Left Unsupervised: 10 Times Access Outlived Its Authorization | UpGuard
ID: 16fa7449-403c-5ad9-b855-f72d5c66bea9
STIX ID: report--16fa7449-403c-5ad9-b855-f72d5c66bea9
Feed Name: UpGuard Blog
This article summarizes ten high-impact incidents where unmonitored, long-lived credentials and insufficient vendor/integration controls enabled large-scale data exposures and active attacks—from OAuth token theft and infostealer-driven breaches (Ticketmaster, various corporate victims) and a nation-state token forgery campaign (Storm-0558) to a self-propagating npm worm (Shai-Hulud). It highlights recurring root causes (stale tokens, lack of secret scanning, overscoped roles, missing MFA, poor offboarding) and prescribes mitigations: enforce short-lived/provenance-backed credentials, mandatory secret scanning and logging, robust vendor offboarding and evidence of data destruction, MFA everywhere, least privilege and periodic access reviews, and independent logging of automated agents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
