logo

Left Unsupervised: 10 Times Access Outlived Its Authorization | UpGuard

ID: 16fa7449-403c-5ad9-b855-f72d5c66bea9

STIX ID: report--16fa7449-403c-5ad9-b855-f72d5c66bea9

Feed Name: UpGuard Blog

Threat Score
82/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

...
...

This article summarizes ten high-impact incidents where unmonitored, long-lived credentials and insufficient vendor/integration controls enabled large-scale data exposures and active attacks—from OAuth token theft and infostealer-driven breaches (Ticketmaster, various corporate victims) and a nation-state token forgery campaign (Storm-0558) to a self-propagating npm worm (Shai-Hulud). It highlights recurring root causes (stale tokens, lack of secret scanning, overscoped roles, missing MFA, poor offboarding) and prescribes mitigations: enforce short-lived/provenance-backed credentials, mandatory secret scanning and logging, robust vendor offboarding and evidence of data destruction, MFA everywhere, least privilege and periodic access reviews, and independent logging of automated agents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.