Index live· 1,284 files · 148 editions
ForensicPost

Search the index

9 results
Try
Results for “Tokens”Newest first
26-0611
File

Klue Compromise Reached Salesforce Environments at Two Dozen Customers

A legacy credential and stolen OAuth tokens reached Salesforce environments at ~24 customers. The tokens were used exactly as designed.

UnattributedOAuth token theftCloudTokens
Sev 4TargetKlueActorUnattributed
26-0429
File

ShinyHunters Campaign Compromised More Than a Thousand Organisations via Device Code Phishing

More than a thousand organisations through device code phishing. There is nothing to patch, which is why the campaign has no natural ceiling.

ShinyHuntersDevice code phishingCloudTokens
Sev 4TargetSaaS tenants, multipleActorShinyHunters
25-0826
File

Cloudflare Says 104 API Tokens Were Exposed via Pasted Support Cases

Everyone scans repositories for committed secrets. Almost nobody scans the ticket system, which accumulates the same material indefinitely.

UNC6395OAuth token theftCloudSupply chain
Sev 4TargetCloudflare case recordsActorUNC6395USA
25-0818
File

One Integration, Seven Hundred Customer Environments

700+ organisations queried through one integration’s stolen tokens. Nothing was exploited; the tokens worked exactly as designed.

UNC6395OAuth token theftCloudTokens
Sev 5TargetSalesloft Drift integrationActorUNC6395
25-0624
File

CitrixBleed 2 NetScaler Flaw CVE-2025-5777 Widely Exploited From June

A sequel name is a judgement that this is the same mistake in the same place. Session tokens leak past authentication entirely.

MultipleMemory disclosureCloudExploitation
Sev 4TargetNetScaler appliancesActorMultiple
25-0523
File

Attackers Drained Cetus Protocol Liquidity Using Spoof Tokens

No credential stolen, no server compromised, no employee deceived. The contract executed exactly as published — the specification and the intent diverged.

UnattributedContract logic manipulationFinanceProtocol
Sev 3TargetCetus ProtocolActorUnattributed
23-0711
File

Storm-0558 Forged Tokens With a Stolen Microsoft Key to Read Government Email

A token signed with a trusted key is not a forgery the platform can detect. It is a valid token.

Storm-0558Forged authentication tokensPublic sectorEspionage
Sev 5TargetExchange Online tenantsActorStorm-0558
23-0104
File

CircleCI Rotated Every Customer Secret After Malware Stole an Engineer’s Session

The credential that mattered was not the password. It was the thing issued after the password.

UnattributedSession token theftTechnologyTokens
Sev 4TargetCircleCIActorUnattributed
22-0412
File

GitHub Says Stolen Heroku and Travis-CI Tokens Exposed Private Repositories at Dozens of Organisations

The security of a system is the security of everyone it has delegated to — a set nobody enumerates.

UnattributedStolen OAuth tokensTechnologySupply chain
Sev 4TargetGitHub customers, incl. npmActorUnattributedUSA
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging