CISA and NIST released Interagency Report (IR) 8587, Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers, the final version of guidance covering the identity tokens and assertions that underpin single sign-on, federation and API-based access in federal cloud environments. The agencies frame the target directly: these are the systems adversaries increasingly attack in order to move laterally through enterprise networks and reach sensitive data, and the practical goal of the report is that a stolen or forged credential cannot become a foothold across an enterprise. The final report incorporates feedback from nearly 250 public comments on token validation, secrets management and detection at scale, and reflects CISA's work with cloud service providers and interagency partners through the Joint Cyber Defense Collaborative โ including a June 2025 technical exchange with more than 50 industry experts and a January 2026 webinar on the draft, with individual engagement sessions involving Google, HashiCorp, IBM, Microsoft, Okta, the OpenID Foundation, Oracle, Amazon Web Services and Wiz. Substantively it expands on Release 5.1.1 of NIST SP 800-53 and its IA-13 control, and provides architectural considerations for identity providers and authorisation servers, enhancements to key management and token verification and token-lifecycle controls, guidance for securing SSO, federation and API access built on digitally signed and asymmetrically encrypted tokens, and principles for configurable, transparent and interoperable controls supporting threat-adaptive defence across cloud environments. The recommendations apply across commercial and government-operated cloud services and support the secure-software-development requirements of Executive Order 14306. On the same day, China's intelligence chief was naming US AI models as a cyber risk to Chinese critical infrastructure โ a reminder that identity infrastructure is now treated as strategic terrain by both sides. The operational reading for non-US organisations is that the report is the most concrete public specification available for the token-theft problem that defeats MFA without touching the password.
| Attribute | Detail |
|---|---|
| Sector | Government |
| Date | 2026-09-16 |
| Source | CISA |
| Reliability | Tier 1 |