The Expiry
Credentials remain active an average of forty-seven days after they are no longer needed. Fifty-one percent of organizations lack formal processes for revoking them. Authorization has always had a ...

Source: DEV Community
Credentials remain active an average of forty-seven days after they are no longer needed. Fifty-one percent of organizations lack formal processes for revoking them. Authorization has always had a time dimension — the industry just never had to care until agents started acting faster than permissions could decay. Between March and June of 2025, attackers accessed Salesloft's GitHub account. They planted malicious workflows and moved laterally into Drift's AWS environment. What they stole was not data directly — it was OAuth tokens. Tokens that had been issued to customer technology integrations months earlier and were still active. In August, two months after the initial compromise was contained, the stolen tokens worked. The attackers used them to access environments at Salesforce, Cloudflare, Palo Alto Networks, and Zscaler. Over seven hundred organizations were exposed. Not because of a zero-day exploit, not because of a sophisticated attack chain, but because tokens granted in one