An approved SaaS app is not automatically a safe SaaS app. If an OAuth connection or trusted integration is compromised, attackers may be able to use permissions your organisation has already granted. CASB security helps mid-market IT and security teams discover cloud-app use and control risky actions, turning SaaS access from a one-time approval into an ongoing control.
CASB security provides visibility and policy control across cloud applications. It helps organisations identify sanctioned and unsanctioned services, govern actions such as uploads and downloads, and reduce blind spots around how users move data. Native SaaS controls remain necessary for reviewing platform-specific OAuth permissions, tokens and application activity.
At TrustLayer, we help organisations address that wider control problem. TrustLayer Browse discovers cloud-app use and applies policy to actions inside supported apps. TrustLayer Posture identifies configuration weaknesses across supported cloud and SaaS services. TrustLayer Users combines awareness training and phishing simulations with built-in MFA policy checks.
Explore TrustLayer One and see how cloud app, posture and user controls work together.
What ShinyHunters reveals about CASB security and SaaS integrations
In July 2026, Microsoft reported ShinyHunters-linked campaigns that abused trusted OAuth relationships to access SaaS data. One route used voice phishing to persuade employees to authorise an attacker-controlled Salesforce application. Another used compromised integrations involving providers such as Salesloft and Gainsight.
Neither route depended on an inherent Salesforce vulnerability. Attackers operated through approved applications, inherited privileges and trusted supplier connections. That allowed them to query and exfiltrate CRM records while avoiding some of the sign-in anomalies security teams usually investigate.
The lesson is broader than Salesforce. A cloud application can be legitimate, useful and properly approved when it is introduced, then become risky later because its owner changes, its permissions no longer match its purpose or the supplier behind it is compromised.
How CASB security helps control cloud-app risk
The answer is not to block every SaaS integration. CASB security helps make cloud-app use easier to see and sensitive actions easier to control, while posture management helps teams prioritise configuration weaknesses. TrustLayer One brings those complementary controls into a modular platform, so organisations can use the layers they need without building another oversized stack.
Discover cloud-app use with TrustLayer Browse
Licence records rarely show the full SaaS estate. Teams adopt plug-ins, file-sharing services, automation tools and personal cloud accounts faster than central lists are updated. TrustLayer Browse applies CASB security controls to detect sanctioned and unsanctioned cloud applications as users access them, helping IT see who is using which services and where shadow IT or SaaS sprawl is developing.
That changes the starting point for an investigation or audit. Instead of reconstructing cloud-app use from expense records, browser history and conversations with different departments, the team has a clearer view of the services in use and can focus on the applications that need attention.
Control risky actions without blocking useful apps
An application does not have to be either completely open or completely blocked. TrustLayer Browse can apply policy to actions inside sanctioned and unsanctioned cloud apps, including uploads and downloads. Rules can reflect factors such as the user, device, location and risk, allowing the business to keep useful services available while placing tighter control around sensitive activity.
This is especially relevant when an organisation wants to allow a collaboration or AI tool but prevent company data being uploaded from an unmanaged device or personal account. The control follows the action that creates the risk, rather than treating every use of the application in the same way.
DirectProtectâ„¢ applies TrustLayer Browse controls without routing browsing traffic through a hosted proxy. Traffic keeps its original path, which reduces deployment friction and avoids making security another source of delay for users.
Find configuration weaknesses with TrustLayer Posture
Cloud risk is not limited to the applications people choose. Weak settings, policy drift and misconfiguration can leave approved environments exposed. TrustLayer Posture identifies configuration weaknesses across supported cloud and SaaS services, brings configuration, identity and policy data into a clearer view, and provides remediation guidance.
For a lean team, the operational benefit is straightforward. Findings can be prioritised without working through a long list of separate admin portals and spreadsheets. The same visibility can also help teams show what was found, what changed and which controls have been addressed when an audit or customer review makes evidence urgent.
Strengthen the user layer with TrustLayer Users
The ShinyHunters campaigns also relied on people being persuaded to trust an unexpected support call or approval process. TrustLayer Users combines security awareness training and phishing simulations with built-in MFA policy checks. It helps organisations reinforce safer behaviour and improve visibility into user and MFA risk without relying on a single annual exercise.
These layers answer different questions. Browse shows which cloud services people use and controls actions inside supported apps. Posture highlights weaknesses in supported environments. Users addresses the behaviours and MFA policies attackers may exploit. Bringing them together reduces console switching and gives IT a more connected view of cloud-app risk.
Why approved access is difficult to govern
OAuth allows one application to receive delegated access to another service without obtaining the user’s password. That access is defined through permissions, often called scopes. Some provide read-only access. Others allow exports, record changes or actions on behalf of a user.
A broad permission is not automatically inappropriate. Some integrations need wide access to do their job. The practical question is whether the permission still matches the application’s current purpose, whether someone owns the decision and whether the access is proportionate to the data involved.
The same judgement applies to activity. A connection with little recent use may be obsolete, or it may support an important month-end process. Removing it on activity data alone can stop a live sales, finance or reporting workflow.
Consider the position when a supplier reports an incident. The original application owner has moved on and nobody can immediately confirm what depends on the connection. The supplier may say its incident is contained. Your team still has to establish what the integration could reach and whether disabling it will interrupt business operations.
Where native SaaS controls still matter
Native controls in the relevant SaaS platform remain necessary for reviewing platform-specific OAuth permissions, revoking tokens and investigating application or API activity. TrustLayer complements that work with CASB security for broader cloud-app discovery and action-level policy, alongside posture visibility and user security.
When a trusted supplier connection is compromised, use the native platform controls to contain access, preserve relevant logs, establish the permissions and potential data reach, and review activity before restoring the integration. Revocation can interrupt a live workflow, so restoration should follow confirmation from both the technical team and an accountable business owner.
An approved app should not receive permanent trust
SaaS integrations are part of normal business operations. The goal is not to remove useful tools. It is to keep the trust around them visible, limited and reviewable.
The ShinyHunters campaigns show why approval cannot be treated as a lifetime warranty. Security teams need to know which services are in use, what actions users can take, where configuration weaknesses exist and which native controls are needed when a platform-specific connection must be investigated.
TrustLayer brings Browse, Posture and Users into one modular platform, helping lean teams reduce cloud-app blind spots, apply policy and act on configuration and user risk with less operational drag.
Book a TrustLayer demo to see how TrustLayer Browse, Posture and Users can help your team discover cloud-app use, control risky actions and reduce configuration blind spots across supported environments.
Frequently asked questions
What is CASB security?
CASB security gives organisations visibility and policy control over how people use cloud applications. It can help discover sanctioned and unsanctioned apps and govern actions such as uploads and downloads. Native SaaS controls remain necessary for reviewing platform-specific OAuth permissions, revoking tokens and investigating application activity.
Can MFA prevent OAuth token abuse?
MFA helps reduce unauthorised sign-ins, but it may not challenge an application using previously authorised access. It should sit alongside native app governance, cloud-app visibility, action controls and configuration monitoring.
Was the ShinyHunters activity caused by a Salesforce vulnerability?
Microsoft stated that the activity was not caused by an inherent Salesforce vulnerability. Attackers abused malicious OAuth consent and compromised trusted integrations to operate through access that appeared legitimate.