Heroes. Here we are, smack in the middle of an NFL season, but the bad guys won't take any time off. So neither will we. Here's a detailed look at the current cybersecurity landscape for September 5, 2025.
Critical Threats
Today's commentary: One of the articles below suggests a Hippocratic Oath for developers.
It's ridiculous on its face as there are no bug-free products, and the fact is risk appetite varies from all parties. In addition, there is too much incentive to put dev cycles into a hyperspeed cadence with modern tool sets.
The smart approach is to keep your side of the street clean. Assume the code is flawed and build in your security layers as such. If it helps you sleep better, the code has always been flawed, so nothing there has changed. But your options have.
High Severity
Executive Briefing
Today's intelligence reveals two converging strategic threats: the weaponization of AI and the exploitation of non-human identities (NHIs). The emergence of tools like 'DarkBard' democratizes advanced cybercrime, while incidents like the Salesforce OAuth breach show how compromised NHIs (API keys, tokens) can lead to widespread supply-chain attacks. Leaders must prioritize investments in both AI-threat detection and robust NHI security platforms to manage this evolving risk landscape, as unmanaged machine identities represent a significant and often invisible vector for enterprise breaches.
Vendor Spotlight
Spotlight Rationale: The current threat landscape is dominated by identity-related breaches, particularly those involving machine or non-human identities. The Salesforce OAuth breach and the analysis on managing NHIs highlight a critical, often overlooked, attack surface. Entro Security is selected for its direct focus on securing these non-human identities, which are at the core of modern application and cloud infrastructure.
Threat Context: Behind the Salesforce OAuth Drift Breach, Innovations in Managing Non-Human Identities
Platform Focus: Entro Security - Non-Human Identity (NHI) Security Platform
Entro provides a specialized platform to discover, manage, and secure the entire lifecycle of non-human identities like API keys, service accounts, tokens, and certificates. In the context of the Salesforce breach, such a platform could have identified the misconfigured or overly permissive OAuth tokens that enabled the attacks. By providing a centralized inventory and enforcing security policies (e.g., rotation, least-privilege), Entro helps organizations close the security gaps created by sprawling, interconnected cloud services and prevent similar supply-chain attacks.
Actionable Platform Guidance: Implement the Entro platform to continuously scan code repositories, cloud configurations, and secret managers to build a comprehensive inventory of all NHIs. Prioritize remediation for identities with excessive permissions, those that are inactive, or those stored insecurely. Establish automated workflows for secret rotation and lifecycle management to minimize the window of opportunity for attackers.
Source: entro.security
Now, during an NFL game, the lead referee wears a white hat, but the rest of the crew wears black hats. The Editorial Staff of this publication isn't keen on conspiracies, but what if this one is operating in plain sight? How do we know the white-hatted referee hasn't been compromised and isn't acting on the influence of the black hats? We know the refs communicate with NFL C2 during the game...so where in the supply chain are the refs compromised?