Microsoft maps year-long OAuth access campaigns
🔎 Microsoft mapped a year-long series of campaigns, running mid-2025 to mid-2026, that gave attackers access to corporate Salesforce environments without exploiting platform bugs. The intrusions relied on OAuth trust: vishing to approve malicious connected apps, theft of vendor OAuth tokens, and misconfigured guest access to Experience Cloud. Microsoft and Salesforce added detection and governance features in Defender for Cloud Apps and improved real-time event visibility to expose connected-app activity and reduce over-permissioned integrations.
