Here we are, deep in the glittering technological future, where artificial intelligence can compose symphonies, write legal briefs, and apparently find software vulnerabilities faster than a caffeinated intern. And yet, password stupidity strikes again — not with a bang, not with a sophisticated AI-powered zero-day exploit, but with the digital equivalent of leaving your front door unlocked because you forgot you had a front door.
The story this week involves a company called Klue, a market intelligence platform used by over 250,000 people worldwide. Somebody, at some point, created a set of login credentials linking Klue to Salesforce. Then that somebody left the company, or changed systems, or simply forgot those credentials existed. The credentials were never deleted. They just sat there, quietly, like a forgotten Tupperware container at the back of the office fridge — until, on around the 11th of June, a cybercriminal found them and helped themselves to the entire contents.
The Breach That Launched a Thousand Facepalms
Using those compromised legacy credentials, attackers obtained OAuth tokens and waltzed into the Salesforce environments of hundreds of Klue customers. Security firms. Password managers. Hundreds of organisations who really, genuinely should have known better. Among the affected was Huntress, a cybersecurity company — and to their enormous credit, they were among the first to publicly admit they had been caught with their digital trousers down.
Huntress came forward and said, essentially, yes, we were one of them, here is what happened, we are sorry. Furthermore, as a security company, they arguably had a moral and legal obligation to do so. In the United States, breach disclosure laws mean you do not really have the option of hoping nobody notices. However, plenty of companies still try. Huntress, to their credit, did not.
Meanwhile, AI Is Apparently Too Busy Being Impressive
Now, there has been considerable noise lately about AI models identifying vulnerabilities before the bad guys do. Security professionals have been quoted describing this summer as the summer from hell, with top-tier AI systems spotting troublesome weaknesses at a genuinely alarming rate. Consequently, everyone has been looking nervously at their keyboards, wondering if some omniscient algorithm is about to unravel civilisation.
And yet. Here we are. The breach that actually caused chaos this week was not perpetrated by a cunning AI. It was perpetrated by a forgotten password from a legacy integration that nobody bothered to clean up. The attack surface was not a sophisticated zero-day vulnerability — it was basic credential hygiene, or rather the complete absence of it. One lazy administrative oversight did more damage than any AI has managed so far.
The Timeless Art of Not Tidying Up After Yourself
This is, of course, not a new problem. Poor password management has been the villain of the security world since roughly the invention of the password itself. Security professionals have been begging people to delete unused credentials, rotate passwords, and implement proper offboarding procedures since before some of today’s sysadmins were born. Nevertheless, here we are in 2026, still discovering that the password equivalent of a Post-it note on the monitor is alive and well.
The delicious irony is that among the companies affected was LastPass — a password manager. A company whose entire purpose is managing passwords. Getting caught out by an unmanaged password is a bit like a dentist being found with seventeen cavities. One admires the commitment to the bit, at least.
Password Stupidity Strikes Again — And Will Strike Next Week Too
AI is clever. AI is fast. AI is, apparently, quite good at finding security vulnerabilities in complex systems. However, AI cannot retroactively force a departing employee’s Salesforce integration credentials to be deleted. It cannot make sysadmins audit their legacy accounts. It cannot cure the very human tendency to leave things in the too-hard pile until a criminal does something interesting with them.
Password stupidity strikes again, as it has always struck, and as it will continue to strike until either humans develop better habits or robots simply take over the IT department entirely. Given current trends, the robots might want to get started.
Read the original story at The Register – BOFH & Odd.
🛒 Related Finds on Amazon
As an Amazon Associate I earn from qualifying purchases.
