Home / Companies / Descope / Blog / October 2025

October 2025 Summaries

9 posts from Descope

Filter
Month: Year:
Post Summaries Back to Blog
Telehealth has revolutionized patient care by providing unprecedented access to healthcare services, but it also presents significant cybersecurity challenges, with the healthcare industry experiencing a high number of data breaches, partly due to the growth of telehealth services. Protecting sensitive patient data requires robust cybersecurity measures, particularly surrounding authentication, which acts as a new perimeter in healthcare security. Employing modern authentication methods such as passwordless login, multi-factor authentication (MFA), and adaptive access control can enhance security while ensuring seamless user experiences for both patients and providers. These methods are crucial for complying with regulations like HIPAA and securing electronic protected health information (ePHI) against unauthorized access. Telehealth providers are encouraged to adopt a combination of these authentication strategies to balance robust access control with a frictionless experience, ensuring patient satisfaction and retention. Platforms like Descope offer no-code solutions to implement these secure, patient-friendly authentication methods quickly, helping organizations streamline their workflows and maintain compliance while enhancing user experience.
Oct 28, 2025 1,561 words in the original blog post.
The Model Context Protocol (MCP) is rapidly becoming a standard for AI system connectivity, adopted by major tech companies like OpenAI and Microsoft. However, this rapid deployment has exposed critical security vulnerabilities, with many MCP servers lacking proper authentication. The text explores several security threats, including tool poisoning, cross-server shadowing, server spoofing, and token theft, and provides mitigation strategies for each. Tool poisoning involves embedding malicious instructions in tool descriptions, while cross-server shadowing allows a malicious server to influence legitimate servers' tool usage. Server spoofing can lead to token theft and data exfiltration, with attackers using nearly identical server names to deceive users. The "Lethal Trifecta" highlights how natural language instructions, autonomous tool calling, and access to sensitive data can lead to significant security breaches. Additionally, rug-pull updates occur when a trusted tool becomes malicious, often going unnoticed due to a lack of notification for changes. To address these vulnerabilities, the text emphasizes the importance of implementing robust authentication, secure token management, and comprehensive monitoring. Descope offers solutions to these challenges, including MCP Auth SDKs, agentic identity control, and secure OAuth 2.1 authorization, helping developers build secure AI systems efficiently.
Oct 24, 2025 2,919 words in the original blog post.
Customer Identity and Access Management (CIAM) has become a critical element of modern digital infrastructure by ensuring security, compliance, and user experience across applications for external users like customers and partners. It focuses on authentication, authorization, and privacy, extending the principles of workplace IAM to broader audiences. The increasing importance of CIAM is driven by technological advancements and regulatory changes, such as the adoption of passwordless authentication, the rise of AI identities, and privacy mandates under frameworks like GDPR. Evaluating CIAM platforms requires considering security, user experience, scalability, developer experience, and integration capabilities. Descope emerges as a standout option due to its no-code/low-code approach, visual workflow editor, and support for modern authentication methods, offering flexibility for developers and seamless identity management across users, partners, and AI agents. Other notable platforms include Auth0, Amazon Cognito, Microsoft Entra External ID, Keycloak, and Firebase Authentication, each with unique strengths catering to different organizational needs.
Oct 23, 2025 2,052 words in the original blog post.
Keycloak is a popular open-source identity and access management solution favored for its flexibility and vendor-neutral deployment, but it poses challenges like complex setup, scaling issues, and maintenance burdens, prompting developers to seek alternatives. The text discusses several alternatives, including Descope, Amazon Cognito, Microsoft Entra External ID, FusionAuth, Authentik, and Ory Kratos, each offering different benefits to address Keycloak's shortcomings. Descope is highlighted for its fully managed IAM platform with visual workflow tools, Amazon Cognito for AWS integration and scalability, and Microsoft Entra External ID for its managed service with governance integration. FusionAuth and Authentik offer ease of setup and flexible hosting, with Authentik providing a lightweight open-source option. Ory Kratos is recognized for its API-driven headless architecture preferred for modern cloud-native applications. These alternatives offer varying degrees of flexibility, ease of use, and integration capabilities, catering to different technical requirements and enterprise needs.
Oct 20, 2025 2,286 words in the original blog post.
The Digital Operational Resilience Act (DORA) is a regulatory framework set to be fully enforceable from January 17, 2025, aimed at enhancing the cybersecurity and operational resilience of financial institutions and insurers in the European Union. It mandates strong cybersecurity measures, particularly in authentication and identity security, to prevent ICT incidents and manage third-party risks. Compliance with DORA involves adhering to five key pillars: ICT Risk Management, ICT Third-Party Risk Management, Incident Management and Reporting, Digital Operational Resilience Testing, and Information Sharing. Organizations must balance robust security controls with user experience, as overly stringent measures can lead to customer dissatisfaction. Descope offers solutions for DORA compliance that enhance security without compromising usability, such as adaptive and step-up authentication, phishing-resistant MFA, and comprehensive audit trails. These solutions aim to unify identity management across channels and maintain compliance while ensuring a seamless user experience.
Oct 17, 2025 1,824 words in the original blog post.
Ory Kratos is an open-source identity and user management system favored for its flexibility and self-hosting capabilities, but it often proves challenging for teams as projects scale and enterprise requirements emerge. Developers frequently seek alternatives due to issues like upgrade difficulties, high maintenance demands, limited enterprise and multi-tenancy support, and scaling complexity. Alternatives such as Descope, Supabase, Keycloak, Amazon Cognito, Microsoft Entra External ID, Authentik, and FusionAuth each offer different strengths, such as simplified operations, integrated services, extensive features, or ease of deployment, catering to various technical and operational needs. Descope, for instance, distinguishes itself with developer-friendly workflows and modern authentication features that simplify implementation and management, allowing developers to concentrate on product development rather than infrastructure maintenance.
Oct 06, 2025 2,224 words in the original blog post.
Artificial intelligence encompasses a wide range of technologies that support various functions, notably generative AI and agentic AI, which are reshaping work and security landscapes. Generative AI, such as OpenAI's ChatGPT, creates outputs like text, images, and code by predicting patterns from large datasets, while agentic AI builds on generative AI to execute tasks by chaining actions using tools and APIs. Despite their potential, these technologies face challenges like accuracy, security, and intellectual property issues, necessitating careful oversight and identity and access management to prevent unauthorized actions. As AI systems evolve, emerging protocols and adaptive identity management are essential for securely integrating AI into enterprise systems, with companies like Descope offering solutions to manage these interactions effectively.
Oct 02, 2025 1,371 words in the original blog post.
In May 2025, the Central Bank of the United Arab Emirates issued Notice 2025/3057, mandating the elimination of SMS and email one-time passwords (OTPs) for consumer-facing financial institutions by March 31, 2026, as part of a broader effort to combat rising digital fraud rates. The directive prohibits vulnerable standalone authentication methods such as SMS OTPs, which are susceptible to sophisticated attacks, and instead recommends secure alternatives like FIDO2 passwordless authentication, biometric verification, and real-time fraud detection systems. With the liability now shifted to financial institutions for any fraud involving SMS OTPs, banks are under pressure to adopt these advanced methods to reduce fraud, lower costs, and enhance user experience. The notice also requires integrating device, location, and behavioral analysis into fraud detection systems to identify and halt suspicious transactions. Descope, a platform offering no/low-code solutions, supports institutions in transitioning to compliant authentication methods quickly by providing tools like passkeys, adaptive MFA, and trusted device recognition, enabling a seamless shift away from legacy systems without extensive custom development.
Oct 02, 2025 1,799 words in the original blog post.
The discussion around "AI agents" and "agentic AI" often centers on the semantics rather than substantive differences, as both terms essentially describe AI systems with the capability to operate autonomously. "AI agents" typically refer to individual software entities performing specific tasks, while "agentic AI" suggests a broader paradigm of autonomous AI behavior. Despite the nuances in terminology—where "agentic AI" is a more recent term gaining popularity in business environments—both terms converge on the core concept of agency. While some argue that these distinctions can influence funding and adoption, the primary focus should remain on the practical applications and capabilities of AI with agency, such as in customer service, scheduling, and workflow automation. The effective implementation of these systems necessitates robust security and privacy measures, emphasizing the importance of identity and access management to prevent potential risks, with companies like Descope offering solutions to secure these AI systems.
Oct 01, 2025 1,318 words in the original blog post.