Home / Companies / FusionAuth / Blog / August 2026

August 2026 Summaries

2 posts from FusionAuth

Filter
Month: Year:
Post Summaries Back to Blog
AI agents amplify long-standing identity and security challenges because they can act continuously and at machine speed using delegated human or organizational authority, making overly broad permissions and weak controls more consequential. The text argues that although AI decision-making is probabilistic, authorization must remain deterministic through clear verification of identity, authority, access scope, trust sources, and audit history. FusionAuth 1.69 introduces controls intended to reinforce this identity layer, including RFC 9207 issuer identification to help prevent authorization-server mix-up attacks, configurable JWT signature verification key selection to reduce unnecessary trust relationships, an AI Agent Entity Type and lifecycle webhooks for monitoring non-human identities, and browser SDK support for DPoP sender-constrained tokens that reduce the risk of stolen-token replay. The release also includes SAML, password import, group auditing, runtime, dependency, and security updates, reflecting the broader need to maintain core identity infrastructure as AI deployments accelerate faster than many organizations’ existing security capabilities.
Aug 25, 2026 1,213 words in the original blog post.
Adaptive MFA adjusts authentication requirements according to the contextual risk of each login, addressing the usability limitations of traditional MFA while preserving stronger protection against credential theft and account takeover. It evaluates factors such as device familiarity, network and IP reputation, location, login time, recent account changes, and behavioral patterns, allowing routine low-risk logins to proceed with less friction while requiring additional verification for suspicious activity. This approach can improve MFA adoption, reduce support burden, and support consistent security policies across IAM, CIAM, SSO, SIEM, and other enterprise systems, though implementation may require investment and policy configuration. The discussion highlights FusionAuth 1.68’s Intelligent MFA as an example of a modern implementation that uses up to ten deterministic risk signals, including impossible travel, dormant accounts, suspicious browsers, bot activity, and stale credentials, to produce explainable, logged challenge decisions that can support compliance and auditing requirements.
Aug 07, 2026 2,258 words in the original blog post.