Key Takeaways
- NIST and CISA released a final interagency report on securing tokens and assertions in hybrid and multi-cloud environments.
- The report addresses risks of token forgery, theft, and misuse that could enable lateral movement.
- Guidance includes recommendations on token validation, secrets management, and detection at scale.
- Feedback was incorporated from the Joint Cyber Defense Collaborative and industry experts.
- The guidance supports Secure by Design principles and Executive Order 14306.
Related Security News

Misconfigured Supabase Apps Expose Data in Over 16,000 Databases
Security researchers have identified more than 16,000 Supabase-backed applications with publicly accessible databases. The exposure stems from default allow rules that permit unrestricted read access to tables containing personally identifiable information, passwords, and authentication tokens. The findings highlight the risk of misconfigured backend-as-a-service platforms when security defaults are not adjusted for production use.

CISO-CMO Alliance Emerges as Strategic Imperative for Cybersecurity-Brand Reputation Alignment
A recent Dark Reading analysis explores how organizations can strengthen governance by establishing regular touchpoints and joint crisis communications plans between Chief Information Security Officers and Chief Marketing Officers. The article emphasizes that translating security risks into brand impact is essential for maintaining stakeholder trust.

_Dzmitry_Skazau_Alamy.jpg?width=720&quality=80&disable=upscale)
