logo

The Back Door Attackers Know About — and Most Security Teams Still Haven’t Closed

ID: 0784aa2e-1b3e-577d-ad83-88e64d6076ed

STIX ID: report--0784aa2e-1b3e-577d-ad83-88e64d6076ed

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

This article warns that persistent OAuth grants (long-lived refresh tokens) are an under-monitored attack vector that bypass perimeter controls and MFA; it cites the Drift incident where UNC6395 used stolen OAuth tokens to access Salesforce environments across 700+ organizations and exfiltrate sensitive data, and recommends continuous behavioral monitoring, blast-radius risk scoring, and automated remediation (Material Security's OAuth Threat Remediation Agent) to detect and revoke high-risk grants.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.