OAuth breaches expose SaaS identity weaknesses

Bleeping Computer

The gist

Identity is the new cybersecurity battleground, as AI-powered scams and OAuth chaos are blowing up the old perimeter and exposing gaping holes in SaaS and supply chain defenses.

What to know

Identity as the New Battleground

Attackers now mimic legitimate users and exploit device enrollment, inbox rules, and business workflows to stealthily bypass traditional defenses and maintain persistent access.

By late 2025, the defense paradigm against sophisticated identity-based threats like Scattered Spider had fundamentally shifted from traditional perimeter security to a holistic identity-centric approach. Organizations were urged to implement continuous identity posture hardening through comprehensive discovery and classification of all identities—including human, machine, API keys, and AI—across diverse environments such as IdPs, SaaS, cloud, and on-premises systems. This integrated strategy combined threat-informed risk modeling with continuous configuration audits to reduce privilege creep and minimize attack surfaces, reflecting a nuanced understanding that identity and credential threats demanded dynamic detection and response capabilities beyond static network defenses.

Late 2025 saw attackers exploiting Microsoft 365 identity features to maintain stealthy, persistent access, notably by enrolling devices to bypass MFA protections—a tactic that rendered password resets ineffective as attackers retained trusted device status. Coupled with this, adversaries like Atlas Lion leveraged Exchange inbox forwarding rules to covertly monitor victim communications and used internal resources such as SharePoint to conduct reconnaissance, effectively operating as insiders. Their ability to escalate privileges by mimicking legitimate business processes, such as submitting ServiceNow ticket requests aligned with past user behavior, underscored a sophisticated blend of social engineering and technical exploitation that blurred the lines between attacker and legitimate user activity.

The emergence of OAuth token abuse through device code phishing marked a significant evolution in identity-centric attacks by late 2025 and early 2026, with state-sponsored groups exploiting Microsoft’s OAuth 2.0 device code authentication flow to gain full Microsoft 365 account access. Attackers deployed phishing campaigns featuring legitimate Microsoft login pages prompting victims to enter device codes or grant permissions via fake OAuth consent screens, often using adversary-in-the-middle phishing kits like Tycoon to capture MFA tokens and session cookies in real time. Despite the proliferation of over two dozen malicious OAuth applications impersonating trusted enterprise services such as Adobe and DocuSign, the overall success rate of account takeovers remained relatively low, attributed to increased user vigilance and imperfect social engineering lures.

By early 2026, identity had unequivocally become the new cybersecurity perimeter amid the erosion of traditional network boundaries caused by cloud adoption and hybrid work models. Attackers escalated their sophistication by leveraging AI to impersonate legitimate users at scale, while novel tactics such as voice phishing (vishing), device code phishing, and MFA abuse targeted SaaS platforms like SharePoint. The Helix group exemplified this evolution, rapidly establishing persistence through registering new multi-factor authenticator apps and automating data exfiltration, with their tactics linked to predecessor groups like ShinyHunters and BlackFile. This continuity highlights an ongoing arms race where defenders must emphasize identity verification and behavioral anomaly detection to counter increasingly stealthy and adaptive identity-centric threats.

Sources
Software Analyst Cyber ResearchThreat Vector by Palo Alto NetworksCyberWire DailyTechRadarN2K NetworksPackt SecPro

AI Supercharges Global Cybercrime

AI-powered social engineering and regionally specialized threat groups have turned cybercrime into an industrialized, collaborative ecosystem that adapts faster than defenses.

By late 2025, financially motivated cybercrime dominated over 90% of daily attacks on businesses, with distinct regional specializations shaping a complex threat ecosystem. Eastern European and Russian groups orchestrated highly structured ransomware campaigns, while West African actors, particularly from Nigeria, focused on voluminous social engineering scams like business email compromise and romance scams that often funneled victims into broader fraud networks. Meanwhile, Southeast Asia’s industrialized 'pig butchering' scams exemplified AI-enabled long-form social engineering blending psychological manipulation with financial fraud, highlighting the operational sophistication and layered collaboration among cybercriminals.

Throughout 2025 and into early 2026, AI-powered social engineering attacks evolved rapidly, exploiting legitimate platforms and authentication flows to bypass traditional defenses. Over two dozen malicious OAuth applications mimicked popular enterprise services, while attackers leveraged Microsoft’s device code authentication to trick victims into surrendering tokens, complicating detection. This shift from high-volume botnets to targeted identity theft and MFA phishing underscored a cat-and-mouse dynamic where attackers innovated in response to improved defenses, as noted by the rise of MFA phishing campaigns adapting to widespread multi-factor authentication adoption.

By early 2026, the cyber threat landscape had become a tangled web of hybrid attacks involving nation-state actors, espionage groups, ransomware operators, and scam centers collaborating across geopolitical and physical domains. This convergence amplified identity risks and complicated detection, as attackers increasingly exploited legitimate signed software and platforms—such as digitally signed remote monitoring tools and fake video conference invites—to blend malicious activity into normal corporate traffic. The FBI’s warnings about ATM jackpotting attacks further illustrated the cross-domain collaboration, with over $20 million lost to criminals exploiting firmware and remote management vulnerabilities.

By mid-2026, AI-enabled social engineering had dramatically escalated the scale and sophistication of identity-based attacks, effectively eroding traditional network perimeters and shifting the cybersecurity battleground to identity itself. Modern cybercriminals increasingly prioritized stealing or imitating trusted identities over exploiting software vulnerabilities, rendering many conventional technical controls obsolete. This evolution necessitated a paradigm shift where organizations moved from controlling network access to continuously verifying identity trustworthiness, emphasizing the critical need for least privilege principles, conditional access policies, and heightened organizational awareness to counteract the complex, AI-empowered threat ecosystem fueled by cryptocurrency-enabled rapid money movement and token stealing.

Sources
CyberWire DailyCyberWire DailyCISO Talk by James AzarOnly Malware in the BuildingPackt SecPro

Klue Breach: OAuth Weaponized

The Klue supply chain attack exposed how legacy OAuth tokens and automated scripts enable mass data theft from trusted SaaS integrations—without ever breaching the core platform.

In June 2026, the Klue supply chain breach orchestrated by the Icarus extortion group exposed critical vulnerabilities in OAuth token management within SaaS ecosystems, enabling attackers to exploit a dormant legacy credential from a 2022 pilot project to infiltrate Klue’s backend. This access allowed the attackers to harvest OAuth tokens used to connect Klue with third-party platforms like Salesforce, Gong, and LastPass, facilitating large-scale data exfiltration from nearly 200 organizations, including major cybersecurity firms such as Huntress, Recorded Future, Tanium, and HackerOne. The attackers employed automated Python scripts leveraging the Salesforce REST API to execute thousands of queries within short bursts, demonstrating how non-human OAuth tokens with persistent business context can be weaponized to bypass direct platform vulnerabilities and evade traditional detection mechanisms.

The breach underscored the cascading risks inherent in third-party SaaS integrations and supply chain attacks, where trust relationships between cloud services and vendors create expansive attack surfaces across multiple enterprises. Despite Salesforce’s platform remaining uncompromised—prompting it to disable the Klue Battlecards app integration and confirm containment—the incident highlighted how attackers can impersonate trusted integrations to access sensitive CRM data without deploying ransomware or malware. This evolving tactic, exemplified by the Klue/Icarus incident and earlier breaches involving Salesloft and Gainsight, emphasizes the urgent need for organizations to rigorously audit OAuth permissions, rotate dormant credentials, and enforce continuous monitoring of third-party integrations to prevent similar large-scale data theft and extortion campaigns.

The Klue breach’s fallout was further complicated when the Icarus extortion group itself was compromised by a secondary threat actor, who launched independent extortion campaigns using the same stolen data, illustrating the multifaceted and escalating nature of supply chain cyberattacks. This multi-stage incident, involving approximately two dozen affected organizations including LastPass, Gong, and Sprout Social, revealed how attackers exploit legacy credentials and OAuth token abuse to maintain persistence and monetize stolen information through ransom threats. As cybersecurity experts caution, the breach serves as a stark reminder that operational security failures—such as abandoned integration accounts and insufficient credential lifecycle management—remain dominant vectors for sophisticated data exfiltration in SaaS environments.

Sources
Bleeping ComputerN2K NetworksBleeping ComputerThe Cybersecurity Pulse (TCP)RECISO Talk by James Azar

SaaS Sprawl Fuels Silent Breaches

Unmanaged guest accounts, stale credentials, and weak governance create massive, invisible attack surfaces that adversaries exploit through forgotten trust relationships.

The Klue supply-chain breach in mid-2026 exemplifies how poor credential lifecycle management, particularly the failure to revoke legacy integration service account credentials, enabled attackers to gain persistent access across nearly 200 customer Salesforce environments. Attackers exploited a compromised credential issued in 2022, leveraging it to harvest OAuth tokens that bypassed traditional defenses, underscoring that stale credentials remain a dominant breach vector despite advances in security technology.

Unmanaged guest accounts and implicit trust in third-party integrations have dramatically expanded the SaaS attack surface, with guest accounts constituting 69% of SaaS accounts in 2025 and often lacking multi-factor authentication. This unchecked access, combined with stale OAuth tokens and orphaned sharing links, allows attackers to maintain long-term, stealthy access and exfiltrate data silently, challenging traditional perimeter defenses and demanding a shift toward continuous identity governance.

Governance failures extend beyond credential management to include mismatched patch cadences, incomplete Conditional Access policies, and weak helpdesk identity verification, such as vishing attacks that enable persistent unauthorized access. These lapses allow attackers to exploit legacy authentication flows and stale trust relationships, as seen in breaches of Oracle E-Business Suite and Microsoft 365, highlighting that attackers succeed by exploiting forgotten paths rather than sophisticated techniques.

Addressing these persistent security gaps requires a governance-first approach that enforces credential expiration policies, mandates regular access reviews, and incorporates out-of-band verification for helpdesk identity challenges. As cybersecurity enters an era where continuous validation of trust relationships is paramount, organizations must extend rigorous governance to all integration service accounts, AI development environments, and third-party dependencies to prevent attackers from exploiting stale credentials and implicit trust.

Sources

Zero Trust Becomes Table Stakes

Continuous identity verification, aggressive credential rotation, and phishing-resistant MFA are now baseline requirements as organizations abandon static perimeter security.

By mid-2026, organizations increasingly recognized that continuous identity verification and stringent OAuth lifecycle management were foundational to robust security postures. For instance, comprehensive audits of Salesforce connected applications and OAuth permissions became standard practice, with a focus on eliminating unused or undocumented third-party integrations to reduce attack surfaces. This proactive approach underscored the necessity of maintaining tight control over identity-linked access points to prevent unauthorized intrusions.

Complementing continuous identity checks, zero-trust governance matured through the enforcement of phishing-resistant multi-factor authentication (MFA) on administrative accounts, a critical defense layer against credential compromise. Simultaneously, organizations prioritized regular credential rotation and meticulous account reviews—such as immediate updates to Fortinet administrative and SSL VPN credentials and audits of Active Directory accounts tied to perimeter devices—to sustain continuous trust validation. These combined strategies reflect a paradigm shift toward dynamic, identity-first security frameworks that adapt in real time to evolving threats.

Sources
CISO Talk by James Azar

AI Agents: The Next Insider Threat

AI development tools and agents now require zero-trust controls, as attackers exploit privileged automation and complex supply chains to bypass legacy defenses and exfiltrate data.

By mid-2026, securing AI development environments has emerged as a paramount challenge, as attackers exploit trusted AI tools and agents to bypass traditional defenses and exfiltrate sensitive data. Microsoft researchers highlighted the risks posed by Agentic AI, where even innocuous tool descriptions can serve as covert exfiltration channels, while zero-click vulnerabilities in AI-powered coding environments like Cursor IDE demonstrate how these privileged identities require threat modeling akin to domain administrators. This evolution underscores the urgent need to apply zero-trust architectures and least privilege frameworks to AI agents, treating them as critical infrastructure with access to repositories, cloud credentials, and enterprise environments simultaneously.

The growing complexity of SaaS and enterprise software supply chains has amplified risk exposure, as exemplified by the Oracle PeopleSoft zero-day attacks that expanded from education into insurance, government, and higher education sectors, impacting over 100 organizations. These incidents reveal how mismatched patch cadences and unprotected legacy authentication flows create exploitable gaps, allowing attackers to leverage trusted platforms as springboards into broader enterprise environments. This supply chain intricacy demands continuous trust validation across every authentication flow, AI agent, and remote access platform, reflecting a fundamental shift from perimeter-based security to a model where 'trust is no longer a security control; verification is.'

Zero-trust principles and continuous validation of trust relationships have become indispensable strategies to counter the rapid evolution of cyber threats and sophisticated attack techniques that exploit assumptions rather than technical vulnerabilities. As attackers rapidly exploit Oracle environments within weeks of patch releases and target configuration files containing cloud infrastructure keys, organizations that rely on yesterday’s approvals find themselves reacting instead of preventing breaches. The traditional security perimeter has dissolved, replaced by a dynamic landscape where every authentication flow and trusted dependency must be scrutinized continuously to maintain resilience, making zero-trust not just a framework but an operational imperative.

Sources
CISO Talk by James AzarCISO Talk by James AzarCISO Talk by James AzarCISO Talk by James Azar

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.