microsegment.io

segment all the things

The Platform Was Not Breached. The Delegated Key Was.

The BigCommerce Ribon incident shows why third-party SaaS identities need their own containment boundaries

Compromised credentials for the Ribon BigCommerce apps reportedly enabled customer-data access and storefront script injection across merchant environments. This article explains how to contain delegated SaaS identities with narrow scopes, separated permissions, independent revocation, and behavioral monitoring.

Non-Human Identities Need Containment, Not Just Rotation

Service accounts, API keys, OAuth apps, and agents are now lateral movement infrastructure

Non-human identities are becoming one of the most important trust paths in modern environments. This article explains why service accounts, API keys, OAuth apps, and AI agents need microsegmentation and blast-radius control, not just secrets hygiene.

Weekly Security Landscape: April 18 - 25, 2026

Why overextended trust kept turning normal infrastructure into the fastest path to impact

This week's biggest security stories through a microsegmentation lens: exposed management planes, SaaS and OAuth trust failures, developer-tool compromise, and router-driven token theft.