Overprivileged OAuth Grants Pose Security Risk to Enterprises
A recent enterprise security review finds that employees at large companies create an average of 88 OAuth grants each, with about 31 giving access to sensitive data. These authorizations frequently remain active even after employees leave or change roles, and often escape security team oversight. Attackers are increasingly targeting overprivileged OAuth tokens, as demonstrated in the Vercel breach traced to a third-party AI tool, raising concerns about the effectiveness of current review processes.
- Average employee creates 88 OAuth grants
- 31 grants per person have sensitive data access
- Disabling user accounts won't revoke most grants
- Vercel breach linked to compromised OAuth token
- Gartner: Half of SaaS breaches may involve OAuth by 2027
Sources covering this
More in Cybersecurity
US and allies disrupt Chinese hacking tools targeting infrastructure
US authorities and international partners have seized domains and tools used by China's Integrity Technology Group to support…
AI-powered attacks target South Korean banks
A cyberattack campaign targeting South Korean financial institutions used AI-based tools to steal personal data, CrowdStrike reported.
Google promotes passkeys as a password alternative
Google is highlighting passkeys as a faster and safer alternative to traditional passwords for its accounts.
Malware found pre-installed on low-cost Android phones
Researchers have discovered malware embedded in the firmware of inexpensive Android smartphones, allowing attackers to remotely install…