Delinea Labs July 2026 Threat Outlook
In this monthly series, Delinea Labs breaks down the identity-related incidents that had the greatest operational impact over the previous month: how attacks unfolded, what failed in real environments and what those failures signal for the month ahead.
June's defining incident didn't involve a stolen password or a bypassed multi-factor authentication (MFA) prompt. Attackers compromised Klue, a competitive intelligence platform, and stole the OAuth tokens its customers used to connect to Salesforce. That delegated access was enough on its own. Huntress and LastPass later confirmed impact, and neither had a credential compromised in the traditional sense.
The token wasn't a way around the security control. It was the security control
Here's Delinea Labs' outlook for July
A Salesforce integration, a CyberArk deployment, and a security assertion markup language (SAML) federation link. Each one exists because an enterprise decided to trust it. June showed what happens when that trust is the only thing standing between an attacker and the environment. The Klue incident didn't require Salesforce credentials or an MFA bypass.
The OAuth grant already carried the access an attacker needed. Alongside it, vulnerabilities disclosed across CyberArk, Cloud Foundry UAA and authentik hit the infrastructure that issues and validates that same trust. Different entry points, same underlying gap: Once a connection is trusted, almost nothing downstream rechecks it.
The Klue breach is the clearest evidence yet that a delegated integration is a privileged identity, whether or not anyone has classified it that way. One compromised token granted attackers simultaneous access across multiple customer environments, with no password prompt and no MFA challenge anywhere in the chain.
Meta's AI-assisted account recovery workflow was abused. It took over more than 20,000 Instagram accounts before the issue was fixed. In this situation, AI isn't the target. AI is already sitting inside the authentication path, deciding who gets back into an account and inheriting the same risks as any other identity-verification system.
A disclosed one-click attack allows GitHub OAuth token theft through VS Code's browser environment. A developer's machine is no longer just a developer's machine. It's a credential store with a path to continuous integration/continuous deployment (CI/CD) pipelines, cloud infrastructure and production secrets.
June brought a wide set of disclosures across CyberArk's product family, including EPM, Secrets Manager, PSM, PSMP, Privilege Cloud Connector, Identity Browser Extension and its self-hosted vault. The disclosures covered authentication weaknesses, privilege escalation, and exposure of secrets. The platforms built to protect the highest-value identities are the platforms worth attacking.
June saw 7,369 common vulnerabilities and exposures (CVEs) disclosed industry-wide. Of those, 727 were identity-related, and 39 directly affected identity products.

Two disclosures are worth specific attention:
CVE-2026-40965 — Cloud Foundry UAA. Exposed elliptic curve (EC) private keys used for OAuth token signing. Once an attacker can forge tokens, every application that trusts them is compromised by extension, whether or not it was directly attacked.
CVE-2026-47201 — authentik. An XML Signature Wrapping flaw in SAML handling that lets an attacker-controlled identity pass as a trusted one. Federation only works if the validation underneath it holds.
TheGentlemen led June's ransomware activity at 13.8%, followed by Qilin (11.8%) and LockBit (7.4%). The initial access methods haven't changed: stolen credentials, VPN access and Active Directory compromise still do more work for these groups than exploiting a vulnerability does.
Encryption is the visible event. Identity compromise is what made it possible
Inventory and scope every active OAuth grant. Klue shows that a delegated integration can carry more access than the account that authorized it. Review third-party OAuth connections the same way you'd review a privileged service account, not as a one-time setup step.
Bring AI-assisted identity workflows under the same governance as human-facing ones. If an AI system can verify identity or recover an account, it needs the same scrutiny as the process it replaced.
Treat developer environments as credential stores. The VS Code GitHub token exposure is a reminder that a compromised integrated development environment (IDE) or browser extension is now a viable route into production, not just into a developer's local files.
Assume session and token theft, not just password theft, in detection coverage. Klue and the broader OAuth pattern this year confirm that stolen sessions bypass the assumptions most MFA-centric detection is still built around.
The Delinea Platform, powered by Iris AI, continuously discovers identities, analyzes privilege risk and enforces access control at the moment of execution across human, machine and AI identities.
Learn how Delinea can help your organization govern trust in real time.