Organizations are facing increasing risks from the proliferation of hardcoded credentials, access tokens, and API keys, which are often exposed in code repositories and other unexpected locations. Recent high-profile attacks, such as those targeting Salesforce customers through stolen OAuth tokens, have demonstrated how attackers exploit poor secret management practices to gain unauthorized access to sensitive systems. Security experts warn that both cybercriminals and nation-state actors are capitalizing on this widespread issue, urging organizations to improve their secret hygiene and reduce over-privileging of credentials.
In response to these threats, enterprises are moving away from static secrets and adopting managed identities and platform-native identity services. This transition is driven by the need to eliminate manual credential management, reduce the risk of credential leakage, and streamline authentication across complex, multicloud environments. Case studies show that organizations implementing managed identities experience significant reductions in time spent managing credentials and improved security posture, highlighting the importance of modernizing identity and access management strategies to counter evolving attacker tactics.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
Attackers breached Red Hat Consulting and gained access to thousands of private repositories along with client secrets. The incident highlighted the broader risk of sensitive data sprawl and poor secret management practices.
A campaign targeted Salesforce environments by abusing OAuth tokens stolen from a third-party application, demonstrating how exposed secrets outside traditional code repositories can enable downstream compromise. Cloudflare was identified among the affected companies.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
github.blog
Open sourcethehackernews.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.