Attackers used a compromised BigCommerce application key held by Ribon to access customer data, according to SecurityWeek. The incident highlights the access risk created when third-party applications hold broad or long-lived platform credentials.

Organizations should review third-party application permissions, rotate credentials suspected of exposure, limit scopes to the minimum needed, and ensure revocation and incident-response processes include SaaS integrations and vendor-held keys.

Source: SecurityWeek.

By Allan