CISA and NIST released NIST IR 8587, Protecting Tokens and Assertions from Forgery, Theft, and Misuse, with implementation recommendations for federal agencies and cloud service providers using tokens in single sign-on, identity federation, API access, and workload-identity environments. Developed through CISA’s Joint Cyber Defense Collaborative in support of Executive Order 14306, the final report addresses attacks involving token forgery, theft, replay, weak validation, compromised signing keys, and misuse—risks that can allow attackers to bypass multifactor authentication.
The guidance calls for protected signing-key management, rigorous token verification, short validity periods, credential scoping, revocation and replay controls, sender-constrained tokens, and continuous monitoring. It also covers token exposure in CI/CD pipelines, machine-to-machine and agentic-AI use cases, and preparation of public-key infrastructure for post-quantum cryptographic migration; the final version incorporates feedback from nearly 250 public comments and more than 20 contributors.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
CISA and NIST released NIST Interagency Report 8587, “Protecting Tokens and Assertions from Forgery, Theft, and Misuse,” with implementation recommendations for federal agencies and cloud service providers. The final guidance covers protections for tokens used in single sign-on, federation, APIs, and workload identities, including signing-key management, validation, lifecycle, replay resistance, and monitoring controls.
NIST and CISA collected feedback on the developing token and assertion security guidance through a public webinar, alongside Joint Cyber Defense Collaborative engagement.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourcecsrc.nist.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.