TL;DR: Compromised SSO credentials, stolen SaaS tokens, and exploitable enterprise platforms enabled breaches across higher education, media, automotive, DeFi, and endpoint management in early November 2025, according to FireCompass. The pattern is clear: once identity and trust boundaries fail, data exfiltration, privileged misuse, and rapid blast-radius expansion follow.
NHIMG editorial — based on content published by FireCompass: Weekly Cybersecurity Intelligence Report, Cyber Threats & Breaches, 3 Nov to 10 Nov 2025
By the numbers:
- Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, ahead of inadequate monitoring and over-privileged accounts at 37% each.
Questions worth separating out
Q: What breaks when an SSO account is compromised in a SaaS-heavy environment?
A: When SSO is compromised, the attacker inherits the organisation's existing trust relationships.
Q: Why do stolen tokens create more risk than a one-time login compromise?
A: Stolen tokens often bypass the normal interactive login flow, so they can be reused silently until expiration or revocation.
Q: What are the signs that a user is misusing SaaS access for reconnaissance or data theft?
A: Common signs include a sudden increase in searches for a competitor, repeated viewing of channels outside the role, access to applications not used for weeks or months, and exporting or downloading content that does not match job duties.
Practitioner guidance
- Harden SSO and federation paths Review SSO-linked applications, enforce MFA for privileged and high-risk workflows, and monitor for unusual cross-application access patterns such as CRM to storage or ERP to marketing exports.
- Constrain token lifetime and reuse Shorten the usable life of browser tokens, API keys, and delegated sessions, and revoke them immediately when endpoint compromise or suspicious sign-in activity is detected.
- Monitor SaaS for bulk and weaponised actions Alert on mass email sends, large downloads, abnormal file sharing, and out-of-hours exports from business platforms that are normally considered trusted.
What's in the full article
FireCompass's full report covers the operational detail this post intentionally leaves for the source:
- Named incident summaries with the attack sequence, impact, and remediation notes for each breach
- MITRE ATT&CK mappings and incident-specific tactics that support deeper triage and hunting
- The original analyst commentary tying the week's events to broader threat activity
- The source's own prioritisation of which incidents matter most for CISOs and security teams
👉 Read FireCompass's weekly cybersecurity intelligence report on recent breaches and attack chains →
SSO and SaaS trust boundaries: what practitioners need to act on?
Explore further
SSO trust is now a blast-radius problem, not just an authentication problem. When a valid account can unlock marketing, collaboration, storage, and ERP systems, the identity layer becomes a lateral movement accelerator. That changes the governance question from "was MFA enabled" to "how far can one trusted session travel before it is challenged." Teams should map trust boundaries around SaaS federation and shared access paths.
A question worth separating out:
Q: How should teams account for delegated access and OAuth apps in identity governance?
A: Teams should inventory every third-party connection that can act on behalf of a user or service account, then assign ownership, review intervals, and revocation criteria. OAuth and service integrations should be treated as governed identities, because their permissions can outlive the user relationship that created them.
👉 Read our full editorial: Weekly breach intelligence shows SSO and SaaS trust failures