Skip to content
Agentic AI Security Hub
Back to feed
Severity: HighIncidentNHI/credential

Stolen OAuth refresh tokens give attackers standing agent access

North America

Sample data. Showing illustrative sample items as a fallback — the live feed is not available right now.

Attackers who phished a single developer harvested OAuth refresh tokens cached by an agent connector and used them to maintain access for weeks. The long-lived tokens carried broad scopes and were not bound to the originating device.

What to do

Issue short-lived, narrowly-scoped tokens with just-in-time elevation, bind tokens to device or workload identity, and monitor for refresh-token reuse from new locations.

#OAuth#token theft#persistence