Severity: HighIncidentNHI/credential
Stolen OAuth refresh tokens give attackers standing agent access
North America
Sample data. Showing illustrative sample items as a fallback — the live feed is not available right now.
Attackers who phished a single developer harvested OAuth refresh tokens cached by an agent connector and used them to maintain access for weeks. The long-lived tokens carried broad scopes and were not bound to the originating device.
What to do
Issue short-lived, narrowly-scoped tokens with just-in-time elevation, bind tokens to device or workload identity, and monitor for refresh-token reuse from new locations.
Mapped framework pillars
Sources
#OAuth#token theft#persistence
