A legacy credential and stolen OAuth tokens reached Salesforce environments at ~24 customers. The tokens were used exactly as designed.
Scanner credentials reached 300+ repositories. Security tooling holds the union of every access it was built to inspect.
No credential stolen, no server compromised, no employee deceived. The contract executed exactly as published — the specification and the intent diverged.
The corpus has been over-weighting the minority route, because a named CVE generates documentation and a stolen password does not.
165 separate failures with one shape, and a platform that was never itself breached.
A HAR file does its job by capturing exactly the material an attacker needs.
A reader comparing incidents by their first published figure is comparing almost nothing.
Not a dump. A selection — sorted by which procedure would hurt the patient most.
No credential stolen, no flaw exploited. Somebody wanted to understand how patients used the portal.