Join our Newsletter — 33% off our NHI Course

SaaS integrations and standing privilege: what IAM teams missed

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Akeyless says attackers used an abandoned Klue test credential to harvest OAuth tokens and reach dozens of customer Salesforce environments, showing that SaaS integrations can become standing non-human identities when their delegated access outlives the purpose it was created for. Lifecycle control, not perimeter trust, is the governance failure that matters here.

Editorial analysis by NHI Mgmt Group, based on content published by Akeyless: “What the Klue Breach Reveals About SaaS Supply Chain Risk and Standing Secrets”.

Key questions

Q: What breaks when a SaaS integration credential is left active after a project ends?

A: The credential becomes standing privileged access that no longer has a legitimate business owner.

Q: Why do stolen OAuth tokens create disproportionate risk in cloud-connected business systems?

A: Stolen OAuth tokens are dangerous because they inherit the permissions already granted to the connected app, so the attacker often does not need to authenticate again.

Q: How do security teams know if integration credentials are operating outside their intended scope?

A: Look for access to systems the credential has never touched before, unusual authentication times, protocol mismatches, and data requests that do not match the integration's normal business function.

Practitioner guidance

  • Inventory every third-party SaaS integration Map OAuth grants, API keys, service accounts, certificates, and other delegated credentials tied to Salesforce, CRM, and adjacent business platforms.
  • Revoke dormant and ownerless credentials Remove test credentials, deprecated integrations, and abandoned pilot secrets before they become replayable access paths.
  • Constrain token scope and lifetime Reduce OAuth scopes to the smallest workable set and enforce short-lived tokens where the platform allows it.

Bottom line: The breach demonstrates that SaaS integrations become security liabilities when their credentials outlive the project or vendor relationship that created them.

What's in the full article

Akeyless's full article covers the operational detail this post intentionally leaves for the source:

  • The step-by-step Klue attack chain from abandoned credential to OAuth token theft and downstream Salesforce access
  • The full list of named affected companies and the reported scope of the compromise
  • The vendor-side control model proposed for dynamic secrets, zero standing privilege, and secretless authentication
  • The specific checklist items for auditing SaaS integrations, token scope, and decommissioning workflows

👉 Read Akeyless's analysis of the Klue breach and SaaS integration NHI risk →

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Abandoned integration credentials are lifecycle failures, not configuration oversights. This breach worked because a credential created for a prototype outlived the project that justified it. That means the governance gap is offboarding, not merely secret storage. When integration credentials are not tied to a decommissioning process, they become latent standing privilege that attackers can discover later. Practitioners should treat every dormant integration secret as evidence of unresolved ownership.

A few things that frame the scale:

  • 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: What should organisations do when a SaaS vendor is part of their CRM access chain?

A: Assign the integration an owner, an expiry, and a documented offboarding path, then review its scopes and revoke anything that no longer matches the use case. Treat the vendor connection as a governed identity, not as a one-time technical setup.

👉 Read our full editorial: Klue breach shows why SaaS integrations need NHI governance


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.