CYFIRMA’s report shows how identity compromise, delegated SaaS access, agentic infrastructure, and data-theft objectives can combine into composable attack surfaces across cases like Vercel/Context.ai, Salesloft/Drift, Taiwan, and EchoLeak. It emphasizes that the Policy/Authorization Control Plane and non-human identity governance are high-leverage defenses, while standards such as AIMS and Cross App Access are emerging to close the gap. #Vercel #Contextai #Salesloft #Drift #EchoLeak #AIMS #CrossAppAccess
Keypoints
- CYFIRMA frames identity, SaaS delegation, agentic systems, and data-access goals as one composable trust graph rather than separate threat classes.
- The report analyzes four cases: Vercel/Context.ai, Salesloft/Drift, the Taiwan government intrusion, and EchoLeak.
- Vercel/Context.ai is a confirmed trust cascade intrusion where an infostealer-led endpoint compromise and broad OAuth grant enabled lateral access.
- Salesloft/Drift is a large-scale confirmed trust cascade intrusion in which stolen vendor-side tokens enabled authenticated access to more than 700 organizations.
- The Taiwan case is treated as TCI-relevant, showing AI-assisted reconnaissance and exploitation of government systems, but not a confirmed identity-first cascade.
- EchoLeak is a boundary case showing prompt injection against Microsoft 365 Copilot without any identity-layer compromise.
- The report argues that task-scoped authorization, SaaS-to-SaaS trust graph visibility, and stronger non-human identity governance are among the highest-leverage controls.
MITRE Techniques
- [T1199 ] Trusted Relationship – Used when compromised trusted SaaS/vendor relationships enabled lateral access and downstream abuse (‘trusted third-party infrastructure’ and ‘a third-party AI tool’s OAuth grant functioned as a lateral-movement path’).
- [T1555.003 ] Credentials from Password Stores: Credentials from Web Browsers – The Vercel/Context.ai case involved an endpoint infostealer harvesting browser-stored corporate credentials (‘Lumma Stealer… yielding Google Workspace credentials’).
- [T1539 ] Steal Web Session Cookie – The stolen material in the Vercel case included session tokens/cookies enabling reuse of authenticated sessions (‘session tokens’).
- [T1528 ] Steal Application Access Token – The report describes theft of OAuth and refresh tokens in both Vercel/Context.ai and Salesloft/Drift (‘OAuth tokens’, ‘OAuth and refresh tokens’).
- [T1550.001 ] Use Alternate Authentication Material: Application Access Token – Stolen OAuth/refresh tokens were used to authenticate directly and bypass MFA (‘the tokens themselves carried trusted access’).
- [T1078.004 ] Valid Accounts: Cloud Accounts – In the Taiwan case, the operation compromised cloud-linked accounts and used valid access to navigate systems (‘compromised at least 85 accounts’).
- [T1213 ] Data from Information Repositories – Attackers queried repositories and records for secrets and sensitive data (‘extracted embedded URLs, API endpoints, OAuth client IDs’).
- [T1560 ] Archive Collected Data – The Salesloft/Drift campaign involved collecting and staging data for follow-on operations (‘bulk theft plus credential harvesting for follow-on ops’).
- [T1567 ] Exfiltration Over Web Service – Data was exfiltrated through web-based services and APIs (‘Bulk API 2.0 job… exfiltrated a database’).
- [T1070 ] Indicator Removal – The Salesloft/Drift actor attempted to delete the Bulk API job to hide traces (‘attempted to delete the job to cover its tracks’).
- [AML.T0051 ] LLM Prompt Injection – EchoLeak used a crafted email with hidden instructions to manipulate Copilot (‘zero-click prompt-injection vulnerability’).
- [AML.T0053 ] LLM Plugin Compromise (AI Agent Tool Invocation) – EchoLeak coerced Copilot into retrieving and acting on data through a trusted action path (‘exfiltrate it via an auto-fetched image request proxied through a trusted Microsoft Teams endpoint’).
- [AML.T0054 ] LLM Jailbreak – The EchoLeak payload bypassed normal safety and redirection controls by altering the model’s behavior through injected instructions (‘hidden instructions’).
Indicators of Compromise
- [Malware / Tool] Endpoint infostealer used in Vercel/Context.ai – Lumma Stealer, commodity infostealer-as-a-service.
- [Platforms / Services] Compromised or affected services in Vercel/Context.ai – Google Workspace, Supabase, Datadog, AuthKit.
- [Threat Actor / Group] Actor tracked in Salesloft/Drift – UNC6395.
- [Platforms / Services] Downstream services abused in Salesloft/Drift – Drift, Salesforce, GitHub, AWS, Bulk API 2.0.
- [Frameworks / Tools] AI-agent frameworks cited in the Taiwan case – Hermes, OpenClaw.
- [Organizations / Systems] Affected systems in the Taiwan case – Taiwanese government systems, Keycloak, nuclear safety agency, energy-sector suppliers.
- [Vulnerability / Product] EchoLeak target – CVE-2025-32711, Microsoft 365 Copilot.
- [Platforms / Services] Trusted delivery path abused in EchoLeak – Microsoft Teams endpoint, auto-fetched image request.
- [File / Content Types] Sensitive data targeted across the cases – environment variables, session tokens, OAuth tokens, URLs, API endpoints, OAuth client IDs, personnel records.
Read more: https://www.cyfirma.com/research/the-trust-cascade/