ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

NIST finalizes IR 8587 playbook to defend identity tokens from theft and forgery

infoAdvisoryimportance 60
What's new: This is the first merged summary for this story. NIST (with CISA's involvement per one source) published the finalized IR 8587 on September 15, 2026, codifying identity-token defense practices for SAML, OIDC, and OAuth 2.0, formally extending token protection guidance to AI agents, and directing agencies and cloud providers to prepare identity systems for the future post-quantum cryptography…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

NIST IR 8587, released September 15, 2026, gives federal agencies and cloud providers implementation guidance to prevent theft, forgery, and misuse of identity tokens across SAML, OpenID Connect, and OAuth 2.0. It is motivated in part by a forged-token attack…

NIST Internal Report (IR) 8587 was released September 15, 2026, providing recommendations covering token creation, signing, validation, storage, revocation, lifecycle management, and session management. Help Net Security reports the playbook was finalized by NIST and CISA, while GBHackers attributes the release to NIST. The guidance builds on NIST SP 800-53 Rev. 5.1.1 and incorporates lessons from breaches involving stolen signing keys, abused OAuth applications, and replayed federated assertions. It urges treating tokens as high-value credentials equivalent to authenticated sessions and defines shared security responsibilities between cloud providers and customer organizations. Recommendations include strong signing algorithms, cryptographic key protection and rotation, strict claim validation, short token lifetimes, token binding, leakage prevention, and continuous monitoring for abnormal use such as impossible travel and suspicious token reuse patterns. The report also promotes secure-by-design defaults from cloud service providers and extends token protection guidance to AI agents, with preparation for a future post-quantum cryptography transition.

  • Guidance document: NIST Internal Report (IR) 8587, released September 15, 2026.
  • Attribution differs by source: Help Net Security says NIST and CISA finalized the playbook; GBHackers says NIST issued the guidance.
  • Scope: identity tokens, access tokens, and federated assertions across SAML, OpenID Connect, and OAuth 2.0 environments.
  • Builds on NIST SP 800-53 Rev. 5.1.1.
  • Cited incident: foreign actors forged tokens with a stolen commercial signing key to steal more than 60,000 emails from one government agency.
  • Key recommendations: key protection and rotation, strong signing algorithms, strict claim validation, short token lifetimes, token binding, leakage prevention, and revocation controls.
  • Monitoring guidance: detect impossible travel and suspicious token reuse patterns; treat tokens as high-value credentials equivalent to authenticated sessions.
  • Defines shared responsibilities between cloud providers and customer organizations; promotes secure-by-design defaults from cloud service providers.
VendorsNISTCISA

Coverage timeline

  1. · 2h ago
    Help Net Security· 60
    NIST and CISA finalize playbook to stop token theft and forgery

    NIST and CISA finalized NIST IR 8587, a playbook helping federal agencies and cloud providers defend identity tokens against theft and forgery.

  2. · 2h ago
    GBHackers· 58
    NIST Issues New Guidance to Protect SSO and API Tokens From Theft and Forgery

    NIST released IR 8587 giving agencies and cloud providers recommendations to prevent identity token forgery, theft, and misuse in SSO and API environments.