In 2022 someone created a credential for a prototype at Klue, a competitive intelligence vendor. The prototype was abandoned; the credential was not. Four years later, that forgotten credential was used to steal the OAuth tokens Klue used to access its customers' Salesforce, and with them, data from some 200 companies. Among those affected are cybersecurity firms such as Huntress, Tanium and Jamf.
The uncomfortable detail is that last part: if it can happen to companies whose business is security, the question is not whether your vendors are infallible, but what they can touch of yours when they fail. Every tool connected to your systems is a key that lives outside your house, and the keys nobody remembers are the ones that last longest.
Two questions worth asking at any company this week: which vendors have direct access to your systems or data, and who checks that access that is no longer used gets revoked. If nobody has the second answer, the first list is incomplete.
The teams that should be watching this are stretched thin, and there is data on it: The capability gap in technology audit.