On 14 September 2026, an attacker used a compromised Brevo Cloudflare API key to deploy a Cloudflare Worker that, for about five and a half hours, injected a malicious script into Brevo’s pages and into three JavaScript files customers embed on their own websites. As the key carried full account permissions, and was hard coded into application source code, this allowed the attackers to create DNS records, workers and routes, all without triggering a single alert.
Some estimates say that more than 100,000 websites loaded the altered scripts. With responses rewritten at the edge, and security headers stripped, there was no impact on the origin files, which meant it bypassed standard integrity checks.
From identity providers and SaaS integrations to AI tools and DevOps pipelines, trusted platforms are such a valuable target to attackers precisely because they are trusted. A single compromise can cause a ripple impact across thousands of victims, without raising so much as an eyebrow, let alone an alert.
What’s behind the shift?
When attackers target trusted platforms, a single compromise provides inherited access to every connected customer, environment and partner. Integrations may hold standing OAuth tokens, embedded scripts and API keys, which means an attacker gets an open door instead of having to earn their way in. Another recent example is Klue, where OAuth tokens were held for hundreds of customer integrations, allowing the attacker into every connected Salesforce environment, without separate exploitation of each downstream organization.
As platforms often by nature need a lot of access, bad actors can also gain broad permissions from a single intrusion. And of course, traffic from a trusted vendor, or activity from a valid token looks like normal activity, which gives the attacker a place to hide. There’s no patch available for a valid login, which makes valid credentials true crown jewels. Take the Fortibleed campaign as a harrowing example of how effective this is — where 86,000 Fortinet admin and VPN credentials were exposed through password theft and reuse.
As platforms often by nature need a lot of access, bad actors can also gain broad permissions from a single intrusion. And of course, traffic from a trusted vendor, or activity from a valid token looks like normal activity, which gives the attacker a place to hide. There’s no patch available for a valid login, which makes valid credentials true crown jewels. Take the Fortibleed campaign as a harrowing example of how effective this is — where 86,000 Fortinet admin and VPN credentials were exposed through password theft and reuse.
This is an important distinction for defenders. Malicious activity conducted through legitimate credentials, authorized OAuth tokens or trusted infrastructure may not resemble traditional intrusion activity. Authentication can succeed normally, API calls may originate from expected services and activity may take place entirely within cloud environments without malware ever reaching an endpoint.
AI is adding further pressure by accelerating vulnerability research and exploit development, reducing the time defenders have to respond. Consider Copy Fail, a Linux kernel flaw that generated more than 140 public exploit variants, including AI-assisted modifications, with initial proofs of concept appearing within hours of the upstream code changes. At the same time, as AI systems gain greater permissions and autonomy, the identities, credentials, configurations and integrations supporting them are becoming part of the enterprise attack surface.
The common attack paths
Let’s understand three of the most common trusted platforms, and how they are exploited.
Software supply chains
Software supply-chain attacks exploit trust between developers, packages, build systems and distribution platforms, allowing attackers to reach multiple downstream environments through a single upstream compromise. Recent TeamPCP activity demonstrated this model, with compromised developer accounts and trusted software packages used to expand access across the software ecosystem and distribute malicious versions through widely used repositories. Developer credentials can also provide access to additional repositories, publishing accounts and CI/CD infrastructure, where stored secrets and privileged permissions create further opportunities for compromise.
Cloud identity and SaaS
With so many critical services now in the cloud, a single valid identity or token can provide attackers with access across multiple connected services. As the Klue incident demonstrated, OAuth tokens and API keys can be particularly valuable because they may remain valid for extended periods, bypass repeated MFA challenges and receive less scrutiny than interactive user logins. Attackers also continue to target the human layer through phishing, vishing and helpdesk impersonation to obtain credentials, reset MFA or enroll new authentication methods before taking over Single Sign-On accounts and pivoting into connected SaaS applications. This activity is becoming increasingly relevant: CrowdStrike reported twice as many vishing-related intrusions in H1 2026 compared to H2 2025.
AI platforms
There’s no doubt that AI adoption is happening faster than organizations can secure or even visualize what’s being introduced. By design, AI assistants and agents need to be able to access code, credentials, connected systems and sensitive data, and act without questioning on local configuration files, workspace settings and more. Every AI agent under your roof is therefore a high-value identity, and if you change what they trust, you control them. And as AI tools aren’t traditional endpoints or business apps, they often fall through the cracks in terms of detection coverage.
Each of these three platforms is deeply integrated, broadly permissioned and trusted by default. Credentials in one environment can open doors in the next.
Making trusted infrastructure trustworthy again
Defending these environments requires extending existing security practices beyond traditional endpoints and network infrastructure:
- Monitor identity and SaaS activity for unusual OAuth grants, unexpected token use, new privileged accounts and abnormal administrative actions. Long-lived credentials should be reduced where possible, secrets should not be embedded in source code and API permissions should follow least-privilege principles.
- CI/CD environments should receive the same security attention as production. Dependencies controlled, pipeline permissions minimized, secrets monitored and rotated and changes to packages, extensions and build processes reviewed for unexpected behavior.
- Organizations need visibility into which AI tools and agents are operating in their environments, what systems they can access, which credentials or integrations they rely on and what actions they are permitted to perform.
- Incident response plans should account for compromise of trusted identities and platforms. Revoking a user password may not be sufficient if OAuth tokens, API keys, application secrets or connected integrations remain active.
Attackers are increasingly scaling through trust. The challenge is not simply identifying another vulnerability to patch, but understanding how access granted to one identity, integration or platform can extend into the rest of the environment.
Cloud identities, SaaS integrations, development pipelines and AI infrastructure should therefore be part of day-to-day security monitoring and incident response. The question for security teams is no longer only whether a trusted platform is secure, but what that platform allows an attacker to access, execute or distribute if that trust were compromised.
_____
About Liora Ziv
Liora Ziv is a cyber threat intelligence analyst who combines a strategic view of global cyber trends with the analysis of modern threat-actor behavior. With a background in international relations and fluency in multiple languages, she brings a global, contextual lens to her work, helping organizations better understand the forces shaping today’s cyber landscape.
Join our LinkedIn group Information Security Community!
