
Enterprise OAuth Sprawl: Hundreds of SaaS Integrations Outpace Security Controls
LastPass's breach via stolen OAuth tokens from Klue exposed a structural vulnerability across enterprise security: most organizations operate hundreds of SaaS applications with Salesforce and other critical systems, yet lack centralized visibility into which third-party apps hold active tokens or revocation mechanisms. Teams typically provision these integrations independently, leaving security teams unable to audit scope, rotation policies, or anomalous token use at scale.
Published